{"id":8011,"date":"2021-09-06T12:10:03","date_gmt":"2021-09-06T06:40:03","guid":{"rendered":"https:\/\/www.skynats.com\/?p=8011"},"modified":"2024-12-12T14:17:55","modified_gmt":"2024-12-12T08:47:55","slug":"lets-encrypt-ssl-certificate-installation-on-the-zimbra-domain","status":"publish","type":"post","link":"https:\/\/www.skynats.com\/blog\/lets-encrypt-ssl-certificate-installation-on-the-zimbra-domain\/","title":{"rendered":"Let&#8217;s Encrypt SSL certificate installation on the Zimbra domain"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Zimbra mail server is a type of dedicated server that manages, contacts, mailbox contents, attachments, calendar, etc,.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here we are going to install Let&#8217;s Encrypt free SSL on a Zimbra mail domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">How to install Let&#8217;s Encrypt SSL on a Zimbra domain?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can install Let&#8217;s Encrypt SSL on the Zimbra domain using certbot utility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First, you have to stop the jetty or nginx utility.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>su zimbra\nzmproxyctl stop\nzmmailboxdctl stop<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>yum install certbot\ncertbot certonly<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If your system is not supported certbot command, in that case you can use the snapd package to install certbot.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Install Epel repository to the server.<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>yum install epel-release<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Install snapd package using the below command.<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo yum install snapd<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Enable snapd packge in the server.<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo systemctl enable --now snapd.socket<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>On sometimes the above command does not work completely, then you can run the given command to create a symbolic link between \/var\/lib\/snapd\/snap and \/snap.<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code><meta charset=\"utf-8\">sudo ln -s \/var\/lib\/snapd\/snap \/snap<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Install snap core.<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo snap install core\nsudo snap refresh core<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Install certbot in the server .<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo snap install --classic certbot\nsudo ln -s \/snap\/bin\/certbot\/ \/usr\/bin\/certbot<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Now you can run the given command to generate the Let&#8217;s Encrypt certficates for the domain.<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo certbot certonly<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Choose option 1: Spin up a temporary webserver (standalone).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then enter the domain name for your Zimbra installed domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, mail.skynats.com<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then the Let&#8217;s Encrypt SSL certificates can be found inside your system&#8217;s \/etc\/letsencrypt\/live\/mail.skynats.com\/ folder.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There you can see cert.pem , chain.pem, fullchain.pem, privkey.pem files.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Next you have to add the given text in end of your chain.pem file.<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>-----BEGIN CERTIFICATE-----\nYour chain\n-----END CERTIFICATE-----\n\n-----BEGIN CERTIFICATE-----\nMIIDSjCCAjKgAwIBAgIQRK+wgNajJ7qJMDmGLvhAazANBgkqhkiG9w0BAQUFADA\/\nMSQwIgYDVQQKExtEaWdpdGFsIFNpZ25hdHVyZSBUcnVzdCBDby4xFzAVBgNVBAMT\nDkRTVCBSb290IENBIFgzMB4XDTAwMDkzMDIxMTIxOVoXDTIxMDkzMDE0MDExNVow\nPzEkMCIGA1UEChMbRGlnaXRhbCBTaWduYXR1cmUgVHJ1c3QgQ28uMRcwFQYDVQQD\nEw5EU1QgUm9vdCBDQSBYMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB\nAN+v6ZdQCINXtMxiZfaQguzH0yxrMMpb7NnDfcdAwRgUi+DoM3ZJKuM\/IUmTrE4O\nrz5Iy2Xu\/NMhD2XSKtkyj4zl93ewEnu1lcCJo6m67XMuegwGMoOifooUMM0RoOEq\nOLl5CjH9UL2AZd+3UWODyOKIYepLYYHsUmu5ouJLGiifSKOeDNoJjj4XLh7dIN9b\nxiqKqy69cK3FCxolkHRyxXtqqzTWMIn\/5WgTe1QLyNau7Fqckh49ZLOMxt+\/yUFw\n7BZy1SbsOFU5Q9D8\/RhcQPGX69Wam40dutolucbY38EVAjqr2m7xPi71XAicPNaD\naeQQmxkqtilX4+U9m5\/wAl0CAwEAAaNCMEAwDwYDVR0TAQH\/BAUwAwEB\/zAOBgNV\nHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFMSnsaR7LHH62+FLkHX\/xBVghYkQMA0GCSqG\nSIb3DQEBBQUAA4IBAQCjGiybFwBcqR7uKGY3Or+Dxz9LwwmglSBd49lZRNI+DT69\nikugdB\/OEIKcdBodfpga3csTS7MgROSR6cz8faXbauX+5v3gTt23ADq1cEmv8uXr\nAvHRAosZy5Q6XkjEGB5YGV8eAlrwDPGxrancWYaLbumR9YbK+rlmM6pZW87ipxZz\nR8srzJmwN0jP41ZL9c8PDHIyh8bwRLtTcm1D9SZImlJnt1ir\/md2cXjbDaJWFBM5\nJDGFoqgCWjBH4d1QB7wCCZAA62RjYJsWvIjJEubSfZGL+T0yjWW06XyxV3bqxbYo\nOb8VZRzI9neWagqNdwvYkQsEjgfbKbYK7p2CNTUQ\n-----END CERTIFICATE-----<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Create a folder named \/opt\/zimbra\/ssl\/letsencrypt and copy these certificate files to there. (Copy each file manually by pasting the content of certificate file because there is a chance of conflicting the symlinks)<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>mkdir -p \/opt\/zimbra\/ssl\/letsencrypt\/<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">copy the content of \/etc\/letsencrypt\/live\/mail.skynats.com\/cert.pem, chain.pem, fullchain.pem, privkey.pem and paste them to \/opt\/zimbra\/ssl\/letsencrypt\/cert.pem, chain.pem , fullchain.pem, privkey.pem correspondingly. