SECURING


Enabling Notes federated login

Enable Notes federated login to allow Notes clients users to start Notes and perform secure operations without being prompted for a Notes ID password.

Before you begin

Complete the following prerequisites:


Procedure

1. In the Domino Directory, open the existing Security Settings policy for users of your organization’s ID vault.

2. On the ID Vault tab, make sure there is an assigned vault.

3. Select the Password Management -> Federated Login tab.

4. Select Yes for Enable Notes federated login with SAML IdP.

5. For client users who have upgraded to 9.0.1, when the policy is initially being deployed, underAdditional settings for Federated Login (Notes or Web), select Yes forAllow password authentication with the ID vault.


6. Optional: Create custom messages for users to notify them when federated login is either enabled or disabled.

7. Select the Keys and Certificates tab.

8. To add the Notes certifier to the policy, in theAdministrative Trust Defaults section, click Update Links.

9. Choose Selected supported and click OK.

10. Click the Notes Certifiers tab, select the certificates which signed the IDs of the Notes users, and click OK.


11. Click the Internet Cross Certificates tab, select the cross certificate from the Notes root certifier to the certificate exported from either ADFS or TFIM 2.0, and clickOK.

12. Click the Internet Certificates tab, select the SSL certificate exported from either ADFS or TFIM 2.0, and click OK.

13. Verify that a chain of at least three certificates is shown (more if there are organization unit certificates): the Notes certifier at the top, the internet cross certificate in the middle, and the internet certificate at the bottom.


14. Optional: Enter a formula under Machine specific formula to apply the policy to specific computers for clients who have multiple computers.

15. Save and close the security policy.

16. From the Domino Administrator, open the ID vault application (idvault.nsf), which by default is stored in theIBM_ID_VAULT directory. Complete the following steps:


What to do next

Testing Notes federated loginIf you enable Notes federated login, use your test user to test that it is working.


Parent topic: Using Security Assertion Markup Language (SAML) to configure federated-identity authentication