Zimbra Sccfd May 2026
zmcontrol stop sccfd zmcontrol start sccfd To trigger sccfd immediately (instead of waiting for next interval):
su - zimbra zmprov modifyServer `zmhostname` -zimbraSSLUseLetSCrypt TRUE zmcontrol stop sccfd zmcontrol disable sccfd # on systemd: systemctl disable zimbra-sccfd To re-enable later: zimbra sccfd
/opt/zimbra/libexec/acme-client -d yourdomain.com -v Cause: Too frequent checks or large cert chain. Fix: Increase ssl_sccfd_check_interval to 172800 (2 days). Issue 4: Certificate renewed but not deployed Fix: Manually reload proxy: zmcontrol stop sccfd zmcontrol start sccfd To trigger
zmproxyctl reload zmmailboxdctl restart # if single-server If you manage certificates manually or via another CA: zimbra sccfd
su - zimbra zmlocalconfig | grep -i sccfd | Parameter | Default | Description | |-----------|---------|-------------| | ssl_allow_untrusted_certs | false | Allow self-signed (not recommended) | | ssl_sccfd_check_interval | 86400 | Check interval in seconds (1 day) | | ssl_sccfd_renew_threshold | 30 | Renew when days left ≤ this value | | ssl_sccfd_random_delay_max | 3600 | Random delay before check (seconds) | Modify a parameter: zmlocalconfig -e ssl_sccfd_renew_threshold=20 Then restart sccfd :

赣公网安备36010602000086号,版权投诉请发邮件到website-sun@qq.com,我们会尽快处理