Solved

How to Export SSL Certificate and Key and convert to PEM format

Posted on 2004-09-16
7
11,957 Views
Last Modified: 2013-11-16
I'm trying to install a SSL acceleration appliance in front of  Domino 6.0 to 6.5.2 servers. In order to get it done I need to export the current SSL certificates and keys currently installed in the Domino server and convert them (using OpenSSL for example) to PEM format so I can install them into the SSL appliance.
Is this possible or Domino uses some proprietary format that can't be converted using openssl?
If it is, how can I export them and what is the exported format (the OpenSSL conversion part I can handle)?
0
Comment
Question by:alexrs
  • 2
  • 2
7 Comments
 
LVL 15

Expert Comment

by:Bozzie4
ID: 12081681
You can find them in the Domino server's data directory as keyfile.kyr (and a second file with the same name / other extension, I forgot which extension)

cheers,

Tom
0
 

Author Comment

by:alexrs
ID: 12088322
OK, but what are their format? I need them to be converted to base-64 (PEM) format.
0
 
LVL 15

Expert Comment

by:Bozzie4
ID: 12120289
Actually, I think it may be impossible for self-certifified certs.  But if you purchased 1 from a vendor (Globalsign/Verisign), you should have received it in a format you can handle....

cheers,

Tom
0
 

Author Comment

by:alexrs
ID: 12123039
I found the answer at IBM support site. Currently it's not possible to export a SSL key (like in MS IIS, Apache or Netscape)

http://www-1.ibm.com/support/docview.wss?rs=463&context=SSKTMJ&q1=export+ssl+certificate&uid=swg21097215&loc=en_US&cs=utf-8&lang=en

Can You Extract the Private Key from a Lotus Domino Key File (*.KYR)?
Technote (FAQ)

Problem
Is it possible to extract or export the private key from a Domino key ring file (*.KYR)? For example, you've included a VeriSign certificate in a Lotus Domino server's key ring file and wish to share its private key with another non-Domino Web server. Or another example would be if you wish to use Microsoft's Internet Security and Acceleration (ISA) Server, which uses an exported private key to serve SSL from the Web server(s) behind it.


Solution
This issue has been reported to Lotus software Quality Engineering as an enhancement request. Currently Domino does not provide functionality for exporting private keys from the key ring file on a Domino server.

Supporting Information:
If you wish to use Microsoft ISA server, consider using Microsoft IIS as the HTTP stack for Domino (also called Domino for IIS). Because Microsoft IIS works with the ISA server, if you use IIS as the HTTP stack for Domino you can obtain this functionality. For more information on using Microsoft ISA server, refer to the following article on the Microsoft Support site (http://support.microsoft.com):

      "How to Set Up Internet Security and Acceleration Server to Host Web Sites by Using the Secure Sockets Layer Protocol"
      Article # 292569
0
 
LVL 1

Accepted Solution

by:
Computer101 earned 0 total points
ID: 12515352
PAQed with points refunded (500)

Computer101
EE Admin
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Changing over from Lotus Approach v3 to MS Access 4 416
Lotus Domino server 11 67
lotus notes, exchange 7 111
IBM Notes How to read an encrypted mail saved as .eml file 7 57
You’ve got a lotus Domino web server, and you have been told that “leverage browser caching” is a must do. This means that we have to tell the browser everywhere in the web to use cache. In other words, we set (and send) an expiration date in the HT…
Lack of Storage capacity is a common problem that exists in every field of life. Here we are taking the case of Lotus Notes Emails, as we all know that we are totally depend on e-communication i.e. Emails. This article is fully dedicated to resolvin…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question