{"id":195232,"status":"ok","playbook":{"id":2389,"items":{"plays":1,"tasks":3,"results":15,"hosts":5,"files":1,"records":0},"arguments":{"version":null,"verbosity":2,"private_key_file":"/home/ssh-gateway/.ssh/id_rsa","remote_user":"root","connection":"ssh","timeout":null,"ssh_common_args":null,"sftp_extra_args":null,"scp_extra_args":null,"ssh_extra_args":null,"ask_pass":false,"connection_password_file":null,"force_handlers":false,"flush_cache":false,"become":false,"become_method":"sudo","become_user":null,"become_ask_pass":false,"become_password_file":null,"tags":["all"],"skip_tags":[],"check":false,"diff":false,"inventory":["/home/ssh-gateway/ansible/zimbra/inv-stage"],"listhosts":false,"subset":null,"extra_vars":"Not saved by ARA as configured by 'ignored_arguments'","vault_ids":[],"ask_vault_pass":false,"vault_password_files":[],"forks":20,"module_path":null,"syntax":false,"listtasks":false,"listtags":false,"step":false,"start_at_task":null,"args":["install_zimbra_certificate_stage.yaml"]},"labels":[{"id":1,"name":"remote_user:root"},{"id":2,"name":"check:False"},{"id":3,"name":"tags:all"}],"started":"2024-12-27T09:07:16.497645Z","ended":"2024-12-27T09:09:36.434442Z","duration":"00:02:19.936797","name":null,"ansible_version":"2.16.11","client_version":"1.7.2","python_version":"3.10.10","server_version":"1.7.2","status":"completed","path":"/home/ssh-gateway/ansible/zimbra/install_zimbra_certificate_stage.yaml","controller":"ssh-gw-4.layershift.com","user":"root"},"play":{"id":2704,"items":{"tasks":3,"results":15},"started":"2024-12-27T09:07:16.531153Z","ended":"2024-12-27T09:09:36.142380Z","duration":"00:02:19.611227","name":"Playbook to install zimbra wildcard certificate on cluster","status":"completed"},"task":{"id":5850,"items":{"results":5},"path":"/home/ssh-gateway/ansible/zimbra/install_zimbra_certificate_stage.yaml","tags":[],"started":"2024-12-27T09:07:22.148518Z","ended":"2024-12-27T09:09:36.093517Z","duration":"00:02:13.944999","name":"Install certificate on host","uuid":"001851d0-75dc-cec1-c661-00000000000a","action":"ansible.builtin.shell","lineno":28,"handler":false,"status":"completed","warnings":[],"deprecations":[],"exceptions":[],"file":4465},"host":{"id":82115,"name":"proxy-stage","changed":1,"failed":0,"ok":3,"skipped":0,"unreachable":0},"delegated_to":[],"content":{"changed":false,"cmd":"set -o pipefail\nchown zimbra.zimbra /tmp/commercial_stage.key /tmp/ssl_stage.crt /tmp/chain_stage.crt\nsu -l zimbra -c \"cp -prf /tmp/commercial_stage.key /opt/zimbra/ssl/zimbra/commercial/commercial.key\"\nsu -l zimbra -c \"zmcertmgr verifycrt comm /tmp/commercial_stage.key /tmp/ssl_stage.crt /tmp/chain_stage.crt\"\nsu -l zimbra -c \"zmcertmgr deploycrt comm /tmp/ssl_stage.crt /tmp/chain_stage.crt\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_required=true\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_supported=1\"\nsu -l zimbra -c \"zmcontrol restart\"\nsu -l zimbra -c \"zmcertmgr viewdeployedcrt\"\n","delta":"0:02:13.279509","end":"2024-12-27 09:09:35.998052","invocation":{"module_args":{"_raw_params":"set -o pipefail\nchown zimbra.zimbra /tmp/commercial_stage.key /tmp/ssl_stage.crt /tmp/chain_stage.crt\nsu -l zimbra -c \"cp -prf /tmp/commercial_stage.key /opt/zimbra/ssl/zimbra/commercial/commercial.key\"\nsu -l zimbra -c \"zmcertmgr verifycrt comm /tmp/commercial_stage.key /tmp/ssl_stage.crt /tmp/chain_stage.crt\"\nsu -l zimbra -c \"zmcertmgr deploycrt comm /tmp/ssl_stage.crt /tmp/chain_stage.crt\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_required=true\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_supported=1\"\nsu -l zimbra -c \"zmcontrol restart\"\nsu -l zimbra -c \"zmcertmgr viewdeployedcrt\"\n","_uses_shell":true,"argv":null,"chdir":null,"creates":null,"executable":"/bin/bash","expand_argument_vars":true,"removes":null,"stdin":null,"stdin_add_newline":true,"strip_empty_ends":true}},"msg":"","rc":0,"start":"2024-12-27 09:07:22.718543","stderr":"Connect: Unable to determine enabled services from ldap.\nEnabled services read from cache. Service list may be inaccurate.","stderr_lines":["Connect: Unable to determine enabled services from ldap.","Enabled services read from cache. Service list may be inaccurate."],"stdout":"** Verifying '/tmp/ssl_stage.crt' against '/tmp/commercial_stage.key'\nCertificate '/tmp/ssl_stage.crt' and private key '/tmp/commercial_stage.key' match.\n** Verifying '/tmp/ssl_stage.crt' against '/tmp/chain_stage.crt'\nERROR: Unable to validate certificate chain: CN = proxy-mta.zimbra.stage.town\nerror 10 at 0 depth lookup: certificate has expired\nerror /tmp/ssl_stage.crt: verification failed\n** Verifying '/tmp/ssl_stage.crt' against '/opt/zimbra/ssl/zimbra/commercial/commercial.key'\nCertificate '/tmp/ssl_stage.crt' and private key '/opt/zimbra/ssl/zimbra/commercial/commercial.key' match.\n** Verifying '/tmp/ssl_stage.crt' against '/tmp/chain_stage.crt'\nERROR: Unable to validate certificate chain: CN = proxy-mta.zimbra.stage.town\nerror 10 at 0 depth lookup: certificate has expired\nerror /tmp/ssl_stage.crt: verification failed\nHost proxy-mta.zimbra.stage.town\n\tStopping vmware-ha...Done.\n\tStopping zmconfigd...Done.\n\tStopping zimlet webapp...Done.\n\tStopping zimbraAdmin webapp...Done.\n\tStopping zimbra webapp...Done.\n\tStopping service webapp...Done.\n\tStopping stats...Done.\n\tStopping mta...Done.\n\tStopping onlyoffice...Done.\n\tStopping spell...Done.\n\tStopping snmp...Done.\n\tStopping cbpolicyd...Done.\n\tStopping archiving...Done.\n\tStopping opendkim...Done.\n\tStopping amavis...Done.\n\tStopping antivirus...Done.\n\tStopping antispam...Done.\n\tStopping proxy...Done.\n\tStopping memcached...Done.\n\tStopping mailbox...Done.\n\tStopping logger...Done.\n\tStopping dnscache...Done.\nHost proxy-mta.zimbra.stage.town\n\tStarting zmconfigd...Failed.\nStarting zmconfigd...failed.\n\n\n\tStarting dnscache...Done.\n\tStarting memcached...Done.\n\tStarting proxy...Done.\n\tStarting amavis...Done.\n\tStarting antispam...Done.\n\tStarting antivirus...Done.\n\tStarting opendkim...Done.\n\tStarting mta...Done.\n\tStarting stats...Done.\n- imapd: /opt/zimbra/conf/imapd.crt\nnotBefore=Dec 23 12:31:18 2024 GMT\nnotAfter=Mar 23 12:31:17 2025 GMT\nsubject=CN = proxy-mta.zimbra.stage.town\nissuer=C = US, O = Let's Encrypt, CN = R10\nSubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town\n- ldap: /opt/zimbra/conf/slapd.crt\nnotBefore=Dec 23 12:31:18 2024 GMT\nnotAfter=Mar 23 12:31:17 2025 GMT\nsubject=CN = proxy-mta.zimbra.stage.town\nissuer=C = US, O = Let's Encrypt, CN = R10\nSubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town\n- mta: /opt/zimbra/conf/smtpd.crt\nnotBefore=Dec 23 12:31:18 2024 GMT\nnotAfter=Mar 23 12:31:17 2025 GMT\nsubject=CN = proxy-mta.zimbra.stage.town\nissuer=C = US, O = Let's Encrypt, CN = R10\nSubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town\n- proxy: /opt/zimbra/conf/nginx.crt\nnotBefore=Dec 23 12:31:18 2024 GMT\nnotAfter=Mar 23 12:31:17 2025 GMT\nsubject=CN = proxy-mta.zimbra.stage.town\nissuer=C = US, O = Let's Encrypt, CN = R10\nSubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town","stdout_lines":["** Verifying '/tmp/ssl_stage.crt' against '/tmp/commercial_stage.key'","Certificate '/tmp/ssl_stage.crt' and private key '/tmp/commercial_stage.key' match.","** Verifying '/tmp/ssl_stage.crt' against '/tmp/chain_stage.crt'","ERROR: Unable to validate certificate chain: CN = proxy-mta.zimbra.stage.town","error 10 at 0 depth lookup: certificate has expired","error /tmp/ssl_stage.crt: verification failed","** Verifying '/tmp/ssl_stage.crt' against '/opt/zimbra/ssl/zimbra/commercial/commercial.key'","Certificate '/tmp/ssl_stage.crt' and private key '/opt/zimbra/ssl/zimbra/commercial/commercial.key' match.","** Verifying '/tmp/ssl_stage.crt' against '/tmp/chain_stage.crt'","ERROR: Unable to validate certificate chain: CN = proxy-mta.zimbra.stage.town","error 10 at 0 depth lookup: certificate has expired","error /tmp/ssl_stage.crt: verification failed","Host proxy-mta.zimbra.stage.town","\tStopping vmware-ha...Done.","\tStopping zmconfigd...Done.","\tStopping zimlet webapp...Done.","\tStopping zimbraAdmin webapp...Done.","\tStopping zimbra webapp...Done.","\tStopping service webapp...Done.","\tStopping stats...Done.","\tStopping mta...Done.","\tStopping onlyoffice...Done.","\tStopping spell...Done.","\tStopping snmp...Done.","\tStopping cbpolicyd...Done.","\tStopping archiving...Done.","\tStopping opendkim...Done.","\tStopping amavis...Done.","\tStopping antivirus...Done.","\tStopping antispam...Done.","\tStopping proxy...Done.","\tStopping memcached...Done.","\tStopping mailbox...Done.","\tStopping logger...Done.","\tStopping dnscache...Done.","Host proxy-mta.zimbra.stage.town","\tStarting zmconfigd...Failed.","Starting zmconfigd...failed.","","","\tStarting dnscache...Done.","\tStarting memcached...Done.","\tStarting proxy...Done.","\tStarting amavis...Done.","\tStarting antispam...Done.","\tStarting antivirus...Done.","\tStarting opendkim...Done.","\tStarting mta...Done.","\tStarting stats...Done.","- imapd: /opt/zimbra/conf/imapd.crt","notBefore=Dec 23 12:31:18 2024 GMT","notAfter=Mar 23 12:31:17 2025 GMT","subject=CN = proxy-mta.zimbra.stage.town","issuer=C = US, O = Let's Encrypt, CN = R10","SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town","- ldap: /opt/zimbra/conf/slapd.crt","notBefore=Dec 23 12:31:18 2024 GMT","notAfter=Mar 23 12:31:17 2025 GMT","subject=CN = proxy-mta.zimbra.stage.town","issuer=C = US, O = Let's Encrypt, CN = R10","SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town","- mta: /opt/zimbra/conf/smtpd.crt","notBefore=Dec 23 12:31:18 2024 GMT","notAfter=Mar 23 12:31:17 2025 GMT","subject=CN = proxy-mta.zimbra.stage.town","issuer=C = US, O = Let's Encrypt, CN = R10","SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town","- proxy: /opt/zimbra/conf/nginx.crt","notBefore=Dec 23 12:31:18 2024 GMT","notAfter=Mar 23 12:31:17 2025 GMT","subject=CN = proxy-mta.zimbra.stage.town","issuer=C = US, O = Let's Encrypt, CN = R10","SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town"]},"created":"2024-12-27T09:09:36.078453Z","updated":"2024-12-27T09:09:36.078488Z","started":"2024-12-27T09:07:22.353744Z","ended":"2024-12-27T09:09:36.071022Z","duration":"00:02:13.717278","changed":false,"ignore_errors":false}