SECURING


Importing and cross-certifying the IdP Internet certificate

When SSL is used between an IdP and Domino, import the IdP SSL certificate into the Domino directory and cross-certify it.

Procedure

1. Connect to the IdP using the Firefox browser.

2. Click the certificates lock icon in the address bar and view the certificates.

3. Click the Details tab and select the Certificates KeyUsage field.

4. Verify that the Certificates KeyUsage field contains values forCertificate Signer and CRL Signer. In the following example, the values are missing:Certificate fields without Certificate Signer and CRL Signer


5. Export the selected certificate and save it as a Base 64 encoded X.509 Certificate (.cer) file. In ADFS, use the following steps: 6. Import the certificate into the Domino directory used by the ID vault and web servers and then cross-certify it:
Parent topic: Preparing for SAML authentication
Previous topic: Completing Domino prerequisites for SAML
Next topic: Creating and replicating the IdP Catalog