Score:0

Renewing cert on Zimbra mail server broke Outlook

ke flag

all.

Strange problem. We renewed our wildcard cert on the Zimbra email server over the weekend, and on Monday several users reported their Outlook no longer connected to the server (fortunately the web client still worked for them).

Looking at the Zimbra logs on the affected machines, I am seeing this:

### WARNING ### Failed to obtain server cert. Error: 12019 @   Connection.cpp#1869[SaveCertAndCalcFingerprint()]
### ERROR ### Internal error loading the SSL libraries @ Connection.cpp#1961[Handle_WINHTTP_CALLBACK_STATUS_SECURE_FAILURE()]
### WARNING ### Detected asynchronous WINHTTP_CALLBACK_STATUS_FLAG_SECURITY_CHANNEL_ERROR -> converting to ERROR_WINHTTP_CANNOT_CONNECT @ Connection.cpp#7220[WrapWinHttpSendRequest()]
### WARNING ### Failed to authenticate @ SessionData.cpp#1993[UserSession::Auth()]
### WARNING ### Failed to determine server version, hr: 0x80040115 @ SessionData.cpp#3048[UserSession::IsServerVersionSupported()]
### ERROR ### unable to establish server connection. hr: 80040115 @ ZimbraXPLogon.cpp#855[ZimbraXPLogon::SubmitMessage()]
### ERROR ### Caught 'MailboxUnreachableException: Unable to connect.' @ ZimbraXPLogon.cpp#1288[ZimbraXPLogon::SubmitMessage()]

This only affects 6 people out of 400 atm, so it does not appear to be an issue central to the server. I re-deployed the cert ensuring that the intermediates and root CA were also included. These users are using the same version of Zimbra Connector for Outlook, and system time is correct (in case that was generating the error loading the SSL libs error).

Checking the firewall, I can see that it is not preventing connections from the users with this issue. I wonder if there is some caching that can be cleared...the previous certificate would have expired on the Monday after I deployed the renewed certs.

Has anyone seen anything similar?

Romeo Ninov avatar
in flag
Do these problematic users use different OS, did not apply updates, different version of outlook?
AaplMike avatar
ke flag
No, the same. I'm guessing the security level on some are higher, hence the fact that only 6 are having the problem and the rest are not. I'm not a Windows guy and these are Win10 machines.
Score:1
ke flag

Renewed chain cert did not include the root CA. Weird but some Win10 Outlook had no problem with that, about 6 refused to connect. I tacked on the root ca cert in the chain cert and the issue went away.

I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.