Wonderful certstore.nsf tool.
Now that Domino is able to easily create certificates, it is necessary to create clear documentation to be able to create self-generated client certificates and easily distribute them on devices, especially web browsers and mobile devices for Traveler.
Certstore.nsf is capable of creating self-signed certificates with very distant expiration times. Their use would allow, for example, to use the internet password very rarely, and instead authenticate internet clients via their client certificate. Using self-generated client certificates in this way would, in my opinion, considerably reduce the inconveniences due to internet password blocking (inetlockout.nsf) whereby, due to attempts to break in the internet password by third parties, the account is blocked and the user is no longer able to use webmail or Traveler.
However, the documentation regarding the generation of self-generated client certificates and their distribution is now fragmented and not organic.
Those best practices were shared at user group conferences. (Hint: why not join them?)
https://www.youtube.com/watch?v=M0p8O10Wdbo