Page 1 of 1

issue with letsencrypt certs

Posted: Sat Jun 16, 2018 8:20 am
by maumar
I have ZCS OS 8.8.8 and Nextcloud 13.0.2
I have installed letsencrypt certs oon eiher sides, Zimbra and Nextcloud
When I click on drive tab, I got java error about letsencrypt cert of nextcloud.

018-06-15 16:59:49,975 WARN [qtp998351292-1593:https:https://groupwarexxxxxx.it/service/soap/BatchRequest] [name=testcloud@xxxxxx.it;mid=6;ip=213.152.204.75;port=41658;ua=ZimbraWebClient - FF60 (Linux)/8.8.8_GA_1703;soapId=6232b787;] extensions - ZAL SOAP Unknown Exception: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
at sun.security.ssl.Alerts.getSSLException (Alerts.java:192)
at sun.security.ssl.SSLSocketImpl.fatal (SSLSocketImpl.java:1959)
at sun.security.ssl.Handshaker.fatalSE (Handshaker.java:302)
at sun.security.ssl.Handshaker.fatalSE (Handshaker.java:296)
at sun.security.ssl.ClientHandshaker.serverCertificate (ClientHandshaker.java:1514)
at sun.security.ssl.ClientHandshaker.processMessage (ClientHandshaker.java:216)
at sun.security.ssl.Handshaker.processLoop (Handshaker.java:1026)
at sun.security.ssl.Handshaker.process_record (Handshaker.java:961)
at sun.security.ssl.SSLSocketImpl.readRecord (SSLSocketImpl.java:1072)
at sun.security.ssl.SSLSocketImpl.performInitialHandshake (SSLSocketImpl.java:1385)
at sun.security.ssl.SSLSocketImpl.startHandshake (SSLSocketImpl.java:1413)
at sun.security.ssl.SSLSocketImpl.startHandshake (SSLSocketImpl.java:1397)
at org.apache.http.conn.ssl.SSLConnectionSocketFactory.createLayeredSocket (SSLConnectionSocketFactory.java:394)
at org.apache.http.conn.ssl.SSLConnectionSocketFactory.connectSocket (SSLConnectionSocketFactory.java:353)
at org.apache.http.impl.conn.DefaultHttpClientConnectionOperator.connect (DefaultHttpClientConnectionOperator.java:141)
at org.apache.http.impl.conn.PoolingHttpClientConnectionManager.connect (PoolingHttpClientConnectionManager.java:353)

Are you using letsencrypt certs, too?
And why do you haven't the same issue?

Re: issue with letsencrypt certs

Posted: Mon Jun 18, 2018 7:30 am
by maumar
Helo
I think that jetty on lst ZCS 8.8.8 should nt have issue with letsencrypt
I will file e bug