Execution
Date
20 Mar 2026 12:47:47 +0000
Duration
00:01:33.33
Controller
ssh-gw-4.layershift.com
User
root
Versions
Ansible
2.16.13
ara
1.7.4 / 1.7.4
Python
3.10.10
Summary
5
Hosts
3
Tasks
15
Results
1
Plays
1
Files
0
Records
Task result details
-
StatusOK
-
Duration00:00:36.95
-
PlayPlaybook to install
-
TaskInstall certificate on host
-
Hostmbox2-stage
-
Date20 Mar 2026 12:48:30 +0000
-
Module / Actionansible.builtin.shell (/home/ssh-gateway/ansible/zimbra/install_zimbra_certificate_stage_le.yaml:36)
| Field | Value |
|---|---|
| changed |
False |
| cmd |
set -o pipefail chown zimbra.zimbra /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt su -l zimbra -c "cp -prf /tmp/commercial_stage_le.key /opt/zimbra/ssl/zimbra/commercial/commercial.key" su -l zimbra -c "zmcertmgr verifycrt comm /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt" su -l zimbra -c "zmcertmgr deploycrt comm /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt" su -l zimbra -c "zmlocalconfig -e ldap_starttls_required=true" su -l zimbra -c "zmlocalconfig -e ldap_starttls_supported=1" su -l zimbra -c "zmcontrol restart" su -l zimbra -c "zmcertmgr viewdeployedcrt" |
| delta |
0:00:36.534365 |
| end |
2026-03-20 12:48:30.564540 |
| invocation |
{ "module_args": { "_raw_params": "set -o pipefail\nchown zimbra.zimbra /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt\nsu -l zimbra -c \"cp -prf /tmp/commercial_stage_le.key /opt/zimbra/ssl/zimbra/commercial/commercial.key\"\nsu -l zimbra -c \"zmcertmgr verifycrt comm /tmp/commercial_stage_le.key /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt\"\nsu -l zimbra -c \"zmcertmgr deploycrt comm /tmp/ssl_stage_le.crt /tmp/chain_stage_le.crt\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_required=true\"\nsu -l zimbra -c \"zmlocalconfig -e ldap_starttls_supported=1\"\nsu -l zimbra -c \"zmcontrol restart\"\nsu -l zimbra -c \"zmcertmgr viewdeployedcrt\"\n", "_uses_shell": true, "argv": null, "chdir": null, "creates": null, "executable": "/bin/bash", "expand_argument_vars": true, "removes": null, "stdin": null, "stdin_add_newline": true, "strip_empty_ends": true } } |
| msg |
|
| rc |
0 |
| start |
2026-03-20 12:47:54.030175 |
| stderr |
Unable to start TLS: SSL connect attempt failed error:0A000086:SSL routines::certificate verify failed when connecting to ldap master. |
| stderr_lines |
[ "Unable to start TLS: SSL connect attempt failed error:0A000086:SSL routines::certificate verify failed when connecting to ldap master." ] |
| stdout |
** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/commercial_stage_le.key' Certificate '/tmp/ssl_stage_le.crt' and private key '/tmp/commercial_stage_le.key' match. ** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt' Valid certificate chain: /tmp/ssl_stage_le.crt: OK ** Creating directory '/opt/zimbra/ssl/zimbra/ca/newcerts' ** Touching file '/opt/zimbra/ssl/zimbra/ca/index.txt' ** Verifying '/tmp/ssl_stage_le.crt' against '/opt/zimbra/ssl/zimbra/commercial/commercial.key' Certificate '/tmp/ssl_stage_le.crt' and private key '/opt/zimbra/ssl/zimbra/commercial/commercial.key' match. ** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt' Valid certificate chain: /tmp/ssl_stage_le.crt: OK ** Copying '/tmp/ssl_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' ** Copying '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt' ** Appending ca chain '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' ** Importing cert '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt' as 'zcs-user-commercial_ca' into cacerts '/opt/zimbra/common/lib/jvm/java/lib/security/cacerts' ** NOTE: restart mailboxd to use the imported certificate. ** Installing imapd certificate '/opt/zimbra/conf/imapd.crt' and key '/opt/zimbra/conf/imapd.key' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/imapd.crt' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/imapd.key' ** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12' ** Creating keystore '/opt/zimbra/conf/imapd.keystore' ** Installing ldap certificate '/opt/zimbra/conf/slapd.crt' and key '/opt/zimbra/conf/slapd.key' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/slapd.crt' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/slapd.key' ** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12' ** Creating keystore '/opt/zimbra/mailboxd/etc/keystore' ** Installing mta certificate '/opt/zimbra/conf/smtpd.crt' and key '/opt/zimbra/conf/smtpd.key' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/smtpd.crt' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/smtpd.key' ** Installing proxy certificate '/opt/zimbra/conf/nginx.crt' and key '/opt/zimbra/conf/nginx.key' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/nginx.crt' ** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/nginx.key' ** NOTE: restart services to use the new certificates. ** Cleaning up 4 files from '/opt/zimbra/conf/ca' ** Removing /opt/zimbra/conf/ca/commercial_ca_1.crt ** Removing /opt/zimbra/conf/ca/4260b799.0 ** Removing /opt/zimbra/conf/ca/commercial_ca_2.crt ** Removing /opt/zimbra/conf/ca/4042bcee.0 ** Copying CA to /opt/zimbra/conf/ca ** Creating /opt/zimbra/conf/ca/commercial_ca_1.crt ** Creating CA hash symlink '4260b799.0' -> 'commercial_ca_1.crt' ** Creating /opt/zimbra/conf/ca/commercial_ca_2.crt ** Creating CA hash symlink '4042bcee.0' -> 'commercial_ca_2.crt' Host mbox2.zimbra.stage.town Stopping vmware-ha...Done. Stopping zmconfigd...Done. Stopping zimlet webapp...Done. Stopping zimbraAdmin webapp...Done. Stopping zimbra webapp...Done. Stopping service webapp...Done. Stopping stats...Done. Stopping onlyoffice...Done. Stopping spell...Done. Stopping snmp...Done. Stopping cbpolicyd...Done. Stopping archiving...Done. Stopping opendkim...Done. Stopping amavis...Done. Stopping antivirus...Done. Stopping antispam...Done. Stopping proxy...Done. Stopping memcached...Done. Stopping mailbox...Done. Stopping convertd...Done. Stopping logger...Done. Stopping dnscache...Done. Host mbox2.zimbra.stage.town - imapd: /opt/zimbra/conf/imapd.crt notBefore=Mar 20 11:40:48 2026 GMT notAfter=Jun 18 11:40:47 2026 GMT subject=CN=proxy-mta.zimbra.stage.town issuer=C=US, O=Let's Encrypt, CN=R13 SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town - ldap: /opt/zimbra/conf/slapd.crt notBefore=Mar 20 11:40:48 2026 GMT notAfter=Jun 18 11:40:47 2026 GMT subject=CN=proxy-mta.zimbra.stage.town issuer=C=US, O=Let's Encrypt, CN=R13 SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town - mailboxd: /opt/zimbra/mailboxd/etc/mailboxd.pem notBefore=Mar 20 11:40:48 2026 GMT notAfter=Jun 18 11:40:47 2026 GMT subject=CN=proxy-mta.zimbra.stage.town issuer=C=US, O=Let's Encrypt, CN=R13 SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town - mta: /opt/zimbra/conf/smtpd.crt notBefore=Mar 20 11:40:48 2026 GMT notAfter=Jun 18 11:40:47 2026 GMT subject=CN=proxy-mta.zimbra.stage.town issuer=C=US, O=Let's Encrypt, CN=R13 SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town - proxy: /opt/zimbra/conf/nginx.crt notBefore=Mar 20 11:40:48 2026 GMT notAfter=Jun 18 11:40:47 2026 GMT subject=CN=proxy-mta.zimbra.stage.town issuer=C=US, O=Let's Encrypt, CN=R13 SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town |
| stdout_lines |
[ "** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/commercial_stage_le.key'", "Certificate '/tmp/ssl_stage_le.crt' and private key '/tmp/commercial_stage_le.key' match.", "** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt'", "Valid certificate chain: /tmp/ssl_stage_le.crt: OK", "** Creating directory '/opt/zimbra/ssl/zimbra/ca/newcerts'", "** Touching file '/opt/zimbra/ssl/zimbra/ca/index.txt'", "** Verifying '/tmp/ssl_stage_le.crt' against '/opt/zimbra/ssl/zimbra/commercial/commercial.key'", "Certificate '/tmp/ssl_stage_le.crt' and private key '/opt/zimbra/ssl/zimbra/commercial/commercial.key' match.", "** Verifying '/tmp/ssl_stage_le.crt' against '/tmp/chain_stage_le.crt'", "Valid certificate chain: /tmp/ssl_stage_le.crt: OK", "** Copying '/tmp/ssl_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'", "** Copying '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt'", "** Appending ca chain '/tmp/chain_stage_le.crt' to '/opt/zimbra/ssl/zimbra/commercial/commercial.crt'", "** Importing cert '/opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt' as 