Workaround for startssl and Domino【转】

本文详细介绍了一种在Linux服务器上使用OpenSSL为IBM Domino环境创建StartSSL免费证书的方法。包括生成密钥文件、CSR文件及PKCS12文件的过程,并介绍了如何利用GSK5-iKeyMan导入.p12文件到Domino密钥环中。
Hi,

I don’t know if you still need it but here is my workaround to get a StartSSL free certificate in Domino.

I use OpenSSL on my Linux server to create a new certificat(证明):
Here are the command I used to create a key and a csr file:

* openssl genrsa -des3 -out keyfile.key 2048

* openssl req -new -key keyfile.key -out request.csr (Answer the usual question)

------kefile.key/request.csr


Ask the certificate at startssl with the CSR file.

-------request.csr-->cert.crt


With your new cert file, you have to create a PKCS (.p12) key file using openssl:

* openssl pkcs12 -export -in cert.crt -inkey keyfile.key -out cert.p12

-----cert.crt+kefile=cert.p12


Create a new keyring (.kyr) file, using the certsrv.nsf database using the SAME information from the linux certificate.

Import the StartSSL Root certificate into the key ring file:
Get the "ca.pem" certificate and Merge it into your kyr file.
Get the "Sub Class 1" certificate and Merge it into your kyr file.


Now the tricky  part… 

To import the .p12 file into a Domino keyring, you need GSK5-iKeyMan(DOWNLOAD)
(This tool might not work in Windows Vista and newer OS, it’s working in 2003)
  • Extract the gsk5-ikeyman.zip file into a directory that has no spaces in the name
  • Start the command line shell (cmd), change directory to the directory where you extracted gsk5.
  • Execute the following command: gskregmod.bat Add
  • Run IKeyman by executing: runikeyman.bat
  • Open the keyfile.kyr file that we created earlier and enter the keyring password.
  • Select Personal certificates and click Import
  • Select the certificate file (.p12) and enter the certificate's password.
Shutdown (关机)  IKeyman and copy the keyfile.kyr and matching keyfile.sth to your  Domino   server's data directory.

Configure your Domino server to use this keyring file and  restart   the http task (or restart domino).


*** Weird thing… 

When I tried to Import my “www.mydomain.com” PKCS key into my keyring, I got a bad p12 certificat(证明) error from gsk5. Everything went well with my 3 other “test” keyring. To test my keyring, I imported my “test.p12” file into my “www” keyring and it worked. I then retry  to import my “www.p12” into the keyring and it was now ok. I removed the “test” certificate from the keyring. I noticed that my “www.crt” was not the same size as my test.crt file… maybe something is missing in the www one!!!!

(I hope I’m clear enough ;-)

With this procedure, I can even import any of my existing certificates into a keyring.

Have a nice free SSL testing!!! :-)

Pat

Feedback number  WEBB8H8UMU  created by  on  2012-12-13
光伏储能虚拟同步发电机VSG并网仿真模型(Similink仿真实现)内容概要:本文档介绍了光伏储能虚拟同步发电机(VSG)并网仿真模型的Simulink实现方法,重点在于通过建立光伏储能系统与虚拟同步发电机相结合的仿真模型,模拟其在并网过程中的动态响应与控制特性。该模型借鉴了同步发电机的惯性和阻尼特性,提升了新能源并网系统的频率和电压支撑能力,增强了系统的稳定性与可控性。文档还提及相关电力系统仿真技术的应用,包括逆变器控制、储能配置、并网稳定性分析等,并提供了完整的Simulink仿真文件及技术支持资源链接,便于科研人员复现与二次开发。; 适合人群:电气工程、自动化、能源系统等相关专业的研究生、科研人员及从事新能源并网技术开发的工程师。; 使用场景及目标:①用于研究光伏储能系统在弱电网条件下的并网稳定性问题;②掌握虚拟同步发电机(VSG)控制策略的设计与仿真方法;③支持高水平论文(如EI/SCI)的模型复现与创新研究;④为微电网、智能电网中的分布式能源接入提供技术参考。; 阅读建议:建议结合提供的Simulink模型文件与文档说明逐步操作,重点关注VSG控制模块的参数设置与动态响应分析,同时可延伸学习文中提及的MPPT、储能管理、谐波分析等相关技术,以提升综合仿真能力。
评论
成就一亿技术人!
拼手气红包6.0元
还能输入1000个字符
 
红包 添加红包
表情包 插入表情
 条评论被折叠 查看
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值