Skip to main content

Manage NIM Certificates and PGP Keys

Configuration → Settings → Certificates

Manage the certificates and PGP keys NIM uses to secure browser access, authenticate connections, and protect files exchanged with other systems.

NIM stores imported certificate material encrypted in C:\ProgramData\Tools4ever\NIM\config\certs. Treat certificate lifecycle management as an operational responsibility: use descriptive names, limit access to private keys, record ownership, and renew certificates before they expire.

Choose the certificate for the jobDirect link to Choose the certificate for the job

NeedCertificate or keyStart here
Secure access to the NIM web interfaceHTTPS certificateConfigure HTTPS
Authenticate NIM to a REST system or directoryProvider-issued client certificate, commonly .pfx or .p12Add or remove a certificate
Connect securely to LDAPTrusted certificate appropriate to the LDAP connectionConfigure LDAP
Decrypt imported CSV files or encrypt exported filesPGP public/private key, commonly .ascUse PGP encryption

Common certificate tasksDirect link to Common certificate tasks

Prepare the file before importDirect link to Prepare the file before import

NIM accepts .pfx, .p12, and .asc certificate files. Confirm the intended use before adding a file.

  • Use .pfx or .p12 when NIM needs the certificate and private key for a secure connection or client authentication.
  • Use .asc for PGP public or private keys used in encrypted file exchange.
  • Obtain REST connector certificates from the system provider or follow its connection guide. For example, see Microsoft Entra ID connection setup or Google Workspace connection setup.
  • Keep private keys and their passwords in your organization’s approved secret-management process. Do not place private keys in email, shared tickets, or unsecured file shares.
Certificate names matter

Use a name that identifies the system, purpose, and renewal owner—for example, Entra-Production-ClientAuth or Partner-SFTP-PGP-2026. It makes connection maintenance and expiry response much safer.

Keep certificates healthyDirect link to Keep certificates healthy

Assign an owner
Record who can renew each certificate and which NIM systems, workflows, or endpoints depend on it.

Alert before expiry
Use the certificate expiration tutorial to notify the responsible team early.

Test after replacement
After importing a renewed certificate, test the affected connection, HTTPS endpoint, or encrypted file workflow before retiring the old certificate.

Troubleshoot a certificate list or trust errorDirect link to Troubleshoot a certificate list or trust error

If the certificate list does not load, first review the NIM logs for TLS, ACME, proxy, or certificate-chain errors. For Let’s Encrypt workflows, confirm the NIM server can reach prod.api.letsencrypt.org and that web filtering is not intercepting or blocking the request.

An error such as UNABLE_TO_GET_ISSUER_CERT_LOCALLY normally indicates that NIM cannot validate a required certificate authority (CA) chain. Work with the network or security team to install or make the trusted CA available to the NIM service.

Add a trusted CA for the NIM serviceDirect link to Add a trusted CA for the NIM service

When your organization uses an internal CA or TLS-inspecting proxy, you can configure the NIM service to trust its CA certificate:

  1. On the NIM server, open Registry Editor and go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NIM.
  2. Create an env key if it does not already exist.
  3. Add a String value named NODE_EXTRA_CA_CERTS with the full path to the trusted .cer file, for example C:\ProgramData\Tools4ever\NIM\config\certs\MyCert.cer.
  4. Restart the NIM service using your organization’s approved change process, then retry the certificate or connection operation.

Do not disable TLS certificate validation

Avoid setting NODE_TLS_REJECT_UNAUTHORIZED to 0. That bypasses certificate validation for the NIM service and should not be used as a permanent fix. Correct the trust chain or network filtering issue instead; involve Tools4ever Support if you need help diagnosing it.