SECURING


1. Issuing a Multi-Factor Authentication Certificate

To allow the use of time-based one-time password (TOTP) authentication, use themfamgt server command to issue a Multi-Factor Authentication Certificate for the the organization unit (OU) or organization (O) of those users that will be using TOTP.

Before you begin

Make sure your ID vault server runs Domino 12 and the ID vault database is upgraded to the Domino 12 idvault.ntf template design.

Procedure

1. At the console of a vault server, issue the following command:

2. Replicate the Domino directory changes to all servers in the domain.

3. Open the Domino directory on any server in the domain, select theCertificates view, and verify that you see a Multi-Factor Authentication Certificate similar to the following one: Example Multi-Factor Authentication Certificate for /mfatest1

4. Issue the show idvault command and verify that output lists the MFA trust for the correct organization, as shown in bold in the following example:


Parent topic: Configuring TOTP authentication
Next topic: 2. Enabling TOTP authentication in the Configuration Settings document