Execution
Date 30 Dec 2024 13:17:56 +0000
Duration 00:02:18.83
Controller ssh-gw-4.layershift.com
User root
Versions
Ansible 2.16.11
ara 1.7.2 / 1.7.2
Python 3.10.10
Summary
5 Hosts
3 Tasks
15 Results
1 Plays
1 Files
0 Records

Task result details

  • Status
    OK
  • Duration
    00:00:49.83
  • Play
    Playbook to install zimbra wildcard certificate on cluster
  • Task
    Install certificate on host

Field Value
changed
False
cmd
set -o pipefail
chown zimbra.zimbra /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt
su -l zimbra -c "cp -prf /tmp/commercial_stage_le.key /opt/zimbra/ssl/zimbra/commercial/commercial.key"
su -l zimbra -c "zmcertmgr verifycrt comm /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt"
su -l zimbra -c "zmcertmgr deploycrt comm /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt"
su -l zimbra -c "zmlocalconfig -e ldap_starttls_required=true"
su -l zimbra -c "zmlocalconfig -e ldap_starttls_supported=1"
su -l zimbra -c "zmcontrol restart"
su -l zimbra -c "zmcertmgr viewdeployedcrt"
delta
0:00:49.385423
end
2024-12-30 13:18:50.923073
invocation
{
    "module_args": {
        "_raw_params": "set -o pipefail\nchown zimbra.zimbra /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt\nsu -l zimbra -c \"cp -prf /tmp/commercial_stage_le.key /opt/zimbra/ssl/zimbra/commercial/commercial.key\"\nsu -l zimbra -c \"zmcertmgr verifycrt comm /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt\"\nsu -l zimbra -c \"zmcertmgr deploycrt comm /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_required=true\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_supported=1\"\nsu -l zimbra -c \"zmcontrol restart\"\nsu -l zimbra -c \"zmcertmgr viewdeployedcrt\"\n",
        "_uses_shell": true,
        "argv": null,
        "chdir": null,
        "creates": null,
        "executable": "/bin/bash",
        "expand_argument_vars": true,
        "removes": null,
        "stdin": null,
        "stdin_add_newline": true,
        "strip_empty_ends": true
    }
}
msg

