Configuring Global Settings
Configure Global Settings to set default values to use for certificate management.
About this task
Procedure
- Open certstore.nsf.
- Click Edit Global Settings.
- In the Admin server field, select the Domino server that will manage certificate processing for the domain.
-
In the Key algorithm field, select one of the following
options:
- RSA Then, select a Key Size. The default key size is 4096.
- ECDSA. Then, select a Curve Name. The default is curve name is NIST P-384. For more information on ECDSA, see ECDSA cryptography support for ACME accounts and for host keys.
-
In the Certificate provider field, select one of the
following options:
- ACME Select this option to use the Let's Encrypt CA.
- Manual Select this option to use another third-party CA.
-
If you selected ACME as the certificate provider, in the
ACME account field, select one of the following
options:
- LetsEncryptStaging Select this option when testing.
- LetsEncryptProduction Select this option for production use.
The staging environment is suitable for testing because it has a higher rate limit and uses an untrusted root certificate. The staging environment's root certificate is not included in any browser. You should manually install it for the duration of the testing and then immediately remove it.
The Let's Encrypt® production environment has stricter rate limits and will fail temporarily if you exceed the limits.
For more information, see the Let's Encrypt documentation on Rate Limits.