1. In the Domino Administrator, click Configuration - Certification - Rollover Certifer Keys.
2. In the Generate New Certifier Key dialog box, click Directory Server and specify a registration server in the list box that appears.
3. Click ID file. In the Choose Certifier ID dialog, select the certifier ID file for which you want to assign new keys.
4. At this point, the options in Generate New Certifier Key dialog box change, depending on whether you chose a top-level certifier ID or an intermediate one.
Click OK. This generates the new key pair and adds it to the top-level certifier ID.