{"id":38313,"date":"2019-10-31T22:22:55","date_gmt":"2019-10-31T19:22:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/kak-pravilno-nastroit-sni-v-zimbra-ose\/"},"modified":"2019-10-31T22:22:55","modified_gmt":"2019-10-31T19:22:55","slug":"kak-pravilno-nastroit-sni-v-zimbra-ose","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-pravilno-nastroit-sni-v-zimbra-ose","title":{"rendered":"How to Properly Configure SNI in Zimbra OSE?","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>At the beginning of the 21st century, resources such as IPv4 addresses were on the brink of depletion. As early as 2011, IANA allocated the last five remaining \/8 blocks from its address pool to regional internet registries, and by 2017, these addresses were exhausted as well. The response to the catastrophic shortage of IPv4 addresses was not only the emergence of the IPv6 protocol but also the SNI technology, which allowed hosting a vast number of websites on a single IPv4 address. The essence of SNI is that this extension allows clients to communicate the name of the website they wish to connect to during the handshake process. This enables the server to store multiple certificates, thus allowing numerous domains to operate on a single IP address. The SNI technology has become particularly sought after among SaaS providers for businesses, enabling them to host practically unlimited domain names without being constrained by the number of required IPv4 addresses. Let\u2019s find out how to implement SNI support in Zimbra Collaboration Suite Open-Source Edition.<\/p>\n<p><img decoding=\"async\" alt=\"How to Properly Configure SNI in Zimbra OSE?\" src=\"\/wp-content\/uploads\/2019\/09\/7f6e085f14e93e97a7b013dad4d6fe14.jpeg\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p>SNI works with all current and supported versions of Zimbra OSE. If your Zimbra Open-Source operates on a multi-server infrastructure, you will need to perform all the following actions on the node with the Zimbra Proxy server installed. Additionally, you will require matching pairs of certificate+key, as well as trusted certificate chains from your certificate authority for each of the domains you wish to host on your IPv4 address. Please note that the overwhelming majority of errors encountered when configuring SNI in Zimbra OSE stem from incorrect certificate files. Therefore, we recommend carefully checking everything before their actual installation.<\/p>\n<p>First and foremost, in order for SNI to work properly, you need to enter the command <b>zmprov mcf zimbraReverseProxySNIEnabled TRUE<\/b> on the node with the Zimbra Proxy server, and then restart the Proxy service using the command\u00a0<b>zmproxyctl restart<\/b>.<\/p>\n<p>We will start by creating a domain name. For example, we will choose the domain <b>company.ru<\/b> After the domain is created, let's decide on the Zimbra virtual host name and the virtual IP address. Note that the Zimbra virtual host name must match the name the user will enter in the browser's address bar to access the domain and also correspond to the name specified in the certificate. For example, let's take the name of the Zimbra virtual host as <b>mail.company.ru<\/b>, and for the virtual IPv4 address, we will use the address <b>1.2.3.4<\/b>.<\/p>\n<p>After that, simply enter the command <b>zmprov md company.ru zimbraVirtualHostName mail.company.ru zimbraVirtualIPAddress 1.2.3.4<\/b>, to bind the Zimbra virtual host to the virtual <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/lir\/ipv4\/\"   title=\"IP address\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"588\">IP address<\/a>. Please note that if the server is behind NAT or a firewall, you need to ensure that all requests to the domain go to the assigned external IP address rather than its address on the local network.<\/p>\n<p>Once everything is done, you just need to check and prepare the domain certificates for installation, and then install them.<\/p>\n<p>If the certificate issuance for the domain was successful, you should have three files with certificates: two of them consist of chains of certificates from your certification authority, and one is the actual domain certificate. Additionally, you should have a file with the key you used to obtain the certificate. Create a separate folder <b>\/tmp\/company.ru<\/b> and place all existing key and certificate files there. In the end, it should look something like this:<\/p>\n<pre><code class=\"bash\">ls \/tmp\/company.ru\ncompany.ru.key\n company.ru.crt\n company.ru.root.crt\n company.ru.intermediate.crt<\/code><\/pre>\n<p>\nAfter that, let's combine the certificate chains into a single file using the command <b>cat company.ru.root.crt company.ru.intermediate.crt &gt;&gt; company.ru_ca.crt<\/b> and make sure that everything is fine with the certificates using the command <b>\/opt\/zimbra\/bin\/zmcertmgr verifycrt comm \/tmp\/company.ru\/company.ru.key \/tmp\/company.ru\/company.ru.crt \/tmp\/company.ru\/company.ru_ca.crt<\/b>. Once the check of the certificates and key is successful, you can proceed to install them.<\/p>\n<p>To begin the installation, first combine the domain certificate and the trusted chains from the certification authorities into one file. This is done using a command like\u00a0<b>cat company.ru.crt company.ru_ca.crt &gt;&gt; company.ru.bundle<\/b>. After that, you need to execute a command to write all certificates and keys into LDAP: <b>\/opt\/zimbra\/libexec\/zmdomaincertmgr savecrt company.ru company.ru.bundle company.ru.key<\/b>, and then install the certificates using the command. <b>\/opt\/zimbra\/libexec\/zmdomaincertmgr deploycrts<\/b>After installation, the certificates and key for the domain company.ru will be stored in the folder <b>\/opt\/zimbra\/conf\/domaincerts\/company.ru<\/b>.