Setting up Notes and Internet clients for SSL client authentication
You can set up a Notes® or Internet client for client authentication with a server. You cannot use client authentication for SMTP and IIOP connections.
About this task
For SSL client authentication, the Notes or Internet client must have:
- An Internet certificate issued by a Domino® or third-party certifier.
- A trusted root certificate for a Domino or third-party certifier.
- (Notes clients only) A cross-certificate for the Domino or third-party certifier created from the trusted root certificate. The trusted root certificate is not necessary for Notes clients after you create the cross-certificate.
- Software, such as a Web browser or a Notes workstation, that supports the use of SSL.
If an LDAP client supports the Simple Authentication and Security Layer protocol (SASL), Domino automatically uses this protocol when the client uses SSL client authentication to connect to the server. SASL is not supported for TCP/IP connections or SSL connections with only server authentication.
To set up Notes clients with certificates issued by a Domino CA
About this task
The CA and client complete these steps.
Procedure
To set up Internet clients with certificates issued by a Domino CA
Procedure
- The CA administrator creates a Person document for the Internet client.
- The client obtains the trusted root certificate for the server's CA.
- The client requests the Internet certificate from the CA.
- The CA approves the request, and Domino automatically adds the client's public key to the user's Person document.
- The client merges the certificate into the local file.
To set up Notes and Internet clients with certificates issued by a third-party CA
About this task
The CA and client complete these steps.
Procedure
- (Internet clients only) The CA administrator creates a Person document for the client.
- Using any browser, the client follows the third-party CA's established procedure to request and merge the Internet certificate.
- The Internet client follows the third-party CA's established procedure to merge the trusted root certificate for the CA.
- The CA adds the client's public key to the Person document.
Example
For example, to obtain an Internet certificate from VeriSign, visit the site SSL Certificate Authority and Digital IDs in the related links and follow the instructions provided.