Manage NIM Certificates and PGP Keys
Configuration → Settings → Certificates
Manage the certificates and PGP keys NIM uses to secure browser access, authenticate connections, and protect files exchanged with other systems.
NIM stores imported certificate material encrypted in C:\ProgramData\Tools4ever\NIM\config\certs. Treat certificate lifecycle management as an operational responsibility: use descriptive names, limit access to private keys, record ownership, and renew certificates before they expire.
Choose the certificate for the jobDirect link to Choose the certificate for the job
| Need | Certificate or key | Start here |
|---|---|---|
| Secure access to the NIM web interface | HTTPS certificate | Configure HTTPS |
| Authenticate NIM to a REST system or directory | Provider-issued client certificate, commonly .pfx or .p12 | Add or remove a certificate |
| Connect securely to LDAP | Trusted certificate appropriate to the LDAP connection | Configure LDAP |
| Decrypt imported CSV files or encrypt exported files | PGP public/private key, commonly .asc | Use PGP encryption |
Common certificate tasksDirect link to Common certificate tasks
Import or remove a certificate
Add a named certificate file to NIM, provide its password when required, or remove a certificate that is no longer in use.
Manage certificates →Enable HTTPS
Use a valid certificate to protect browser access to NIM and every public self-service or onboarding URL.
Configure HTTPS →Protect imported and exported files
Generate, import, and export PGP keys for encrypted CSV exchange with trusted partners and systems.
Use PGP encryption →Monitor upcoming expiration
Create a notification workflow so certificate owners have time to renew before a connection or public endpoint fails.
Build expiration notifications →Prepare the file before importDirect link to Prepare the file before import
NIM accepts .pfx, .p12, and .asc certificate files. Confirm the intended use before adding a file.
- Use
.pfxor.p12when NIM needs the certificate and private key for a secure connection or client authentication. - Use
.ascfor PGP public or private keys used in encrypted file exchange. - Obtain REST connector certificates from the system provider or follow its connection guide. For example, see Microsoft Entra ID connection setup or Google Workspace connection setup.
- Keep private keys and their passwords in your organization’s approved secret-management process. Do not place private keys in email, shared tickets, or unsecured file shares.
Use a name that identifies the system, purpose, and renewal owner—for example, Entra-Production-ClientAuth or Partner-SFTP-PGP-2026. It makes connection maintenance and expiry response much safer.
Keep certificates healthyDirect link to Keep certificates healthy
Assign an owner
Record who can renew each certificate and which NIM systems, workflows, or endpoints depend on it.
Alert before expiry
Use the certificate expiration tutorial to notify the responsible team early.
Test after replacement
After importing a renewed certificate, test the affected connection, HTTPS endpoint, or encrypted file workflow before retiring the old certificate.
Troubleshoot a certificate list or trust errorDirect link to Troubleshoot a certificate list or trust error
If the certificate list does not load, first review the NIM logs for TLS, ACME, proxy, or certificate-chain errors. For Let’s Encrypt workflows, confirm the NIM server can reach prod.api.letsencrypt.org and that web filtering is not intercepting or blocking the request.
An error such as UNABLE_TO_GET_ISSUER_CERT_LOCALLY normally indicates that NIM cannot validate a required certificate authority (CA) chain. Work with the network or security team to install or make the trusted CA available to the NIM service.
Add a trusted CA for the NIM serviceDirect link to Add a trusted CA for the NIM service
When your organization uses an internal CA or TLS-inspecting proxy, you can configure the NIM service to trust its CA certificate:
- On the NIM server, open Registry Editor and go to
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NIM. - Create an
envkey if it does not already exist. - Add a String value named
NODE_EXTRA_CA_CERTSwith the full path to the trusted.cerfile, for exampleC:\ProgramData\Tools4ever\NIM\config\certs\MyCert.cer. - Restart the NIM service using your organization’s approved change process, then retry the certificate or connection operation.
Avoid setting NODE_TLS_REJECT_UNAUTHORIZED to 0. That bypasses certificate validation for the NIM service and should not be used as a permanent fix. Correct the trust chain or network filtering issue instead; involve Tools4ever Support if you need help diagnosing it.