1.4.5.5.4.3. Automatic certificate search and manual selection

If the configuration key `certname ` is not set, the server automatically searches the Windows certificate store for a valid certificate that matches the server's hostname. Alternatively, certname can be set to the Common Name (CN) or Subject Alternative Name (SAN) of the desired certificate :

certname = meinserver.firma.de
[Note]Note

Certificates from the Windows certificate store are used automatically if they meet the following requirements: The CommonName or SubjectAlternateName must match the machine's hostname, the certificate must be issued for server authentication and be valid (not expired), and the service user must have access to the private key.