Forcing Notes to use the Internet Certificate

Hi all,

I have a PKCS#11 module. My two Lotus Notes users are Smart-card Enabled. They are able to sign emails to each other, and the signing goes through the PKCS#11 interface.

But, when I sign and encrypt, it does not. I understand that the encryption won’t, but I find it strange that the signing doesn’t.

The other issue, is that it signs it using the Lotus Notes certificate, rather than my Internet Certificate. How do I force it to use the Internet Certificate?

I have also looked into the User Security->Mail->Internet-style Mail Options->Certificate Configuration and I have the warning “Problem has been detected with your certificate in the Domino Directory”. “Your Internet encryption certificate was not found in the Domino directory. Notes users will have trouble sending you Internet-style encrypted mail”

How, from the client, do I put the certificate in the Domino Directory? I have been searching through documentation, and the web and have been quite unsuccessful. Any help would be appreciated.

Thank you

Vadim Tabakman

Subject: Forcing Notes to use the Internet Certificate

  1. Register the parent certifier keyring file in the directory using the admin client’s Internet Certifier command. (Configuration tab, Tools | Registration menu)

  2. Gnerate your internet certificate and add it to your person doc with the Add Internet Cert to Selected People command. (People tab, Actions menu)

  3. Authenticate with your home server, and (in theory) your client should download the internet cert into your ID file.

Subject: RE: Forcing Notes to use the Internet Certificate

Hi Bruce,

thanx for your reply. My experience with configuring Lotus Notes or Domino is limited, so bare with me.

  1. I played around and created a selfcertificed keyring file. I hope that is correct and used that in the Internet Certifier Command

  2. I did the Add Internet Cert to Select People. It seemed to take about 2 seconds. Then I assume it worked. (any way to check???)

  3. This is what i’m not sure about. How do I Authenticate with the home server? How does the client download the internet cert (what commands? menus?)

  4. If I’m correct, we are generating a cert for the user. What happens if the company gets internet certs elsewhere, like Verisign?

Thanx for your help Bruce

Subject: RE: Forcing Notes to use the Internet Certificate

  1. How did you create the self-certified keyring? If you used the Certificate Authority db, then that’ll work fine.

  2. “any way to check?” Yes. The person document has a Certificates tab wihc has an internet certificates tab, which will tell you if there are any internet certs in that person doc.

  3. Bounce the client and open your mail file. That should cause the dynamic configuration protocol to do all the things it does, including pulling down internet certs from the person doc. (In reality, it sometimes takes a few client restarts, but eventually it’ll be there.)

  4. There are different kinds of certs you can buy from VeriSign. If you buy a cert that lets you use it as your own root to generate user certs, then the process is the same, once you have the keyring file. It’s the creation of the keyring itself that may vary.

Subject: RE: Forcing Notes to use the Internet Certificate

Hi Bruce, I appreciate your help, even though I’m probably asking silly questions.

I’ll give you the scenario with which I’m working.

I’ve create a PKCS#11 module to communicate with a token where the private key will be stored. The certificate will on the other hand be stored in Notes. This will allow the user to sign and decrypt emails coming to them. I can understand how if you have a keyring file, you can generate internet certificates for the users (btw I can’t seem to get this to work, no matter how many times I bounce my client). I am also very interested in how to get certificates made for users from another CA to work.

What I have done is go into User Security in the client, and enable SmartCard login, then import a cert from a PKCS#12 file, and moved the Private Key to the SmartCard. As I’ve said earlier, this seems to work for signing to Notes users, but when encrypting to a Notes user, it doesn’t use the Internet Certificate(public key), but uses the Notes Certificate(public key) to encrypt. Signing,encrypting,decrypting works if I’m emailing an internet user rather than a Notes user.

I do not have a cert that lets me use it as my own root to generate user certs. We have a CA that generates certificates for users (development environment). In a production system, the company would most likely obtain certs from Verisign.

I hope I have explained my situation. I went into the Domino Administrater, selected a person and went to Action->Add Internet Cert to Select People. I get successful, but nothing in the person record changes. I close the record and open it, and still no certificate under Internet Certificates.

I did notice that in the Action menu now, I can choose Import Internet Certificate. When I did that, that updated the record. Will this allow me to Sign/Encrypt/Decrypt emails now using that cert? (I will try it) Is this what the Notes documentation means, when it says your Internet certificate needs to be in the Domino Directory??

Thanx (sorry for the long winding message)

Vadim Tabakman

Subject: Encryption/Decryption and Signing Working

Hi Bruce,

well I believe with all your help and pointing me in the right direction, I’ve finally got it working.

In the administrator, I opened up each of my users and went to Action->Import Internet Certificates. Also in the Basics form, I made sure that for each use the “Format preference for incoming email” was set to “Prefers MIME”.

So that is the Domino Directory done.

On the client end, I SmartCard enabled the users ID, and imported a certificate into the ID, then moved the private key to the smart card. (after overcoming some development issues with my PKCS#11 interface) everything worked fine.

I am now signing and encrypting and decrypting emails.

Thanx very much for your help and assistance.

Vadim Tabakman

vtabakman@betrusted.com

Subject: RE: Encryption/Decryption and Signing Working

Well, I’m glad thatr you got it working before I posted this to tell you the step I left out of the admin-driven process, which was to wait for the admin process to run on the server and add the internet certificate(s) to the person doc(s).

Subject: RE: Encryption/Decryption and Signing Working

Thanx for your help Bruce. It was great. i’ve nominated you in that Member Spotlight.

Once again, THANX :o)

Subject: RE: Encryption/Decryption and Signing Working

Now, I settup Domino CA. Users can use Internet certificates to encrypt mail between clients. So, if user use Notes client to send a messages to MS outlook that display on MS “The Body is encypted by Notes certificates”. How can MS outlook can see this message? How can I do?regards

Le Thanh Son