avoid self signed certs
self signed certs should be considered
for testing purposes only
strongly recommend a certifcate with
a domino CA or a 3rd party CA instead as it will include the cert chain
so the client can generate the needed certificate trust chain
as it stands today you're unable to
use that database to create a selfsigned certificate of 2048 strength