Ask a Question

Advanced Search

Alert ID : INFO268

Last Modified : 04/22/2019

Managed PKI for SSL - Certificate Signing Request (CSR) Generation Instructions for Lotus Domino 5.x


To generate a CSR, you will need to create a key pair for your server. These two items are a digital certificate key pair and cannot be separated. If you lose your public/private key file or your password and generate a new one, your SSL Certificate will no longer match. You will have to request a new SSL Certificate and may be charged.

If you are not able to perfom the steps bellow on your server, Symantec recommends that you contact the server vendor for additional information.

Step 1: Generate a Private Key 

         NOTE: All certificates that will expire after December 2013 must have a 2048 bit key size.

  1. Launch the Domino Administration client.
  2. Select File-Open Server and select the Domino server you wish to administer
  3. Click the file tab
  4. Double click on Server Certificate Administration database (certsrv.nsf)
  5. From the administration panel, click System Databases and choose Open Domino Server Certificate Administration (CERTSRV.NSF) on the local machine.
  6. Click Create Key Ring.
  7. Enter a name for the key ring file in the "Key Ring File Name" field.
  8. Enter a password for the server key ring file in the "Key Ring Password" field. Note Password is an alphanumeric set of characters that protects the key ring from unauthorized use. The password is case sensitive. You should specify at least 12 alphanumeric characters for the password.

Step 2: Generate a Certificate Signing Request

  1. Specify the components of your server's distinguished name.

    The CSR needs to contain the following attributes

  • Country Name (C): Enter the two-character abbreviation of country in which organization resides (e.g. US).
  • State or Province (S): Enter the full name of your state or province.
    Note: Make sure the State or Province is not abbreviated (e.g. California).
  • Locality or City (L): Usually the city of your organization's main office, or a main office for your organization.
  • Organization (O): The full legal name of your company.
  • Organizational Unit (OU): Use this field to differentiate between divisions within an organization.
  • Common Name (CN): The fully-qualified domain name to which your certificate will be issued.
  1. Click Create Key Ring.
  2. After you read the information about the key ring file and distinguished server name, click OK.
  3. Click Create Certificate Request.
  4. If you want to log information about this request in the Server Certificate Administration application, select Yes in the "Log Certificate Request" field. Otherwise, select No.
  5. Enter the password of the key ring file you have specified when you were creating the key ring Step 1.
  6. You have just created a key pair and a CSR.
  7. Verify your CSR
  8. To copy and paste the information into the enrollment form, open the file in a text editor that does not add extra characters (Notepad or Vi are recommended).
  9. Proceed with Enrollment.

Contact Information

        Your Managed PKI for SSL Administrator will be responsible for issuing the certificate to you after your enrollment has been completed.
        Please contact them for assistance.   

Once the certificate has been issued, follow the steps from this link to install the certificate on your server: INFO287