User Tools

Site Tools


internet:security:ssl_cert_letsencrypt_zimbra

This is an old revision of the document!


Using LetsEncrypt SSL Certificates with Zimbra

See also Zimbra Self-Signed SSL Certs

Howto: https://wiki.zimbra.com/wiki/Installing_a_LetsEncrypt_SSL_Certificate

Your Zimbra will be restarted during this process, taking users offline!
Be sure to include all Subject Alternative Hostnames (SANs) that you need on the certificate.

FIXME This next tip needs careful testing and verification!

The single-server portion of the howto is fantastic. However, it only works for the actual hostname and doesn't include any SANs (alternate hostnames) you might need. If you already have an Nginx Proxy Manager, you might use it to create a Redirection Host for your main Zimbra hostname, including the LetsEncrypt certificate.

Troubleshooting

If you have trouble reissuing a new cert, or if Zimbra won't start, recreate and deploy a new self-signed cert to get Zimbra 'working' again. Then re-implement a LetsEncrypt cert.

If a cert is expired, you must reissue a new cert.

If a certificate renewal fails, try reissuing a new cert instead.

internet/security/ssl_cert_letsencrypt_zimbra.1659637944.txt.gz · Last modified: 2022/08/04 12:32 by gcooper