Configuring Global Settings

Configure Global Settings to set default values to use for certificate management.

About this task

Global Settings provide default values that are applied to TLS Credential documents that you create to generate certificates. The default values can be modified when you create the TLS Credentials documents.

Procedure

  1. Open certstore.nsf.
  2. Click Edit Global Settings.
  3. For the Admin server, the first server where you start CertMgr is selected as the CertMgr server.
  4. In the Key algorithm field, select one of the following options:
  5. In the Certificate provider field, select one of the following options:
    • ACME Select this option to use the Let's Encrypt CA.
    • Manual Select this option to use another third-party CA.
  6. If you selected ACME as the certificate provider, in the ACME account field, select one of the following options:
    • LetsEncryptStaging Select this option when testing.
    • LetsEncryptProduction Select this option for production use.

    The staging environment is suitable for testing because it has a higher rate limit and uses an untrusted root certificate. The staging environment's root certificate is not included in any browser. You should manually install it for the duration of the testing and then immediately remove it.

    The Let's Encrypt® production environment has stricter rate limits and will fail temporarily if you exceed the limits.

    For more information, see the Let's Encrypt documentation on Rate Limits.