Добрый день, Оксана!
Побовал обновить сертификат по Вашей ссылке, но судя по логу, часть действий прошли с ошибками:
Normal
0
false
false
false
RU
X-NONE
X-NONE
MicrosoftInternetExplorer4
Ну так у вас <control-param> не учитывается в gc:contractor, так как вы закрыли тэг <control /> сразу. Уберите из строки <control template="/alvex-masterData-select.ftl"/> слэш перед закрытием тэга, и закройте тэг как </control> после указания параметра.
Побовал обновить сертификат по Вашей ссылке, но судя по логу, часть действий прошли с ошибками:
Normal 0 false false false RU X-NONE X-NONE MicrosoftInternetExplorer4
root@mail:/# /opt/zimbra/bin/zmcertmgr createca -new
** Creating directory /opt/zimbra/ssl/zimbra
** Creating directory /opt/zimbra/ssl/zimbra/ca
** Creating directory /opt/zimbra/ssl/zimbra/server
** Creating directory /opt/zimbra/ssl/zimbra/commercial
** Creating /opt/zimbra/ssl/zimbra/ca/zmssl.cnf...done
** Creating CA private key /opt/zimbra/ssl/zimbra/ca/ca.key...done.
** Creating CA cert /opt/zimbra/ssl/zimbra/ca/ca.pem...done.
_____________________________________________________
root@mail:/# /opt/zimbra/bin/zmcertmgr createcrt -new -days 365
Validation days: 365
** Creating /opt/zimbra/conf/zmssl.cnf...done
** Backup /opt/zimbra/ssl/zimbra to /opt/zimbra/ssl/zimbra.20131029160425
** Generating a server csr for download self -new -keysize 1024
** Backup /opt/zimbra/ssl/zimbra to /opt/zimbra/ssl/zimbra.20131029160425
** Retrieving Commercial CA cert from ldap...failed.
** Creating server cert request /opt/zimbra/ssl/zimbra/server/server.csr...done.
** Saving server config key zimbraSSLPrivateKey...failed.
** Signing cert request /opt/zimbra/ssl/zimbra/server/server.csr...done.
_____________________________________________________
root@mail:/# /opt/zimbra/bin/zmcertmgr deploycrt self
** Saving server config key zimbraSSLCertificate...failed.
** Saving server config key zimbraSSLPrivateKey...failed.
** Installing mta certificate and key...done.
** Installing slapd certificate and key...done.
** Installing proxy certificate and key...done.
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done.
** Installing CA to /opt/zimbra/conf/ca...done.
______________________________________________________
root@mail:/# /opt/zimbra/bin/zmcertmgr deployca
** Importing CA /opt/zimbra/ssl/zimbra/ca/ca.pem into CACERTS...done.
** Saving global config key zimbraCertAuthorityCertSelfSigned...failed.
** Saving global config key zimbraCertAuthorityKeySelfSigned...failed.
** Copying CA to /opt/zimbra/conf/ca...done.
_______________________________________________________
root@mail:/# /opt/zimbra/bin/zmcertmgr viewdeployedcrt
::service mta::
notBefore=Oct 29 13:04:30 2013 GMT
notAfter=Oct 29 13:04:30 2014 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=mail.xxx-xxx.com
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=mail.xxx-xxx.com
SubjectAltName=
::service proxy::
notBefore=Oct 29 13:04:30 2013 GMT
notAfter=Oct 29 13:04:30 2014 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=mail.xxx-xxx.com
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=mail.xxx-xxx.com
SubjectAltName=
::service mailboxd::
notBefore=Oct 29 13:04:30 2013 GMT
notAfter=Oct 29 13:04:30 2014 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=mail.xxx-xxx.com
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=mail.xxx-xxx.com
SubjectAltName=
::service ldap::
notBefore=Oct 29 13:04:30 2013 GMT
notAfter=Oct 29 13:04:30 2014 GMT
subject= /C=US/ST=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=mail.xxx-xxx.com
issuer= /C=US/ST=N/A/L=N/A/O=Zimbra Collaboration Suite/OU=Zimbra Collaboration Suite/CN=mail.xxx-xxx.com
SubjectAltName= /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Обычная таблица"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-priority:99; mso-style-qformat:yes; mso-style-parent:""; mso-padding-alt:0cm 5.4pt 0cm 5.4pt; mso-para-margin-top:0cm; mso-para-margin-right:0cm; mso-para-margin-bottom:10.0pt; mso-para-margin-left:0cm; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:"Times New Roman"; mso-fareast-theme-font:minor-fareast; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin;}_________________________________________________________________________________________
После запустил - zmcontrol start, ошибка таже самая.
Может дело действительно в DNS, как это можно проверить?
Спасибо!
Из менее банальных: если Zimbra проработала год или 2, то скорее всего пришло время обновлять сертификат. Самая нормальная инструкция: http://mbahjasjus.wordpress.com/2011/02/01/renew-certificate-or-create-new-certificate-from-zimbra-cli/
does not resolve to address 77.78.23.170