Deploying Internet Root CA and using that CA within other Internet CA's as a root

Hi,

I am trying to deploy a structure of Internet CA’s which consists of a root and three underlying CA’s which are used to sign certificates for special usage like VPN or SSL.

I’ve set up the CA’s within the Domino-Administrator and have created the certificate request databases, so I could start issuing certificates.

But…

I’ve got the problem that I don’t know how to issue a certificate for another CA.

The I’ve read in the documentation not to use the keyring file. But it seems to me to be impossible not to create it.

Has anybody ever done such a thing within the Domino Server based CA process???

I’d appreciate any help

Greetings

Norbert