\u00a0<\/p>\n<p>By repeating these actions using different domain names but the same IP address, you can host hundreds of domains on a single IPv4 address. At the same time, you can use certificates from various issuing authorities without any issues. You can verify the correctness of all performed actions in any browser, where each virtual host name should display its own <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/ssl-sertifikat\/\"   title=\"SSL certificate\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"363\">SSL certificate<\/a>.\u00a0<\/p>\n<p>The safety alphabet in Kubernetes: authentication, authorization, auditing<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/zimbra\/blog\/468025\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 21-\u0433\u043e \u0432\u0435\u043a\u0430 \u043d\u0430 \u0433\u0440\u0430\u043d\u0438 \u0438\u0441\u0442\u043e\u0449\u0435\u043d\u0438\u044f \u0442\u0430\u043a\u043e\u0439 \u0440\u0435\u0441\u0443\u0440\u0441, \u043a\u0430\u043a \u0430\u0434\u0440\u0435\u0441\u0430 IPv4. \u0415\u0449\u0435 \u0432 2011 \u0433\u043e\u0434\u0443 IANA \u0432\u044b\u0434\u0435\u043b\u0438\u043b\u0430 \u0440\u0435\u0433\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u044b\u043c \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u0430\u043c \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u0435 \u043f\u044f\u0442\u044c \u043e\u0441\u0442\u0430\u0432\u0448\u0438\u0445\u0441\u044f \u0431\u043b\u043e\u043a\u043e\u0432 \/8 \u0438\u0437 \u0441\u0432\u043e\u0435\u0433\u043e \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0430, \u0430 \u0443\u0436\u0435 \u0432 2017 \u0433\u043e\u0434\u0443 \u0430\u0434\u0440\u0435\u0441\u0430 \u0437\u0430\u043a\u043e\u043d\u0447\u0438\u043b\u0438\u0441\u044c \u0438 \u0443 \u043d\u0438\u0445. \u041e\u0442\u0432\u0435\u0442\u043e\u043c \u043d\u0430 \u043a\u0430\u0442\u0430\u0441\u0442\u0440\u043e\u0444\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u043d\u0435\u0445\u0432\u0430\u0442\u043a\u0443 IPv4-\u0430\u0434\u0440\u0435\u0441\u043e\u0432 \u0441\u0442\u0430\u043b\u043e \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 IPv6, \u043d\u043e \u0438 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 SNI, \u043a\u043e\u0442\u043e\u0440\u0430\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":28761,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-38313","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 21-\u0433\u043e \u0432\u0435\u043a\u0430 \u043d\u0430 \u0433\u0440\u0430\u043d\u0438 \u0438\u0441\u0442\u043e\u0449\u0435\u043d\u0438\u044f \u0442\u0430\u043a\u043e\u0439 \u0440\u0435\u0441\u0443\u0440\u0441, \u043a\u0430\u043a \u0430\u0434\u0440\u0435\u0441\u0430 IPv4.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-pravilno-nastroit-sni-v-zimbra-ose\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u043a \u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c SNI \u0432 Zimbra OSE? | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 21-\u0433\u043e \u0432\u0435\u043a\u0430 \u043d\u0430 \u0433\u0440\u0430\u043d\u0438 \u0438\u0441\u0442\u043e\u0449\u0435\u043d\u0438\u044f \u0442\u0430\u043a\u043e\u0439 \u0440\u0435\u0441\u0443\u0440\u0441, \u043a\u0430\u043a \u0430\u0434\u0440\u0435\u0441\u0430 IPv4.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-pravilno-nastroit-sni-v-zimbra-ose\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:22:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:22:55+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47How to properly configure SNI in Zimbra OSE? | ProHoster","description":"At the beginning of the 21st century, a resource like IPv4 addresses was on the brink of exhaustion.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-pravilno-nastroit-sni-v-zimbra-ose","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u043a \u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c SNI \u0432 Zimbra OSE? | ProHoster","og:description":"\u0412 \u043d\u0430\u0447\u0430\u043b\u0435 21-\u0433\u043e \u0432\u0435\u043a\u0430 \u043d\u0430 \u0433\u0440\u0430\u043d\u0438 \u0438\u0441\u0442\u043e\u0449\u0435\u043d\u0438\u044f \u0442\u0430\u043a\u043e\u0439 \u0440\u0435\u0441\u0443\u0440\u0441, \u043a\u0430\u043a \u0430\u0434\u0440\u0435\u0441\u0430 IPv4.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-pravilno-nastroit-sni-v-zimbra-ose","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:22:55+00:00","article:modified_time":"2019-10-31T19:22:55+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38313","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-08 20:37:35","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:11:24","updated":"2026-02-08 20:37:35","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38313","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=38313"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38313\/revisions"}],"predecessor-version":[{"id":157779,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38313\/revisions\/157779"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/28761"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=38313"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=38313"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=38313"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}