more details please...zimbraxtc wrote:Fixed it by rerunning getssl with a specified chain and appended correct cert x1. And got a OKzimbraxtc wrote:Hello and thanks for a great thread!
Im running a old 8.6 and would like to install a lets encrypt cert...
So... I used getssl to generate those files:
-rw------- 1 root root 5768 apr 4 15:55 chain.crt
-rw------- 1 root root 6076 apr 4 16:21 fullchain.crt
-rw------- 1 root root 3448 apr 4 15:41 mymailserver.se.crt
-rw------- 1 root root 1614 apr 4 15:06 mymailserver.se.csr
-rw------- 1 root root 3243 apr 4 15:06 mymailserver.se.key
I also tried to append fullchain with files according to different posts but I didnt get it to work and just run into:
fredde@xx:~/.getssl/mymailserver/archive/2021_04_04_15_06$ sudo /opt/zimbra/bin/zmcertmgr verifycrt comm mymailserver.se.key mymailserver.se.crt fullchain.crt
** Verifying mymailserver.se.crt against mymailserver.se.key
Certificate (mymailserver.se.crt) and private key (mymailserver.key) match.
XXXXX ERROR: Invalid Certificate: mymailserver.se.crt: C = US, O = (STAGING) Internet Security Research Group, CN = (STAGING) Pretend Pear X1
error 2 at 2 depth lookup:unable to get issuer certificate
I have tried to append fullchain.crt with a lot of different certs but cant get it working...
I have looked into: https://letsencrypt.org/certificates/ but really cant see what I am doing wrong.
Any great ideas??
Thanks a lot!
have the same problem.