This will help you get a signed certificate for your dn42 domain.
Download the client shell script from the link below
Get a re-usable token verifying your DN42 identity:
Save the provided token under a file called 'token.txt' alongside the script
Run ./client.sh get_certificate <domain.dn42> (replace the parameters in brackets with the correct values) to generate a certificate and have it signed
Configure the signed.crt and server.key files resulting from the previous command in your webserver.