SECURING


Creating a self-certified certificate to test TLS certification

You can create a self-certified certificate to test the certificate procedure at your organization. Because this certificate is not certified by a CA, use it only for testing purposes.

About this task

Note: This procedure describes steps used in Domino 11 and earlier versions. As of Domino 12, use of Certificate Manager and Certificate Store (certstore.nsf) is the preferred method for generating and managing certificates. For more information, seeManaging TLS certificates with Certificate Manager.

Procedure

1. From the HCL Notes® client, open the Server Certificate Admin application, and then click Create Key Rings & Certificates.

2. Click Create Key Ring with Self-Certified Certificate.

3. Complete these fields, and then click Create Key Ring with Self-Certified Certificate:


4. Copy the key ring file and stash (.STH) file to the HCL Domino® data directory of the server.

5. Configure the port for TLS.

6. Set up database access.

Parent topic: Managing TLS certificates without Certificate Manager
Previous topic: Renewing expired certificates

Related concepts
TLS security

Related tasks
Configuring a port for TLS
Configuring a database ACL