IMAP SSL certificate expired

Guido Flohr <[email protected]> Mon, 28 Feb 2005 20:36:11 +0100
Newsgroups gmane.linux.suse.domino
Message-ID <[email protected]>
Hi,

I connect to our Notes server via imaps and the SSL server certificate
has expired.  The Notes server is version 5.0.12 running on Linux and
the administrator, yours truly, got stuck looking for the right way to
do that.

My favorite option would be to use our internal local CA to sign a new
certificate.  I /think/ I have already managed to add the CA certificate
to the list of trusted CAs, as it shows up under "Certification
Authorities" in a database "certsrv.nsf" (labelled "Server Certificate
Admin").

I have also found a database "cca50.nsf" labelled "Domino Certificate
Authority" that shows that the now expired certificate had been
certified by exactly that (also local) "Domino Certificate Authority".
This would be another option to get to a new SSL certificate.

But where can I add a fresh SSL certificate that is used for imaps (and
https)? I already grepped recursively through my data directory with
some keywords from the expired certificate and I cannot find the right
place. How/where do I create a certificate request, and where do I
install the signed certificate?

I would also like to know whether the Notes clients will automatically
trust the new root CA that I have installed, or will I have to change
the configuration of all clients?  I would prefer to use my own CA,
because its root certificate is already installed in non-notes clients
like web browsers and MUAs.

The notes server also refuses a connection on the https port (but
accepts connections on http).  It used to work until lately.  Could the
expired certificate be the reason for that?

Yes, I am /not/ a regular Notes administrator.  I was forced to take
over the job. ;-)

Thanks for your help!
Guido
-- 
Imperia AG, Development
Leyboldstr. 10 - D-50354 Hürth - http://www.imperia.net/