Setting up TLS on AUT servers

HCL Notes® clients connect to AUT servers over secure HTTPS connections. Before you configure AUT servers, complete this procedure to create an TLS certificate on AUT servers.

To create a TLS certificate on AUT servers, generate a TLS SHA-2 certificate in a keyring file, deploy the keyring file on the AUT servers, and import the certificate into the Domino® Directory of the AUT servers.

Next, create a Configuration document in the Domino Directory for AUT servers according to which procedure applies to your Domino version:

Domino 12.0 servers and later

  1. For Domino servers running 12.0 and later, to set up TLS it is best to use the Certificate Store application (certstore.nsf) with the TLS credentials document needed for an Internet site. For more information, see Certificate management with CertMgr.
  2. For the AUT download site, create a TLS credentials document in certstore.nsf with the fully qualified hostname of the AUT download site.
  3. If you have existing keyring files for the same hostname, you can import them certstore.nsf as described in Upgrading TLS credentials.
  4. Update the Keyring file name field for the AUT Internet site in the Domino Directory, using the same hostname that is specified in the TLS Credentials document in certstore.nsf.

Domino 10.0.1 and 11.0.1 servers

  1. Use OpenSSL (available on the Internet) and KYRTool (installed with Domino) to generate the keyring file for the AUT Servers to use. For instructions, see the article How to set up SSL using a third-party Certificate Authority (CA) on the HCL Software Support site.
  2. Copy the keyring file to the data directory of each AUT server.
  3. Import the certificate into the Domino Directory:
    1. Copy the Internet certificate file to your Domino Administrator client computer.
    2. From the Domino Administrator, click the People & Groups tab and the Certificates view.
    3. Click Actions > Import Internet Certificates.
    4. Browse for and open the local certificate file.
    5. Verify that the certificate is selected in the Open Internet Certificates box and then click Accept All.
    6. Click View > Refresh and verify that the new certificate is now displayed in the Certificates view of the Domino Directory.