Moving SSL Certificate

Hi All,

I need create another Domino Domain and infrastructure with new servers for receive one applications that running in the actual Domain and servers…

So, after i create the new Domain, i need moving the SSL certificate to the new infra.

How i dump de SSL and put in the another NAB ?

I see in the certserv.nsf and i can’t find any option…

Thanks and regards,

Marce

Subject: Moving SSL Certificate

As far As I Know, you can’t do that. Since the SSL certificate is related, among other things, to the server’s fully qualified domain name. You can’t use the same SSL certificate for two different server’s.

Hope this helps,

Oswaldo Escobar Mendoza

Lima, Perú

Subject: RE: Moving SSL Certificate

Hola Oswaldo ¿que tal? :wink:

Look, i don't will change the host name, i will change de notes domain only.



Let me explain better... 



I have one domino server in the notes domain called XX, this server running one web application that users access by host.xx.com.



Now, i need recreate this environment in a new notes domain for running the same web application and with the same host host.xx.com.



I only need extract this certificate from the current server and install in the new notes server, all other things continue the same ex. hostname, ip address etc... 



But look, i think better now, i have the certificate received from the verisign, if i put this certificate in the new server, what you think ? 

Saludos

Marce

Subject: RE: Moving SSL Certificate

Ok, I see I haven’t understood your question.

When you create a new keyring for the new server, it will has a different “fingerprint” (don’t remember the exact term for this), and maybe the certificate received from Verisign will be rejected, However, copying the old keyring (including the SSL certificate) to the new server could work, but not sure of that, I never done before.

Regards,

Oswaldo Escobar Mendoza

Lima, Perú

P.S.: que bueno poder escribir al menos una línea en español :slight_smile:

Subject: RE: Moving SSL Certificate

Bingo…

It’s working fine !!!

I put the keyring file in the data folder and put the certificate in the certlog and working fine…

Hermano, nice to meet u… see u…

Oswaldo, if u can write me, please write to contatopessoal@hotmail.com.

Thanks or Gracias

Marce

Subject: RE: Moving SSL Certificate

Marce, you write: “I put the keyring file in the data folder and put the certificate in the certlog and working fine…”.

I did put both keyring files on our new server “Data” folder, but I canno’t figure which certificate you put in the certlog. Where you get this certificate: from the certsrv.nsf DB?

You’re help would be much appreciate.

My e-mail: bernard.lebleu@agora.qc.ca

Subject: RE: Moving SSL Certificate

Estimado Oswaldo,

   I will try to move the certificate with this process and i let you and the forum know the results...



   It's really very fine write some words in spanish, if you like, send me your e-mail address and we could write more words friendly in spanish.



   See u..

Marce

Subject: RE: Moving SSL Certificate

Except when it’s a wildcard (*.domain.net) CN in the certificate.

Subject: Moving SSL Certificate

Bingo…

  It's working fine !!!



   I put the keyring file in the data folder and put the certificate in the certlog and working fine...



   Hermano, nice to meet u..  see u...



    Oswaldo, if u can write me, please write to contatopessoal@hotmail.com.

Thanks or Gracias

Marce