SECURING


Automatically generating a certificate to encrypt SAML assertions

You can generate a certificate to use to encrypt SAML assertions automatically from an IdP configuration document.

About this task

Create the certificate from the server that will authenticate users. For web users (web federated login), create the certificate for each mail server, to allow the use of secure mail operations. For Notes users (Notes federated login), create the certificate from the ID vault server.

You can use this procedure if the server ID file is not password protected and if you want to create a new Internet Certificate in the server ID file. Otherwise, follow the procedure to generate the certificate manually.

To complete this task, you must be listed (or belong to a group) in the Server document, inFull Access Administrators >Administrators >Sign or run unrestricted methods and operations.

Generate the certificate automatically with the Create Certificate button in the IdP configuration document.

Note: Complete this procedure before you use theExport XML button in an IdP configuration document to export the configuration to theidp.xml file. Then, the certificate is automatically included in the Domino metadata .xml file (idp.xml) that you import into the IdP.

Procedure

1. Open a Web server IdP configuration document or the ID vault server IdP configuration document in idpcat.nsf. Open it on the server that you want to generate the certificate.

2. Click the Certificate Management tab.

3. Click Create SP Certificate. In the Create company certificate prompt, enter your company name and click OK to add the name to the Company Name field.


4. In the Domino URL field, enter a string to identify the fully qualified DNS name in a URL of the Domino server.
5. In the Single logout URL field, enter a URL. Even if your IdP does not require or support a single logout, you should enter a syntactically correct URL so that the exported metadata file will have proper syntax. The TFIM IdP with SAML 2.0 configuration requires a single logout URL to be specified at the IdP and in the Domino metadata file, even though Domino does not currently implement a SAML 2.0 single logout feature.
What to do next

Export the Web server or ID vault server configuration toidp.xml.

Parent topic: Generating a certificate to encrypt SAML assertions

Related tasks
Exporting the Domino web configuration to an .xml file
Exporting the ID vault server configuration to an .xml file