Configuring the Certstore database for TLS
Specify TLS communication settings in the Certstore database (certstore.nsf).
Before you begin
- You will need to perform the following steps on the Certmgr server and then replicate the Certstore database to Domino IQ servers.
- The Certmgr server needs to run Domino 14.5 and the design of certstore.nsf must be upgraded to the latest template.
Procedure
- From the Domino Administrator client, open certstore.nsf.
- Go to the TLS CredentialsBy Hostname view, and click theAdd TLS Credentials button.
- In theHostname field, enterlocalhost.
- In theServers with access field, select the Domino IQ servers that have theUse TLS option enabled.
- In theCertificate Provider field, selectMicroCA. In theCertificate Authority field, selectDominoMicroCA.
- Click on theCreate Exportable keys button. Provide the password for the exportable keys.
- Click theSubmit Request button.
- Refresh the view and ensure that the Certmgr server processes the localhost TLS Credentials document successfully.
- Now, go to the Configurations\Certificate Authorities view in the Certstore database. Open the DominoMicroCA document and click theCreate Trusted Root button.The localhost certificate under the DominoMicroCA Trusted root certifier is ready for use on Domino IQ servers.
- For faster access, replicate the Certstore database to the Domino IQ servers.