!free! — Zimbra Sccfd
/opt/zimbra/libexec/acme-client -d yourdomain.com -v Cause: Too frequent checks or large cert chain. Fix: Increase ssl_sccfd_check_interval to 172800 (2 days). Issue 4: Certificate renewed but not deployed Fix: Manually reload proxy:
su - zimbra zmprov modifyServer `zmhostname` -zimbraSSLUseLetSCrypt TRUE zmcontrol stop sccfd zmcontrol disable sccfd # on systemd: systemctl disable zimbra-sccfd To re-enable later: zimbra sccfd
zmcontrol stop sccfd zmcontrol start sccfd To trigger sccfd immediately (instead of waiting for next interval): /opt/zimbra/libexec/acme-client -d yourdomain
zmproxyctl reload zmmailboxdctl restart # if single-server If you manage certificates manually or via another CA: zimbra sccfd
su - zimbra zmcontrol status | grep sccfd Expected output (if enabled):
su - zimbra zmcertmgr viewdeployedcrt # Check current expiry zmcertmgr renewcrt # Force renewal if within threshold Or restart sccfd – it will check on startup: