Execution
Date 29 Aug 2025 11:45:39 +0100
Duration 00:01:34.25
Controller ssh-gw-4.layershift.com
User root
Versions
Ansible 2.16.11
ara 1.7.3 / 1.7.3
Python 3.10.10
Summary
5 Hosts
3 Tasks
15 Results
1 Plays
1 Files
0 Records

Task result details

  • Status
    OK
  • Duration
    00:01:16.82
  • Play
    Playbook to install
  • Task
    Install certificate on host

Field Value
changed
False
cmd
set -o pipefail
chown zimbra.zimbra /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt
su -l zimbra -c "cp -prf /tmp/commercial_stage_le.key /opt/zimbra/ssl/zimbra/commercial/commercial.key"
su -l zimbra -c "zmcertmgr verifycrt comm /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt"
su -l zimbra -c "zmcertmgr deploycrt comm /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt"
su -l zimbra -c "zmlocalconfig -e ldap_starttls_required=true"
su -l zimbra -c "zmlocalconfig -e ldap_starttls_supported=1"
su -l zimbra -c "zmcontrol restart"
su -l zimbra -c "zmcertmgr viewdeployedcrt"
delta
0:01:16.347823
end
2025-08-29 10:47:02.061431
invocation
{
    "module_args": {
        "_raw_params": "set -o pipefail\nchown zimbra.zimbra /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt\nsu -l zimbra -c \"cp -prf /tmp/commercial_stage_le.key /opt/zimbra/ssl/zimbra/commercial/commercial.key\"\nsu -l zimbra -c \"zmcertmgr verifycrt comm /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt\"\nsu -l zimbra -c \"zmcertmgr deploycrt comm /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_required=true\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_supported=1\"\nsu -l zimbra -c \"zmcontrol restart\"\nsu -l zimbra -c \"zmcertmgr viewdeployedcrt\"\n",
        "_uses_shell": true,
        "argv": null,
        "chdir": null,
        "creates": null,
        "executable": "/bin/bash",
        "expand_argument_vars": true,
        "removes": null,
        "stdin": null,
        "stdin_add_newline": true,
        "strip_empty_ends": true
    }
}
msg

rc
0
start
2025-08-29 10:45:45.713608
stderr
Connect: Unable to determine enabled services from ldap.
Enabled services read from cache. Service list may be inaccurate.
stderr_lines
[
    "Connect: Unable to determine enabled services from ldap.",
    "Enabled services read from cache. Service list may be inaccurate."
]
stdout
** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/commercial_stage_le.key'
Certificate '/tmp/ssl_stage_le.crt' and private key '/tmp/commercial_stage_le.key' match.
** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt'
Valid certificate chain: /tmp/ssl_stage_le.crt: OK
** Creating directory '/opt/zimbra/ssl/zimbra/ca/newcerts'
** Touching file '/opt/zimbra/ssl/zimbra/ca/index.txt'
** Verifying '/tmp/ssl_stage_le.crt' against '/opt/zimbra/ssl/zimbra/commercial/commercial.key'
Certificate '/tmp/ssl_stage_le.crt' and private key '/opt/zimbra/ssl/zimbra/commercial/commercial.key' match.
** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt'
Valid certificate chain: /tmp/ssl_stage_le.crt: OK
** Copying '/tmp/ssl_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'
** Copying '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt'
** Appending ca chain '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'
** Importing cert '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt' as 'zcs-user-commercial_ca' into cacerts '/opt/zimbra/common/lib/jvm/java/lib/security/cacerts'
** NOTE: restart mailboxd to use the imported certificate.
** Installing imapd certificate '/opt/zimbra/conf/imapd.crt' and key '/opt/zimbra/conf/imapd.key'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/imapd.crt'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/imapd.key'
** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12'
** Creating keystore '/opt/zimbra/conf/imapd.keystore'
** Installing ldap certificate '/opt/zimbra/conf/slapd.crt' and key '/opt/zimbra/conf/slapd.key'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/slapd.crt'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/slapd.key'
** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12'
** Creating keystore '/opt/zimbra/mailboxd/etc/keystore'
** Installing mta certificate '/opt/zimbra/conf/smtpd.crt' and key '/opt/zimbra/conf/smtpd.key'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/smtpd.crt'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/smtpd.key'
** Installing proxy certificate '/opt/zimbra/conf/nginx.crt' and key '/opt/zimbra/conf/nginx.key'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/nginx.crt'
** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/nginx.key'
** NOTE: restart services to use the new certificates.
** Cleaning up 4 files from '/opt/zimbra/conf/ca'
** Removing /opt/zimbra/conf/ca/commercial_ca_1.crt
** Removing /opt/zimbra/conf/ca/31dfb39d.0
** Removing /opt/zimbra/conf/ca/commercial_ca_2.crt
** Removing /opt/zimbra/conf/ca/4042bcee.0
** Copying CA to /opt/zimbra/conf/ca
** Creating /opt/zimbra/conf/ca/commercial_ca_1.crt
** Creating CA hash symlink '4260b799.0' -> 'commercial_ca_1.crt'
** Creating /opt/zimbra/conf/ca/commercial_ca_2.crt
** Creating CA hash symlink '4042bcee.0' -> 'commercial_ca_2.crt'
Host mbox2.zimbra.stage.town
	Stopping vmware-ha...Done.
	Stopping zmconfigd...Done.
	Stopping zimlet webapp...Done.
	Stopping zimbraAdmin webapp...Done.
	Stopping zimbra webapp...Done.
	Stopping service webapp...Done.
	Stopping stats...Done.
	Stopping onlyoffice...Done.
	Stopping spell...Done.
	Stopping snmp...Done.
	Stopping cbpolicyd...Done.
	Stopping archiving...Done.
	Stopping opendkim...Done.
	Stopping amavis...Done.
	Stopping antivirus...Done.
	Stopping antispam...Done.
	Stopping proxy...Done.
	Stopping memcached...Done.
	Stopping mailbox...Done.
	Stopping convertd...Done.
	Stopping logger...Done.
	Stopping dnscache...Done.
Host mbox2.zimbra.stage.town
	Starting zmconfigd...Done.
	Starting logger...Done.
	Starting convertd...Done.
	Starting mailbox...Done.
	Starting spell...Done.
	Starting stats...Done.
	Starting service webapp...Done.
	Starting zimbra webapp...Done.
	Starting zimbraAdmin webapp...Done.
	Starting zimlet webapp...Done.
- imapd: /opt/zimbra/conf/imapd.crt
notBefore=Aug 29 07:26:43 2025 GMT
notAfter=Nov 27 07:26:42 2025 GMT
subject=CN = proxy-mta.zimbra.stage.town
issuer=C = US, O = Let's Encrypt, CN = R13
SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town
- ldap: /opt/zimbra/conf/slapd.crt
notBefore=Aug 29 07:26:43 2025 GMT
notAfter=Nov 27 07:26:42 2025 GMT
subject=CN = proxy-mta.zimbra.stage.town
issuer=C = US, O = Let's Encrypt, CN = R13
SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town
- mailboxd: /opt/zimbra/mailboxd/etc/mailboxd.pem
notBefore=Aug 29 07:26:43 2025 GMT
notAfter=Nov 27 07:26:42 2025 GMT
subject=CN = proxy-mta.zimbra.stage.town
issuer=C = US, O = Let's Encrypt, CN = R13
SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town
- mta: /opt/zimbra/conf/smtpd.crt
notBefore=Aug 29 07:26:43 2025 GMT
notAfter=Nov 27 07:26:42 2025 GMT
subject=CN = proxy-mta.zimbra.stage.town
issuer=C = US, O = Let's Encrypt, CN = R13
SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town
- proxy: /opt/zimbra/conf/nginx.crt
notBefore=Aug 29 07:26:43 2025 GMT
notAfter=Nov 27 07:26:42 2025 GMT
subject=CN = proxy-mta.zimbra.stage.town
issuer=C = US, O = Let's Encrypt, CN = R13
SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town
stdout_lines
[
    "** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/commercial_stage_le.key'",
    "Certificate '/tmp/ssl_stage_le.crt' and private key '/tmp/commercial_stage_le.key' match.",
    "** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt'",
    "Valid certificate chain: /tmp/ssl_stage_le.crt: OK",
    "** Creating directory '/opt/zimbra/ssl/zimbra/ca/newcerts'",
    "** Touching file '/opt/zimbra/ssl/zimbra/ca/index.txt'",
    "** Verifying '/tmp/ssl_stage_le.crt' against '/opt/zimbra/ssl/zimbra/commercial/commercial.key'",
    "Certificate '/tmp/ssl_stage_le.crt' and private key '/opt/zimbra/ssl/zimbra/commercial/commercial.key' match.",
    "** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt'",
    "Valid certificate chain: /tmp/ssl_stage_le.crt: OK",
    "** Copying '/tmp/ssl_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'",
    "** Copying '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt'",
    "** Appending ca chain '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'",
    "** Importing cert '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt' as 'zcs-user-commercial_ca' into cacerts '/opt/zimbra/common/lib/jvm/java/lib/security/cacerts'",
    "** NOTE: restart mailboxd to use the imported certificate.",
    "** Installing imapd certificate '/opt/zimbra/conf/imapd.crt' and key '/opt/zimbra/conf/imapd.key'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/imapd.crt'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/imapd.key'",
    "** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12'",
    "** Creating keystore '/opt/zimbra/conf/imapd.keystore'",
    "** Installing ldap certificate '/opt/zimbra/conf/slapd.crt' and key '/opt/zimbra/conf/slapd.key'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/slapd.crt'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/slapd.key'",