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Next you have to change the ownership of the \/opt\/zimbra\/ssl\/letsencrypt folder to zimbra user.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>chown -R zimbra:zimbra \/opt\/zimbra\/ssl\/letsencrypt<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Then you have to verify the certificates.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"652\" sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"https:\/\/www.skynats.com\/blog\/wp-content\/uploads\/2021\/09\/Screenshot-2021-09-03-at-4.05.35-PM-1024x652.png\" alt=\"\" class=\"wp-image-8017\" srcset=\"https:\/\/www.skynats.com\/blog\/wp-content\/uploads\/2021\/09\/Screenshot-2021-09-03-at-4.05.35-PM-1024x652.png 1024w, https:\/\/www.skynats.com\/blog\/wp-content\/uploads\/2021\/09\/Screenshot-2021-09-03-at-4.05.35-PM-300x191.png 300w, https:\/\/www.skynats.com\/blog\/wp-content\/uploads\/2021\/09\/Screenshot-2021-09-03-at-4.05.35-PM-768x489.png 768w, https:\/\/www.skynats.com\/blog\/wp-content\/uploads\/2021\/09\/Screenshot-2021-09-03-at-4.05.35-PM.png 1040w\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>su zimbra\ncd \/opt\/zimbra\/ssl\/letsencrypt\/\n\/opt\/zimbra\/bin\/zmcertmgr verifycrt comm privkey.pem cert.pem chain.pem<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Deploy the certficates.<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>cp \/opt\/zimbra\/ssl\/letsencrypt\/privkey.pem \/opt\/zimbra\/ssl\/zimbra\/commercial\/commercial.key\n\n\/opt\/zimbra\/bin\/zmcertmgr deploycrt comm cert.pem chain.pem<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"396\" sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"https:\/\/www.skynats.com\/blog\/wp-content\/uploads\/2021\/09\/Screenshot-2021-09-03-at-4.22.48-PM-1024x396.png\" alt=\"\" class=\"wp-image-8018\" srcset=\"https:\/\/www.skynats.com\/blog\/wp-content\/uploads\/2021\/09\/Screenshot-2021-09-03-at-4.22.48-PM-1024x396.png 1024w, https:\/\/www.skynats.com\/blog\/wp-content\/uploads\/2021\/09\/Screenshot-2021-09-03-at-4.22.48-PM-300x116.png 300w, https:\/\/www.skynats.com\/blog\/wp-content\/uploads\/2021\/09\/Screenshot-2021-09-03-at-4.22.48-PM-768x297.png 768w, https:\/\/www.skynats.com\/blog\/wp-content\/uploads\/2021\/09\/Screenshot-2021-09-03-at-4.22.48-PM-1200x464.png 1200w, https:\/\/www.skynats.com\/blog\/wp-content\/uploads\/2021\/09\/Screenshot-2021-09-03-at-4.22.48-PM.png 1340w\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Restart the Zimbra services as Zimbra user using the below command.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>su zimbra\nzmproxyctl start\nzmmailboxdctl start\nzmcontrol restart<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You can now access the Zimbra domain with SSL (https).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">https:\/\/domain.com<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is easy to set up SL for the Zimbra domain, but most of the users are getting errors when installing let&#8217;s encrypt without following the proper way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our <a href=\"https:\/\/www.skynats.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener\"><span style=\"color:#0277a8\" class=\"has-inline-color\">technical team<\/span><\/a> with proficient knowledge in Mail Servers will help you at any time troubleshooting issues with any kind of mail server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Zimbra mail server is a type of dedicated server that manages, contacts, mailbox contents, attachments, calendar, etc,. Here we are going to install Let&#8217;s Encrypt free SSL on a Zimbra mail domain. How to install Let&#8217;s Encrypt SSL on a Zimbra domain? You can install Let&#8217;s Encrypt SSL on the Zimbra domain using certbot utility. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,261],"tags":[11,656],"class_list":["post-8011","post","type-post","status-publish","format-standard","hentry","category-blog","category-ssl-certificate","tag-ssl-certificates","tag-zimbra"],"_links":{"self":[{"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/posts\/8011","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/comments?post=8011"}],"version-history":[{"count":0,"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/posts\/8011\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/media?parent=8011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/categories?post=8011"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.skynats.com\/blog\/wp-json\/wp\/v2\/tags?post=8011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}