rc
0
start
2024-12-30 13:18:01.537650
stderr

stderr_lines
[]
stdout
** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/commercial_stage_le.key'
Certificate '/tmp/ssl_stage_le.crt' and private key '/tmp/commercial_stage_le.key' match.
** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt'
Valid certificate chain: /tmp/ssl_stage_le.crt: OK
** Creating directory '/opt/zimbra/ssl/zimbra/ca/newcerts'
** Touching file '/opt/zimbra/ssl/zimbra/ca/index.txt'
** Verifying '/tmp/ssl_stage_le.crt' against '/opt/zimbra/ssl/zimbra/commercial/commercial.key'
Certificate '/tmp/ssl_stage_le.crt' and private key '/opt/zimbra/ssl/zimbra/commercial/commercial.key' match.
** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt'
Valid certificate chain: /tmp/ssl_stage_le.crt: OK
** Copying '/tmp/ssl_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'
** Copying '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt'
** Appending ca chain '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'
** Importing cert '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt' as 'zcs-user-commercial_ca' into cacerts '/opt/zimbra/common/lib/jvm/java/lib/security/cacerts'
** NOTE: restart mailboxd to use the imported certificate.
** Saving config key 'zimbraSSLCertificate' via zmprov modifyServer ldap1.zimbra.stage.town...ok
** Saving config key 'zimbraSSLPrivateKey' via zmprov modifyServer ldap1.zimbra.stage.town...ok
** Installing imapd certificate '/opt/zimbra/conf/imapd.crt' and key '/opt/zimbra/conf/imapd.key'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/imapd.crt'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/imapd.key'
** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12'
** Creating keystore '/opt/zimbra/conf/imapd.keystore'
** Installing ldap certificate '/opt/zimbra/conf/slapd.crt' and key '/opt/zimbra/conf/slapd.key'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/slapd.crt'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/slapd.key'
** Installing mta certificate '/opt/zimbra/conf/smtpd.crt' and key '/opt/zimbra/conf/smtpd.key'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/smtpd.crt'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/smtpd.key'
** Installing proxy certificate '/opt/zimbra/conf/nginx.crt' and key '/opt/zimbra/conf/nginx.key'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/nginx.crt'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/nginx.key'
** NOTE: restart services to use the new certificates.
** Cleaning up 3 files from '/opt/zimbra/conf/ca'
** Removing /opt/zimbra/conf/ca/ca.key
** Removing /opt/zimbra/conf/ca/ca.pem
** Removing /opt/zimbra/conf/ca/4b0006c8.0
** Copying CA to /opt/zimbra/conf/ca
** Creating /opt/zimbra/conf/ca/commercial_ca_1.crt
** Creating CA hash symlink 'aa578057.0' -> 'commercial_ca_1.crt'
** Creating /opt/zimbra/conf/ca/commercial_ca_2.crt
** Creating CA hash symlink '4042bcee.0' -> 'commercial_ca_2.crt'
Host ldap1.zimbra.stage.town
	Stopping zmconfigd...Done.
	Stopping zimlet webapp...Done.
	Stopping zimbraAdmin webapp...Done.
	Stopping zimbra webapp...Done.
	Stopping service webapp...Done.
	Stopping stats...Done.
	Stopping onlyoffice...Done.
	Stopping spell...Done.
	Stopping snmp...Done.
	Stopping cbpolicyd...Done.
	Stopping archiving...Done.
	Stopping opendkim...Done.
	Stopping amavis...Done.
	Stopping antivirus...Done.
	Stopping antispam...Done.
	Stopping proxy...Done.
	Stopping memcached...Done.
	Stopping mailbox...Done.
	Stopping logger...Done.
	Stopping dnscache...Done.
	Stopping ldap...Done.
Host ldap1.zimbra.stage.town
	Starting ldap...Done.
	Starting zmconfigd...Done.
	Starting stats...Done.
- imapd: /opt/zimbra/conf/imapd.crt
notBefore=Dec 23 12:31:18 2024 GMT
notAfter=Mar 23 12:31:17 2025 GMT
subject=CN = proxy-mta.zimbra.stage.town
issuer=C = US, O = Let's Encrypt, CN = R10
SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town
- ldap: /opt/zimbra/conf/slapd.crt
notBefore=Dec 23 12:31:18 2024 GMT
notAfter=Mar 23 12:31:17 2025 GMT
subject=CN = proxy-mta.zimbra.stage.town
issuer=C = US, O = Let's Encrypt, CN = R10
SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town
- mta: /opt/zimbra/conf/smtpd.crt
notBefore=Dec 23 12:31:18 2024 GMT
notAfter=Mar 23 12:31:17 2025 GMT
subject=CN = proxy-mta.zimbra.stage.town
issuer=C = US, O = Let's Encrypt, CN = R10
SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town
- proxy: /opt/zimbra/conf/nginx.crt
notBefore=Dec 23 12:31:18 2024 GMT
notAfter=Mar 23 12:31:17 2025 GMT
subject=CN = proxy-mta.zimbra.stage.town
issuer=C = US, O = Let's Encrypt, CN = R10
SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town
stdout_lines
[
    "** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/commercial_stage_le.key'",
    "Certificate '/tmp/ssl_stage_le.crt' and private key '/tmp/commercial_stage_le.key' match.",
    "** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt'",
