SECURING


Enabling the Domino ID vault server to support Notes federated login
The Domino® administrator specifies SAML configuration settings for Notes® federated login in IdP Configuration document(s) in the IdP Catalog (idpcat.nsf) application.

Before you begin


About this task

The SAML configuration settings for Notes federated login are specified in IdP Configuration document(s) in the IdP Catalog (idpcat.nsf) application. The IdP Configuration document includes several fields whose values are supplied automatically when you import the metadata.xml file from the IdP.

Important: If the Domino server has a server.id file protected by a password, the administrator cannot use the Create Certificate button described in this topic. Instead, see the related topic Creating a Domino metadata file manually.

Note: This procedure assumes the Domino ID vault server participating in Notes federated login does not have the Domino Web server configured, but your organization may use such a combination if necessary.

Note: To support Notes federated login, certain fields in this IdP Configuration document (Service provider ID and Domino URL) must be specified with a string that mimics the URL that would be used if the ID Vault server were also configured as a Domino Web server. However, this does not mean the ID vault server must actually be configured as a Domino Web server.

Procedure

1. From the Domino Administrator client, create the IdP Catalog application (idpcat.nsf), using the template with the file name idpcat.ntf, or open the application if it already exists.


2. It is recommended that you restrict the ACL highly. Assign access in the ACL only to the Domino server, and to any Domino SAML administrator(s) who are trusted to manage security.
3. Click Add IdP Config to create a new configuration document.
4. On the Basics tab, in the Host names or addresses mapped to this site field, enter either an IP address or Web address (DNS hostname, or Internet site name), or both, representing the Domino ID vault server. If you enter both, separate the IP from the Web address using a semicolon, for example, n.nn.nnn.n; www.renovations.com. The order of addresses does not matter, and you can enter multiple items, separated by semicolons.
5. In the IdP name field, enter a name to identify the Web site of the identity provider; the name does not have to be exact, and is only for your administrative convenience.
6. In the Protocol version field, select a SAML version.
7. Leave State for this Configuration document as Enabled (the default).

8. In the Federation product field, select either TFIM for Tivoli Federated Identity Manager or ADFS for Microsoft Active Directory Federation Services, depending on which federation service you intend to use for SAML authentication. The default is ADFS.

9. In the Service provider ID field, enter a string that identifies Domino as a service provider partner with the IdP.


10. Click Import XML file, and specify the metadata.xml file exported from the IdP.
11. On the Client Settings tab, perform all of the following substeps:
12. If you are using SAML 2.0 and need to export a certificate from Domino to use at the IdP, on the Certificate Management tab, perform all of the following substeps: 13. At the beginning of the form, click the Export XML button to save the created idp.xml file as an attachment to the document.
14. Save and close the IdP Configuration document.

Parent topic: Supporting federated login on the Notes client
Previous topic: Setting up the SAML identity provider and federation
Next topic: Configuring the ID vault for Notes federated login

Related tasks
Creating a Domino metadata file manually
Enabling the Domino Web server to provide SAML authentication
Configuring SAML from the Internet Site (Web Site) document

Related information
Supplementary information on Security Assertion Markup Language (SAML) configuration combinations of IBM Domino and other products