Hi,
To create new keyrings please follow the instructions here:
https://www-10.lotus.com/ldd/dominowiki.nsf/dx/3rd_Party_SHA-2_with_OpenSSL_and_kyrtool
how many certificates you need depends. In short and simplified: you need a certificate for every CN/Hostname you use. So if all your 15 sites have different hostnames, you need 15 certs.
Alternatively you can use either wildcard certificates or "Subject Alternate Names -SAN" in your certificate. The later would mean one certificate per server with 14 SANs, which is quite expensive. I never used SANs in Domino, so you might want to doublecheck first.
Hope that helps,
Manuel