Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 12 of 12
  1. #1
    Member
    Join Date
    Nov 2002
    Posts
    153

    Default exim.crt errors

    Been seeing these in the exim logs since yesterday:

    2007-05-04 11:06:10 TLS error on connection from (xxncxxk) [90.xxx.xxx.xxx] (SSL_CTX_use_certificate_chain_file file=/etc/exim.crt): error:0200100D:system library:fopen:Permission denied

    Any ideas what the cause is.

    Thanks

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge TSJasonH's Avatar
    Join Date
    Nov 2003
    Location
    Chicago, IL
    Posts
    34

    Default

    I'm also now seeing this with the new exim 4.66 on some servers (rhel 3).
    Regards,
    Jason H.
    TouchSupport LLC
    http://www.touchsupport.com
    24/7 Tech Support and Server Administration

  3. #3
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    if you guys are using cp11 you will find a server certificates manager in the left menu of WHM under service configuration ..you will see "manage service certificates"

    Go into that sections and see if you can select the certificate again that you want to use for exim and basically re-install or re-link it but going through that process. look for errors when exim restarts.
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  4. #4
    Member serversphere's Avatar
    Join Date
    Jan 2004
    Posts
    658

    Default

    RPM - you sure? looks more like a permissions error than anything else. Or did the update to v11 mux up the key when it moved it? I get no errors when exim restarts. No errors when doing /scripts/eximup --force except that it cannot write to the crt/key files. Yet the files are there and the links are in place... weird!
    Last edited by serversphere; 05-04-2007 at 10:44 AM.
    Darren Benfer | SS-Darren | AIM: serversphere
    www.serversphere.com
    Dedicated Server Solutions Have Come Full Circle

  5. #5
    Member serversphere's Avatar
    Join Date
    Jan 2004
    Posts
    658

    Default

    Okay, just got this fixed. Check permissions on both your links in /etc (/etc/exim.key and /etc/exim.crt) and the ones in /var/cpanel/ssl/exim. Make sure they are owned by mailnull:mail. Restart courier-imap, cpanel and exim. See if that does it for you.

    ps - make sure your key files are only root read/write-able. You don't want that key getting out for any reason.
    Darren Benfer | SS-Darren | AIM: serversphere
    www.serversphere.com
    Dedicated Server Solutions Have Come Full Circle

  6. #6
    Member
    Join Date
    Nov 2002
    Posts
    153

    Default

    just checked and those files are owned by root:root. Just chowned them, so will see if the errors stop.

    Thanks

  7. #7
    Member serversphere's Avatar
    Join Date
    Jan 2004
    Posts
    658

    Default

    Quote Originally Posted by simplybe View Post
    just checked and those files are owned by root:root. Just chowned them, so will see if the errors stop.

    Thanks
    Mine were like that as well. Change ownership and you should be good.
    Darren Benfer | SS-Darren | AIM: serversphere
    www.serversphere.com
    Dedicated Server Solutions Have Come Full Circle

  8. #8
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    Quote Originally Posted by serversphere View Post
    RPM - you sure? looks more like a permissions error than anything else. Or did the update to v11 mux up the key when it moved it? I get no errors when exim restarts. No errors when doing /scripts/eximup --force except that it cannot write to the crt/key files. Yet the files are there and the links are in place... weird!
    absolutely a perms/ownership issue or a combination. I just fixed a box just using the SSL installer on exim. That's why I suggested that. It worked on a centos box.
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  9. #9
    Member
    Join Date
    Sep 2006
    Posts
    23

    Default

    Excellent Beta Testing Upgrades!

    Much Appreciated heh.

  10. #10
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default

    Can't find anything that would set it to not be owned by mailnull:mail (Cpanel::SSLCerts takes care of this).


    If affected posting :

    ls -l /etc/exim.crt /etc/exim.key

    would be extremely helpful.

    In the mean time 11619+ will check to make sure they are correct at upcp time.

  11. #11
    Member serversphere's Avatar
    Join Date
    Jan 2004
    Posts
    658

    Default

    Cool thanks Nick. Does the upgrade to v11 simply move the files to the new directory and then symlink to them? Maybe they were root:root all along and worked that way in the past..?
    Darren Benfer | SS-Darren | AIM: serversphere
    www.serversphere.com
    Dedicated Server Solutions Have Come Full Circle

  12. #12
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default

    Quote Originally Posted by serversphere View Post
    Cool thanks Nick. Does the upgrade to v11 simply move the files to the new directory and then symlink to them? Maybe they were root:root all along and worked that way in the past..?
    11.x moves them all in /var/cpanel/ssl/SERVICE_NAME_HERE/

    and symlinks them.

Similar Threads & Tags
Similar threads

  1. perl/Exim errors - Exim not starting
    By lukemcr in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 02-16-2011, 09:14 AM
  2. Exim errors with jailshell
    By ralphday in forum E-mail Discussions
    Replies: 0
    Last Post: 08-18-2010, 12:52 AM
  3. exim.crt & key don't exist?
    By beddo in forum E-mail Discussions
    Replies: 5
    Last Post: 06-04-2007, 06:01 PM
  4. How can I restart exim so it refreshes the SSL exim.crt and .key?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 02-07-2006, 10:23 AM
  5. How Can I updated /etc/exim.crt and /etc/exim.key?
    By seeyes in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-14-2004, 01:18 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube