SECURING
About this task
A certificate request is essentially certificate data that has not been signed by a CA. The CA turns the request into a certificate by signing it.
If you are requesting a server certificate from a server-based certification authority, you can use the Notes® client to create the server key ring and the server certificate in the Certificate Requests database. You must be able to access the Domino server using the Notes client.
To request a server certificate using a Notes client
Procedure
1. From the Notes client, open the Certificate Requests database for the certifier from which you want to request a server certificate.
2. Do the following to create a server key ring file to store the server certificate and merge the CA certificate as a trusted root into the server key ring file:
b. In the Create Key Ring form, complete these fields:
c. Verify the information in the Key Ring Created dialog box, then click OK to automatically add the CA as a trusted root and generate a certificate request for the server.
d. Verify the information in the Merge Trusted Root Certificate Confirmation dialog box and click OK.
e. Click OK when the Certificate received into key ring and designated as trusted root confirmation dialog box appears.
f. Click OK when the Certificate Request Successfully Submitted for Key Ring dialog box appears.
After an RA approves the request for a server certificate, the CA issues a server certificate and sends notification that you can pick up the certificate.
4. Choose Domino Key Ring Management -> Pickup Key Ring Certificate.
5. Enter the key ring file name and password, paste the pickup ID into the form and click Pickup Certificate.
6. Verify the information in the Merge Signed Certificate Confirmation dialog box and click OK.
7. When the Certificate received into key ring dialog box appears, click OK.
8. Copy or use FTP (in binary mode) to transfer the new key ring and its associated .STH file to the server's data directory.
From a Domino CA using a Web browser
This procedure for generating a server certificate request is the same regardless of whether you are requesting a server certificate from a Domino server-based certification authority or a Domino 5 certificate authority.
1. Make sure you already created the server key ring file and mapped a drive to the directory that contains the server key ring file.
2. From the Notes client, open the Domino Directory of the server on which you want to create SSL, and open the Server Certificate Admin application.
3. Click Create Certificate Request.
4. Complete these fields:
6. Enter the password for the server key ring file.
7. Copy the certificate request to the system Clipboard (include the Begin Certificate and End Certificate lines), and click OK.
8. On the server, use one of these methods to browse to the Domino certificate authority application (the Certificate Requests application for a server-based certification authority, and the Domino Certificate Authority for a Domino 5 Certificate Authority) on the Domino server's Web site:
10. Enter your name, email address, phone number, and any comments for the CA.
11. Paste the certificate request into the dialog box, and then click Submit Certificate Request.
12. Merge the CA certificate as a trusted root.
From a third-party CA
1. Make sure you already created the server key ring file.
2. From the Notes client, open the Server Certificate Admin application on server for which you want to set up SSL.
7. If you selected Paste into form on CA's site in Step 4, do the following:
b. Use a browser to visit the CA's site, and then follow the instructions that the CA's site provides for submitting a request for a new certificate.
Related tasks Creating a server key ring file Merging a CA certificate as a trusted root Viewing requests for certificates Setting up SSL on a Domino server