You can configure a passphrase in a file (see 
               		To Configure the Passphrase in a File for more information), or you can set it when you start the 
               		Enterprise Server instance. To set a passphrase when you start the instance: 
               	 
            
 
            	 
             
               		
               - Start your enterprise server from the home page of ES Admin and wait for it to start. 
                  		
               
- Go to the Listeners page and find your TLS-enabled listener. The status column should indicate "Start pending" and the Status
                  Log column should show "Waiting for keyfile passphrase". 
                  		
               
- Click 
                  		  Authorize in the Status column of the TLS-enabled listener. 
                  		
               
- Enter your passphrases and click 
                  		  Set passphrases. 
                  		
               
- Confirm that the status of the TLS-enabled listener is now "Started", by looking at the main Listeners page (and clicking
                  
                  		  Refresh if necessary). 
                  		
               
Note:  
               		
                
                  		  
                  - If you have problems starting or running an SSL-enabled listener, it can be useful to look at the MFCS log. Click 
                     			 Server > 
                     			 Diagnostics > 
                     			 CS Console. 
                     		  
                  
- The passphrase is not tested against the certificate and keyfile until an attempt is made to start the listener.