'zcs-user-commercial_ca' into cacerts '/opt/zimbra/common/lib/jvm/java/lib/security/cacerts'", "** NOTE: restart mailboxd to use the imported certificate.", "** Installing imapd certificate '/opt/zimbra/conf/imapd.crt' and key '/opt/zimbra/conf/imapd.key'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/imapd.crt'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/imapd.key'", "** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12'", "** Creating keystore '/opt/zimbra/conf/imapd.keystore'", "** Installing ldap certificate '/opt/zimbra/conf/slapd.crt' and key '/opt/zimbra/conf/slapd.key'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/slapd.crt'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/slapd.key'", "** Creating file '/opt/zimbra/ssl/zimbra/jetty.pkcs12'", "** Creating keystore '/opt/zimbra/mailboxd/etc/keystore'", "** Installing mta certificate '/opt/zimbra/conf/smtpd.crt' and key '/opt/zimbra/conf/smtpd.key'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/smtpd.crt'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/smtpd.key'", "** Installing proxy certificate '/opt/zimbra/conf/nginx.crt' and key '/opt/zimbra/conf/nginx.key'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.crt' to '/opt/zimbra/conf/nginx.crt'", "** Copying '/opt/zimbra/ssl/zimbra/commercial/commercial.key' to '/opt/zimbra/conf/nginx.key'", "** NOTE: restart services to use the new certificates.", "** Cleaning up 4 files from '/opt/zimbra/conf/ca'", "** Removing /opt/zimbra/conf/ca/commercial_ca_1.crt", "** Removing /opt/zimbra/conf/ca/4260b799.0", "** Removing /opt/zimbra/conf/ca/commercial_ca_2.crt", "** Removing /opt/zimbra/conf/ca/4042bcee.0", "** Copying CA to /opt/zimbra/conf/ca", "** Creating /opt/zimbra/conf/ca/commercial_ca_1.crt", "** Creating CA hash symlink '4260b799.0' -> 'commercial_ca_1.crt'", "** Creating /opt/zimbra/conf/ca/commercial_ca_2.crt", "** Creating CA hash symlink '4042bcee.0' -> 'commercial_ca_2.crt'", "Host mbox2.zimbra.stage.town", "\tStopping vmware-ha...Done.", "\tStopping zmconfigd...Done.", "\tStopping zimlet webapp...Done.", "\tStopping zimbraAdmin webapp...Done.", "\tStopping zimbra webapp...Done.", "\tStopping service webapp...Done.", "\tStopping stats...Done.", "\tStopping onlyoffice...Done.", "\tStopping spell...Done.", "\tStopping snmp...Done.", "\tStopping cbpolicyd...Done.", "\tStopping archiving...Done.", "\tStopping opendkim...Done.", "\tStopping amavis...Done.", "\tStopping antivirus...Done.", "\tStopping antispam...Done.", "\tStopping proxy...Done.", "\tStopping memcached...Done.", "\tStopping mailbox...Done.", "\tStopping convertd...Done.", "\tStopping logger...Done.", "\tStopping dnscache...Done.", "Host mbox2.zimbra.stage.town", "- imapd: /opt/zimbra/conf/imapd.crt", "notBefore=Mar 20 11:40:48 2026 GMT", "notAfter=Jun 18 11:40:47 2026 GMT", "subject=CN=proxy-mta.zimbra.stage.town", "issuer=C=US, O=Let's Encrypt, CN=R13", "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town", "- ldap: /opt/zimbra/conf/slapd.crt", "notBefore=Mar 20 11:40:48 2026 GMT", "notAfter=Jun 18 11:40:47 2026 GMT", "subject=CN=proxy-mta.zimbra.stage.town", "issuer=C=US, O=Let's Encrypt, CN=R13", "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town", "- mailboxd: /opt/zimbra/mailboxd/etc/mailboxd.pem", "notBefore=Mar 20 11:40:48 2026 GMT", "notAfter=Jun 18 11:40:47 2026 GMT", "subject=CN=proxy-mta.zimbra.stage.town", "issuer=C=US, O=Let's Encrypt, CN=R13", "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town", "- mta: /opt/zimbra/conf/smtpd.crt", "notBefore=Mar 20 11:40:48 2026 GMT", "notAfter=Jun 18 11:40:47 2026 GMT", "subject=CN=proxy-mta.zimbra.stage.town", "issuer=C=US, O=Let's Encrypt, CN=R13", "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town", "- proxy: /opt/zimbra/conf/nginx.crt", "notBefore=Mar 20 11:40:48 2026 GMT", "notAfter=Jun 18 11:40:47 2026 GMT", "subject=CN=proxy-mta.zimbra.stage.town", "issuer=C=US, O=Let's Encrypt, CN=R13", "SubjectAltName=ldap1.zimbra.stage.town, ldap2.zimbra.stage.town, mbox1.zimbra.stage.town, mbox2.zimbra.stage.town, proxy-mta.zimbra.stage.town, zimbra.stage.town" ] |