    "Valid certificate chain: /tmp/ssl_stage_le.crt: OK",
    "** Creating directory '/opt/zimbra/ssl/zimbra/ca/newcerts'",
    "** Touching file '/opt/zimbra/ssl/zimbra/ca/index.txt'",
    "** Verifying '/tmp/ssl_stage_le.crt' against '/opt/zimbra/ssl/zimbra/commercial/commercial.key'",
    "Certificate '/tmp/ssl_stage_le.crt' and private key '/opt/zimbra/ssl/zimbra/commercial/commercial.key' match.",
    "** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt'",
    "Valid certificate chain: /tmp/ssl_stage_le.crt: OK",
    "** Copying '/tmp/ssl_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'",
    "** Copying '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt'",
    "** Appending ca chain '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'",
    "** Importing cert '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt' as 'zcs-user-commercial_ca' into cacerts '/opt/zimbra/common/lib/jvm/java/lib/security/cacerts'",
    "** NOTE: restart mailboxd to use the imported certificate.",
    "** Saving config key 'zimbraSSLCertificate' via zmprov modifyServer ldap1.zimbra.stage.town...ok",
    "** Saving config key 'zimbraSSLPrivateKey' via zmprov modifyServer ldap1.zimbra.stage.town...ok",
    "** Installing imapd certificate '/opt/zimbra/conf/imapd.crt' and key '/opt/zimbra/conf/imapd.key'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/imapd.crt'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/imapd.key'",
    "** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12'",
    "** Creating keystore '/opt/zimbra/conf/imapd.keystore'",
    "** Installing ldap certificate '/opt/zimbra/conf/slapd.crt' and key '/opt/zimbra/conf/slapd.key'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/slapd.crt'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/slapd.key'",
    "** Installing mta certificate '/opt/zimbra/conf/smtpd.crt' and key '/opt/zimbra/conf/smtpd.key'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/smtpd.crt'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/smtpd.key'",
    "** Installing proxy certificate '/opt/zimbra/conf/nginx.crt' and key '/opt/zimbra/conf/nginx.key'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/nginx.crt'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/nginx.key'",
    "** NOTE: restart services to use the new certificates.",
    "** Cleaning up 3 files from '/opt/zimbra/conf/ca'",
    "** Removing /opt/zimbra/conf/ca/ca.key",
    "** Removing /opt/zimbra/conf/ca/ca.pem",
    "** Removing /opt/zimbra/conf/ca/4b0006c8.0",
    "** Copying CA to /opt/zimbra/conf/ca",
    "** Creating /opt/zimbra/conf/ca/commercial_ca_1.crt",
    "** Creating CA hash symlink 'aa578057.0' -> 'commercial_ca_1.crt'",
    "** Creating /opt/zimbra/conf/ca/commercial_ca_2.crt",
    "** Creating CA hash symlink '4042bcee.0' -> 'commercial_ca_2.crt'",
    "Host ldap1.zimbra.stage.town",
    "\tStopping zmconfigd...Done.",
    "\tStopping zimlet webapp...Done.",
    "\tStopping zimbraAdmin webapp...Done.",
    "\tStopping zimbra webapp...Done.",
    "\tStopping service webapp...Done.",
    "\tStopping stats...Done.",
    "\tStopping onlyoffice...Done.",
    "\tStopping spell...Done.",
    "\tStopping snmp...Done.",
    "\tStopping cbpolicyd...Done.",
    "\tStopping archiving...Done.",
    "\tStopping opendkim...Done.",
    "\tStopping amavis...Done.",
    "\tStopping antivirus...Done.",
    "\tStopping antispam...Done.",
    "\tStopping proxy...Done.",
    "\tStopping memcached...Done.",
    "\tStopping mailbox...Done.",
    "\tStopping logger...Done.",
    "\tStopping dnscache...Done.",
    "\tStopping ldap...Done.",
    "Host ldap1.zimbra.stage.town",
    "\tStarting ldap...Done.",
    "\tStarting zmconfigd...Done.",
    "\tStarting stats...Done.",
    "- imapd: /opt/zimbra/conf/imapd.crt",
    "notBefore=Dec 23 12:31:18 2024 GMT",
    "notAfter=Mar 23 12:31:17 2025 GMT",
    "subject=CN = proxy-mta.zimbra.stage.town",
    "issuer=C = US, O = Let's Encrypt, CN = R10",
    "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town",
    "- ldap: /opt/zimbra/conf/slapd.crt",
    "notBefore=Dec 23 12:31:18 2024 GMT",
    "notAfter=Mar 23 12:31:17 2025 GMT",
    "subject=CN = proxy-mta.zimbra.stage.town",
    "issuer=C = US, O = Let's Encrypt, CN = R10",
    "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town",
    "- mta: /opt/zimbra/conf/smtpd.crt",
    "notBefore=Dec 23 12:31:18 2024 GMT",
    "notAfter=Mar 23 12:31:17 2025 GMT",
    "subject=CN = proxy-mta.zimbra.stage.town",
    "issuer=C = US, O = Let's Encrypt, CN = R10",
    "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town",
    "- proxy: /opt/zimbra/conf/nginx.crt",
    "notBefore=Dec 23 12:31:18 2024 GMT",
    "notAfter=Mar 23 12:31:17 2025 GMT",
    "subject=CN = proxy-mta.zimbra.stage.town",
    "issuer=C = US, O = Let's Encrypt, CN = R10",
    "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town"
]