Installing a wildcard certificate from a pfx file

Hi,I have a pre-registered wildcard certificate that has been created for the company I work for. (*.mydomain.com) It is in the format of filname.pfx.

Can I use this for SSL on my domino servers?

I have imported the CA’s root certificates but as this is a certificate that was already preregistered I’m not sure what steps to take. Obviously I dont need to make a certificate request as the wildcard already has the private and public keys in it.

I have extracted the .cer by importing the pfx in to internet explorer and exporting it as a cer (base 64 X509)file and when I skip to step 4 in the serer certificate administration database it always complains about the ‘No private key exists for this certificate’ This would be correct as it does not contain the private key when you export from IE.

Maybe what I need to do is to convert the pfx file to a kyr file? I’m not sure. Please help.

Subject: Installing a wildcard certificate from a pfx file

I did some documentation and a checklist on how to do this at my company blog.Maybe that could help you out, here is the link:

Regards

Mats

Subject: No Private Key

Did you find a way around this, im getting the same error while trying to import my existing certificate…

Subject: No private key

Same here, is there a way to export the private key from a kyr file and request a certificate from a CA

Subject: IBM doesn’t make it easy, but it’s possible

Here are some other threads discussing the problem: : Import SSL certificates into Domino

: View / Export Private Key in keyfile.kyr

IBM used to have a technote that included the correct ikeyman program and some instructions, but for some reason they have deleted it. It was titled “How to export the private key from a Domino keyfile by using IKEYMAN” (#1308138)", and was at this url: http://www.ibm.com/support/docview.wss?uid=swg21308138

The program is still available at ftp://ftp.software.ibm.com/software/lotus/tools/Domino/gsk5-ikeyman.zip , and some more recent comments from people detailing the steps involved are at:

http://www.turtleweb.com/turtleblog.nsf/dx/11022009232215GDAVGR.htm?opendocument&comments

I just imported a wildcard cert into Domino last month, so it definitely works.

Subject: Download gsk5-ikeyman

The ftp to download ikeyman is not working anymore.

You can download it from here:

http://www-01.ibm.com/support/docview.wss?uid=swg21615277&aid=1

Source: http://www-01.ibm.com/support/docview.wss?uid=swg21615277