Execution
Date
09 Sep 2024 13:34:55 +0100
Duration
00:01:16.19
Controller
ssh-gw-4.layershift.com
User
root
Versions
Ansible
2.16.4
ara
1.7.1 / 1.7.1
Python
3.10.10
Summary
5
Hosts
3
Tasks
15
Results
1
Plays
1
Files
0
Records
Task result details
-
StatusOK
-
Duration00:01:04.48
-
PlayPlaybook to install zimbra wildcard certificate on cluster
-
TaskInstall certificate on host
-
Hostproxy-stage
-
Date09 Sep 2024 13:36:05 +0100
-
Module / Actionansible.builtin.shell (/home/ssh-gateway/ansible/zimbra/install_zimbra_certificate_stage.yaml:28)
| Field | Value |
|---|---|
| changed |
False |
| cmd |
set -o pipefail chown zimbra.zimbra /tmp/commercial_stage.key /tmp/ssl_stage.crt /tmp/chain_stage.crt su -l zimbra -c "cp -prf /tmp/commercial_stage.key /opt/zimbra/ssl/zimbra/commercial/commercial.key" su -l zimbra -c "zmcertmgr verifycrt comm /tmp/commercial_stage.key /tmp/ssl_stage.crt /tmp/chain_stage.crt" su -l zimbra -c "zmcertmgr deploycrt comm /tmp/ssl_stage.crt /tmp/chain_stage.crt" su -l zimbra -c "zmlocalconfig -e ldap_starttls_required=true" su -l zimbra -c "zmlocalconfig -e ldap_starttls_supported=1" su -l zimbra -c "zmcontrol restart" su -l zimbra -c "zmcertmgr viewdeployedcrt" |
| delta |
0:01:04.008992 |
| end |
2024-09-09 12:36:05.480218 |
| invocation |
{ "module_args": { "_raw_params": "set -o pipefail\nchown zimbra.zimbra /tmp/commercial_stage.key /tmp/ssl_stage.crt /tmp/chain_stage.crt\nsu -l zimbra -c \"cp -prf /tmp/commercial_stage.key /opt/zimbra/ssl/zimbra/commercial/commercial.key\"\nsu -l zimbra -c \"zmcertmgr verifycrt comm /tmp/commercial_stage.key /tmp/ssl_stage.crt /tmp/chain_stage.crt\"\nsu -l zimbra -c \"zmcertmgr deploycrt comm /tmp/ssl_stage.crt /tmp/chain_stage.crt\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_required=true\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_supported=1\"\nsu -l zimbra -c \"zmcontrol restart\"\nsu -l zimbra -c \"zmcertmgr viewdeployedcrt\"\n", "_uses_shell": true, "argv": null, "chdir": null, "creates": null, "executable": "/bin/bash", "expand_argument_vars": true, "removes": null, "stdin": null, "stdin_add_newline": true, "strip_empty_ends": true } } |
| msg |
|
| rc |
0 |
| start |
2024-09-09 12:35:01.471226 |
| stderr |
|
| stderr_lines |
[]
|
| stdout |
** Verifying '/tmp/ssl_stage.crt' against '/tmp/commercial_stage.key' Certificate '/tmp/ssl_stage.crt' and private key '/tmp/commercial_stage.key' match. ** Verifying '/tmp/ssl_stage.crt' against '/tmp/chain_stage.crt' Valid certificate chain: /tmp/ssl_stage.crt: OK ** Verifying '/tmp/ssl_stage.crt' against '/opt/zimbra/ssl/zimbra/commercial/commercial.key' Certificate '/tmp/ssl_stage.crt' and private key '/opt/zimbra/ssl/zimbra/commercial/commercial.key' match. ** Verifying '/tmp/ssl_stage.crt' against '/tmp/chain_stage.crt' Valid certificate chain: /tmp/ssl_stage.crt: OK ** Copying '/tmp/ssl_stage.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' ** Copying '/tmp/chain_stage.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt' ** Appending ca chain '/tmp/chain_stage.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' ** Importing cert '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt' as 'zcs-user-commercial_ca' into cacerts '/opt/zimbra/common/lib/jvm/java/lib/security/cacerts' ** NOTE: restart mailboxd to use the imported certificate. ** Installing imapd certificate '/opt/zimbra/conf/imapd.crt' and key '/opt/zimbra/conf/imapd.key' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/imapd.crt' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/imapd.key' ** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12' ** Creating keystore '/opt/zimbra/conf/imapd.keystore' ** Installing ldap certificate '/opt/zimbra/conf/slapd.crt' and key '/opt/zimbra/conf/slapd.key' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/slapd.crt' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/slapd.key' ** Installing