IMAP SSL certificate expired
Guido Flohr <[email protected]> Mon, 28 Feb 2005 20:36:11 +0100
| Newsgroups | gmane.linux.suse.domino |
|---|---|
| Message-ID | <[email protected]> |
Hi, I connect to our Notes server via imaps and the SSL server certificate has expired. The Notes server is version 5.0.12 running on Linux and the administrator, yours truly, got stuck looking for the right way to do that. My favorite option would be to use our internal local CA to sign a new certificate. I /think/ I have already managed to add the CA certificate to the list of trusted CAs, as it shows up under "Certification Authorities" in a database "certsrv.nsf" (labelled "Server Certificate Admin"). I have also found a database "cca50.nsf" labelled "Domino Certificate Authority" that shows that the now expired certificate had been certified by exactly that (also local) "Domino Certificate Authority". This would be another option to get to a new SSL certificate. But where can I add a fresh SSL certificate that is used for imaps (and https)? I already grepped recursively through my data directory with some keywords from the expired certificate and I cannot find the right place. How/where do I create a certificate request, and where do I install the signed certificate? I would also like to know whether the Notes clients will automatically trust the new root CA that I have installed, or will I have to change the configuration of all clients? I would prefer to use my own CA, because its root certificate is already installed in non-notes clients like web browsers and MUAs. The notes server also refuses a connection on the https port (but accepts connections on http). It used to work until lately. Could the expired certificate be the reason for that? Yes, I am /not/ a regular Notes administrator. I was forced to take over the job. ;-) Thanks for your help! Guido -- Imperia AG, Development Leyboldstr. 10 - D-50354 Hürth - http://www.imperia.net/