Vendredi 18 juin 2010 5 18 /06 /Juin /2010 10:15

Setting up the Server Certificate Admin application.


Domino automatically creates the Server Certificate Admin application during server setup.

If the Server Certificate Admin application is not available after you start the Domino server, use the Server Certificate Admin template (CSRV50.NTF) to create it.

Use the Server Certificate Admin application to:

ü  Request server certificates from either a Domino or third-party CA

ü  Add a CA certificate as a trusted root

ü  Manage server certificates in a key ring file

ü  Create a self-certified certificate for testing purposes


To set up the Server Certificate Admin application

1. Make sure you set up the server as a Domino Web server.

2. Edit the ACL of the Server Certificate Admin application, as follows:

  •  
    •  
      • Add the names of server administrators who will need to obtain and manage server certificates. Assign Manager access.
      • Set -Default- access to No access to prevent others from using the database.

3. Create a server key ring file.

TipTo hide the Server Certificate Admin application when users choose File - Database - Open, deselect "Show in 'Open Database' dialog" in the Database Properties box.

 

 

http://www.ssl247.fr/

Par Les nouvelles du SSL
Ecrire un commentaire - Voir les 3 commentaires
Vendredi 18 juin 2010 5 18 /06 /Juin /2010 10:13

1) Installed Office Communications Server 2007 (OCS)

Click Start -> Programs -> Administrative Tools -> Office Communications Server 2007


2) Expand the items in the snap-in until you get to the Enterprise Edition Server that you installed.


3) Right-click on the correct server name and select "Certificates".

Click next to get past the Certificate Wizard welcome screen.


4) Choose to "Create a new Certificate" then

Click Next.


5) Choose to "Prepare the request now, but send it later" then

Click Next.


6) Under "Name" enter name for your certificate. (This name is simply a label for the certificate, so you can name it whatever you like such as the server name or the pool FQDN)


7) Clear the check to "Mark cert as exportable" then

Click Next.


8) For "Organization" enter your legal company name (Be precise) including Inc, LLC, Ltd etc. if applicable


9) For "Organizational Unit", enter the department such as Web  or Sales then

Click Next.


10) For "Subject Name" enter the Fully Qualified Domain Name (be precise) of the pool. Select the option to "Automatically add local computer name", then

Click Next.


11) Enter your Country, State/Province, and City details then

Click Next.


12) Choose a file name and location to save your new Certificate Request (CSR). The file will be a text file, so it should be given a .txt extension.

Click Save.


13) Review the settings and finish the certificate wizard. This will save the CSR file to the location you entered above. While ordering your certificate, you will be asked to copy and paste your CSR to the SSL247 order form. Open your CSR file with notepad, and copy and paste the contents to the order form. Select "Microsoft Office Communications Server 2007" as the server platform.


Find more information, see Microsoft's official Office Communications Server documentation, located at http://r.office.microsoft.com/r/rlidOCS?clid=1033&p1=library

 

 

 

 

http://www.ssl247.fr/

Par Les nouvelles du SSL
Ecrire un commentaire - Voir les 0 commentaires
Vendredi 18 juin 2010 5 18 /06 /Juin /2010 10:11

Advice:Before you begin, you should know the port which your server uses to listen for SSL connections.


1) Start the Certificate Request Generator. This is done by entering the following into your web browser:

à https://hostname:port/certificate


Where hostname is the name designated for your server, and port is the number of the port for SSL connections.


2) A form will be loaded into your web browser. Input the information at each prompt, then

Click the 'Generate Request' button. (If any required fields are left blank, you will be so prompted by the servlet.)


The Certificate Request Generator servlet will create three files:

yourdomain-key.der - the private key file
yourdomain-request.dem - the certificate request in binary format
yourdomain-request.pem - the certificate request in ASCII format


Advice:If you choose not to give a password, you will receive an unencyrpted RSA private key. If you do give a password, your private key will be PKCS-8 encrypted. With the latter, you must check the Use Encrypted Keys field on the SSL tab in the Server window of the Administration Console.


The last of the three files is the one to open and copy/ paste into the SSL247 web form (including the BEGIN and END tags).

ormal>`nlps>http://www.ssl247.com/ssl-certificate-signing-solutions/ssl-certificates/organization-validation.php

 

 

 

http://www.ssl247.fr/

 

Par Les nouvelles du SSL
Ecrire un commentaire - Voir les 0 commentaires
Vendredi 18 juin 2010 5 18 /06 /Juin /2010 10:09
Par Les nouvelles du SSL
Ecrire un commentaire - Voir les 0 commentaires
Vendredi 18 juin 2010 5 18 /06 /Juin /2010 10:08

You must create a SSL configuration file, before generating a CSR. This can be completed by running the following command:

# /usr/local/bin/genconf

When you run this command, the Big-IP will ask for your company information.


Country Name (2 letter code) [AU]:GB
State or Province Name (full name) [Some-State]:London
Locality Name (eg, city) []:London
Organization Name (eg, company) [Internet Widgits Pty Ltd]:Global Sign
Organizational Unit Name (eg, section) []:IT
Common Name (eg, YOUR name) []:www.globalsign.net (Must be the Fully Qualifed Domain Name)
Email Address - Leave blank
Challenge Password - Leave blank
Retype Password - Leave blank


Run the following command to generate a new certificate request:

# /usr/local/bin/genkey www.yourdomain.com

Be sure to replace www.yourdomain.com with your Common name - FQDN (Fully Qualifed domain name). You will be prompted again for your company information during this step.


Country Name (2 letter code) [AU]:GB
State or Province Name (full name) [Some-State]:
London
Locality Name (eg, city) []:
London
Organization Name (eg, company) [Internet Widgits Pty Ltd]:Global Sign
Organizational Unit Name (eg, section) []:IT
Common Name (eg, YOUR name) []:www.globalsign.net (Must be the FQDN - Fully Qualifed Domain Name)

 

 

http://www.ssl247.fr/

The CSR will be stored in the following: /config/bigconfig/ssl.crt/Fully Qualified Domain Name.crt


Copy the entire contents of the CSR, insuring to include



-----BEGIN CERTIFICATE REQUEST-----
and
-----END CERTIFICATE REQUEST-----


Par Les nouvelles du SSL
Ecrire un commentaire - Voir les 0 commentaires

Présentation

Créer un Blog

Recherche

Calendrier

Mai 2012
L M M J V S D
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31      
<< < > >>
Créer un blog gratuit sur over-blog.com - Contact - C.G.U. - Rémunération en droits d'auteur - Signaler un abus