mta certificate '/opt/zimbra/conf/smtpd.crt' and key '/opt/zimbra/conf/smtpd.key' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/smtpd.crt' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/smtpd.key' ** Installing proxy certificate '/opt/zimbra/conf/nginx.crt' and key '/opt/zimbra/conf/nginx.key' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/nginx.crt' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/nginx.key' ** NOTE: restart services to use the new certificates. ** Cleaning up 4 files from '/opt/zimbra/conf/ca' ** Removing /opt/zimbra/conf/ca/commercial_ca_1.crt ** Removing /opt/zimbra/conf/ca/31dfb39d.0 ** Removing /opt/zimbra/conf/ca/commercial_ca_2.crt ** Removing /opt/zimbra/conf/ca/4042bcee.0 ** Copying CA to /opt/zimbra/conf/ca ** Creating /opt/zimbra/conf/ca/commercial_ca_1.crt ** Creating CA hash symlink '31dfb39d.0' -> 'commercial_ca_1.crt' ** Creating /opt/zimbra/conf/ca/commercial_ca_2.crt ** Creating CA hash symlink '4042bcee.0' -> 'commercial_ca_2.crt' Host proxy-mta.zimbra.stage.town Stopping zmconfigd...Done. Stopping zimlet webapp...Done. Stopping zimbraAdmin webapp...Done. Stopping zimbra webapp...Done. Stopping service webapp...Done. Stopping stats...Done. Stopping mta...Done. Stopping onlyoffice...Done. Stopping spell...Done. Stopping snmp...Done. Stopping cbpolicyd...Done. Stopping archiving...Done. Stopping opendkim...Done. Stopping amavis...Done. Stopping antivirus...Done. Stopping antispam...Done. Stopping proxy...Done. Stopping memcached...Done. Stopping mailbox...Done. Stopping logger...Done. Stopping dnscache...Done. Host proxy-mta.zimbra.stage.town Starting zmconfigd...Done. Starting dnscache...Done. Starting memcached...Done. Starting proxy...Done. Starting amavis...Done. Starting antispam...Done. Starting antivirus...Done. Starting opendkim...Done. Starting mta...Done. Starting stats...Done. - imapd: /opt/zimbra/conf/imapd.crt notBefore=Sep 9 11:09:44 2024 GMT notAfter=Dec 8 11:09:43 2024 GMT subject=CN = proxy-mta.zimbra.stage.town issuer=C = US, O = Let's Encrypt, CN = R11 SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town - ldap: /opt/zimbra/conf/slapd.crt notBefore=Sep 9 11:09:44 2024 GMT notAfter=Dec 8 11:09:43 2024 GMT subject=CN = proxy-mta.zimbra.stage.town issuer=C = US, O = Let's Encrypt, CN = R11 SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town - mta: /opt/zimbra/conf/smtpd.crt notBefore=Sep 9 11:09:44 2024 GMT notAfter=Dec 8 11:09:43 2024 GMT subject=CN = proxy-mta.zimbra.stage.town issuer=C = US, O = Let's Encrypt, CN = R11 SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town - proxy: /opt/zimbra/conf/nginx.crt notBefore=Sep 9 11:09:44 2024 GMT notAfter=Dec 8 11:09:43 2024 GMT subject=CN = proxy-mta.zimbra.stage.town issuer=C = US, O = Let's Encrypt, CN = R11 SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town |
| stdout_lines |
[ "** Verifying '/tmp/ssl_stage.crt' against '/tmp/commercial_stage.key'", "Certificate '/tmp/ssl_stage.crt' and private key '/tmp/commercial_stage.key' match.", "** Verifying '/tmp/ssl_stage.crt' against '/tmp/chain_stage.crt'", "Valid certificate chain: /tmp/ssl_stage.crt: OK", "** Verifying '/tmp/ssl_stage.crt' against '/opt/zimbra/ssl/zimbra/commercial/commercial.key'", "Certificate '/tmp/ssl_stage.crt' and private key '/opt/zimbra/ssl/zimbra/commercial/commercial.key' match.", "** Verifying '/tmp/ssl_stage.crt' against '/tmp/chain_stage.crt'", "Valid certificate chain: /tmp/ssl_stage.crt: OK", "** Copying '/tmp/ssl_stage.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'", "** Copying '/tmp/chain_stage.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt'", "** Appending ca chain '/tmp/chain_stage.