    "** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12'",
    "** Creating keystore '/opt/zimbra/mailboxd/etc/keystore'",
    "** Installing mta certificate '/opt/zimbra/conf/smtpd.crt' and key '/opt/zimbra/conf/smtpd.key'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/smtpd.crt'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/smtpd.key'",
    "** Installing proxy certificate '/opt/zimbra/conf/nginx.crt' and key '/opt/zimbra/conf/nginx.key'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/nginx.crt'",
    "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/nginx.key'",
    "** NOTE: restart services to use the new certificates.",
    "** Cleaning up 4 files from '/opt/zimbra/conf/ca'",
    "** Removing /opt/zimbra/conf/ca/commercial_ca_1.crt",
    "** Removing /opt/zimbra/conf/ca/31dfb39d.0",
    "** Removing /opt/zimbra/conf/ca/commercial_ca_2.crt",
    "** Removing /opt/zimbra/conf/ca/4042bcee.0",
    "** Copying CA to /opt/zimbra/conf/ca",
    "** Creating /opt/zimbra/conf/ca/commercial_ca_1.crt",
    "** Creating CA hash symlink '4260b799.0' -> 'commercial_ca_1.crt'",
    "** Creating /opt/zimbra/conf/ca/commercial_ca_2.crt",
    "** Creating CA hash symlink '4042bcee.0' -> 'commercial_ca_2.crt'",
    "Host mbox2.zimbra.stage.town",
    "\tStopping vmware-ha...Done.",
    "\tStopping zmconfigd...Done.",
    "\tStopping zimlet webapp...Done.",
    "\tStopping zimbraAdmin webapp...Done.",
    "\tStopping zimbra webapp...Done.",
    "\tStopping service webapp...Done.",
    "\tStopping stats...Done.",
    "\tStopping onlyoffice...Done.",
    "\tStopping spell...Done.",
    "\tStopping snmp...Done.",
    "\tStopping cbpolicyd...Done.",
    "\tStopping archiving...Done.",
    "\tStopping opendkim...Done.",
    "\tStopping amavis...Done.",
    "\tStopping antivirus...Done.",
    "\tStopping antispam...Done.",
    "\tStopping proxy...Done.",
    "\tStopping memcached...Done.",
    "\tStopping mailbox...Done.",
    "\tStopping convertd...Done.",
    "\tStopping logger...Done.",
    "\tStopping dnscache...Done.",
    "Host mbox2.zimbra.stage.town",
    "\tStarting zmconfigd...Done.",
    "\tStarting logger...Done.",
    "\tStarting convertd...Done.",
    "\tStarting mailbox...Done.",
    "\tStarting spell...Done.",
    "\tStarting stats...Done.",
    "\tStarting service webapp...Done.",
    "\tStarting zimbra webapp...Done.",
    "\tStarting zimbraAdmin webapp...Done.",
    "\tStarting zimlet webapp...Done.",
    "- imapd: /opt/zimbra/conf/imapd.crt",
    "notBefore=Aug 29 07:26:43 2025 GMT",
    "notAfter=Nov 27 07:26:42 2025 GMT",
    "subject=CN = proxy-mta.zimbra.stage.town",
    "issuer=C = US, O = Let's Encrypt, CN = R13",
    "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town",
    "- ldap: /opt/zimbra/conf/slapd.crt",
    "notBefore=Aug 29 07:26:43 2025 GMT",
    "notAfter=Nov 27 07:26:42 2025 GMT",
    "subject=CN = proxy-mta.zimbra.stage.town",
    "issuer=C = US, O = Let's Encrypt, CN = R13",
    "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town",
    "- mailboxd: /opt/zimbra/mailboxd/etc/mailboxd.pem",
    "notBefore=Aug 29 07:26:43 2025 GMT",
    "notAfter=Nov 27 07:26:42 2025 GMT",
    "subject=CN = proxy-mta.zimbra.stage.town",
    "issuer=C = US, O = Let's Encrypt, CN = R13",
    "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town",
    "- mta: /opt/zimbra/conf/smtpd.crt",
    "notBefore=Aug 29 07:26:43 2025 GMT",
    "notAfter=Nov 27 07:26:42 2025 GMT",
    "subject=CN = proxy-mta.zimbra.stage.town",
    "issuer=C = US, O = Let's Encrypt, CN = R13",
    "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town",
    "- proxy: /opt/zimbra/conf/nginx.crt",
    "notBefore=Aug 29 07:26:43 2025 GMT",
    "notAfter=Nov 27 07:26:42 2025 GMT",
    "subject=CN = proxy-mta.zimbra.stage.town",
    "issuer=C = US, O = Let's Encrypt, CN = R13",
    "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town"
]