Jump to content

GSTN mail certificate renewal process

From TetraWiki


check if backup of /opt/zimbra/ssl has been taken for all servers

copy certificate files ( zip) on all the servers in /tmp


Readiness[edit]

cd /tmp 
unzip zip 
mv <mail_gstn_org_in.crt> commercial.crt
cp /opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt . 

ensure /tmp/commercial.crt and /tmp/commercial_ca.crt are readable by Zimbra user


Verify the Certificate[edit]

su - zimbra 
/opt/zimbra/bin/zmcertmgr verifycrt comm /opt/zimbra/ssl/zimbra/commercial/commercial.key /tmp/commercial.crt /tmp/commercial_ca.crt

Answer should be OK


Then deploy certificate[edit]

/opt/zimbra/bin/zmcertmgr deploycrt comm /tmp/commercial.crt /tmp/commercial_ca.crt 

All line should be Ok or Done . There should not be any failures or failed

Deploy on all m/c


Restart Zimbrra Services[edit]

on MTA1 / Mta 2 and archive

su - zimbra 
zmcontrol restart 

on Active mailbox server

pcs status 

on active node

pcs cluster standby <Hostname>

check for services on the other host

Check on Browser https://mail.gstn.org.in