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'", "** Importing cert '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt' as 'zcs-user-commercial_ca' into cacerts '/opt/zimbra/common/lib/jvm/java/lib/security/cacerts'", "** NOTE: restart mailboxd to use the imported certificate.", "** Installing imapd certificate '/opt/zimbra/conf/imapd.crt' and key '/opt/zimbra/conf/imapd.key'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/imapd.crt'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/imapd.key'", "** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12'", "** Creating keystore '/opt/zimbra/conf/imapd.keystore'", "** Installing ldap certificate '/opt/zimbra/conf/slapd.crt' and key '/opt/zimbra/conf/slapd.key'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/slapd.crt'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/slapd.key'", "** Installing mta certificate '/opt/zimbra/conf/smtpd.crt' and key '/opt/zimbra/conf/smtpd.key'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/smtpd.crt'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/smtpd.key'", "** Installing proxy certificate '/opt/zimbra/conf/nginx.crt' and key '/opt/zimbra/conf/nginx.key'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/nginx.crt'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/nginx.key'", "** NOTE: restart services to use the new certificates.", "** Cleaning up 4 files from '/opt/zimbra/conf/ca'", "** Removing /opt/zimbra/conf/ca/commercial_ca_1.crt", "** Removing /opt/zimbra/conf/ca/31dfb39d.0", "** Removing /opt/zimbra/conf/ca/commercial_ca_2.crt", "** Removing /opt/zimbra/conf/ca/4042bcee.0", "** Copying CA to /opt/zimbra/conf/ca", "** Creating /opt/zimbra/conf/ca/commercial_ca_1.crt", "** Creating CA hash symlink '31dfb39d.0' -> 'commercial_ca_1.crt'", "** Creating /opt/zimbra/conf/ca/commercial_ca_2.crt", "** Creating CA hash symlink '4042bcee.0' -> 'commercial_ca_2.crt'", "Host proxy-mta.zimbra.stage.town", "\tStopping zmconfigd...Done.", "\tStopping zimlet webapp...Done.", "\tStopping zimbraAdmin webapp...Done.", "\tStopping zimbra webapp...Done.", "\tStopping service webapp...Done.", "\tStopping stats...Done.", "\tStopping mta...Done.", "\tStopping onlyoffice...Done.", "\tStopping spell...Done.", "\tStopping snmp...Done.", "\tStopping cbpolicyd...Done.", "\tStopping archiving...Done.", "\tStopping opendkim...Done.", "\tStopping amavis...Done.", "\tStopping antivirus...Done.", "\tStopping antispam...Done.", "\tStopping proxy...Done.", "\tStopping memcached...Done.", "\tStopping mailbox...Done.", "\tStopping logger...Done.", "\tStopping dnscache...Done.", "Host proxy-mta.zimbra.stage.town", "\tStarting zmconfigd...Done.", "\tStarting dnscache...Done.", "\tStarting memcached...Done.", "\tStarting proxy...Done.", "\tStarting amavis...Done.", "\tStarting antispam...Done.", "\tStarting antivirus...Done.", "\tStarting opendkim...Done.", "\tStarting mta...Done.", "\tStarting stats...Done.", "- imapd: /opt/zimbra/conf/imapd.crt", "notBefore=Sep 9 11:09:44 2024 GMT", "notAfter=Dec 8 11:09:43 2024 GMT", "subject=CN = proxy-mta.zimbra.stage.town", "issuer=C = US, O = Let's Encrypt, CN = R11", "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town", "- ldap: /opt/zimbra/conf/slapd.crt", "notBefore=Sep 9 11:09:44 2024 GMT", "notAfter=Dec 8 11:09:43 2024 GMT", "subject=CN = proxy-mta.zimbra.stage.town", "issuer=C = US, O = Let's Encrypt, CN = R11", "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town", "- mta: /opt/zimbra/conf/smtpd.crt", "notBefore=Sep 9 11:09:44 2024 GMT", "notAfter=Dec 8 11:09:43 2024 GMT", "subject=CN = proxy-mta.zimbra.stage.town", "issuer=C = US, O = Let's Encrypt, CN = R11", "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town", "- proxy: /opt/zimbra/conf/nginx.crt", "notBefore=Sep 9 11:09:44 2024 GMT", "notAfter=Dec 8 11:09:43 2024 GMT", "subject=CN = proxy-mta.zimbra.stage.town", "issuer=C = US, O = Let's Encrypt, CN = R11", "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town" ] |