SECURING
Enable Notes federated login to allow Notes clients users to start Notes and perform secure operations without being prompted for a Notes ID password.
Before you begin
Complete the following prerequisites:
1. In the Domino Directory, open the existing Security Settings policy for users of your organization’s ID vault.
2. On the ID Vault tab, make sure there is an assigned vault.
3. Select the Password Management -> Federated Login tab.
4. Select Yes for Enable Notes federated login with SAML IdP.
5. For client users who have upgraded to 9.0.1, when the policy is initially being deployed, underAdditional settings for Federated Login (Notes or Web), select Yes forAllow password authentication with the ID vault.
7. Select the Keys and Certificates tab.
8. To add the Notes certifier to the policy, in theAdministrative Trust Defaults section, click Update Links.
9. Choose Selected supported and click OK.
10. Click the Notes Certifiers tab, select the certificates which signed the IDs of the Notes users, and click OK.
12. Click the Internet Certificates tab, select the SSL certificate exported from either ADFS or TFIM 2.0, and click OK.
13. Verify that a chain of at least three certificates is shown (more if there are organization unit certificates): the Notes certifier at the top, the internet cross certificate in the middle, and the internet certificate at the bottom.
15. Save and close the security policy.
16. From the Domino Administrator, open the ID vault application (idvault.nsf), which by default is stored in theIBM_ID_VAULT directory. Complete the following steps:
b. In the field Notes federated login approved IdP configurations, enter the host name from the Host names or addresses mapped to this site field of the ID vault server IdP configuration document, for examplevault.domino1.us.renovations.com.
c. Click Save & Close.
Testing Notes federated loginIf you enable Notes federated login, use your test user to test that it is working.
Using Notes federated login in combination with Notes Shared Login to support offline users (Windows only) If your organization uses Windows™ for your Notes clients, you can configure a combination of Notes federated login and the Notes shared login feature. The Notes shared login feature ensures that the Notes user will not be prompted for an ID file password, and this feature is needed if the Notes client operates offline. If there is any situation where the Notes client id file is missing from the desktop, Notes federated login feature ensures that SAML authentication can be used to retrieve the user's ID file from the vault (SAML authentication must be accomplished when the Notes client is operating online).