Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.

For more information and upcoming events around #dominoforever, please visit our Destination Domino Page

ADD A NEW IDEA

My ideas: Security

Showing 273 of 7962

Fix the ID vault so it doesn't use a separate ID file or capture that ID file so it isn't lost all the time

Time and time again, I encounter environments where no one has a copy of the ID file used to create the ID Vault. This is because during the process of creating the vault, there was no warning of the importance of the ID file created at the time a...
2 months ago in Domino / Security 0 Needs Review

Whitelist Active Content Filter on iNotes

We can use the parameter iNotes_WA_DisableActCntSecurity=1 to disable the Active Content Filter on iNotes and this removes potentially harmful active content from HTML in mail messages prior to display in a browser. However, using the parameter ...
3 months ago in Domino / Security 1 Needs Review

Possibility to log in via certificate AND password

Currently you can set Domino to authenticate users via password OR certificate. It would increase security when login using certificate is selected and additionaly user is asked for his notes/internet password (as second factor). Then the security...
3 months ago in Domino / Security 0 Needs Review

have a seperate port for webmail and verse clients,

there should be an option to block the webmail page, while affecting no verse client. Currently if I block http port 443 it is affecting both webmail and verse clients where as technically there should be seperate handles for both the services.So ...
9 months ago in Domino / Security 1 No Plans to Implement

Certmgr: certificate per internet site not per server

If you use multiple internet site documents per one server with different certificates for each one you cannot use certmgr and certstore db. TLS Credentials should be configred per virtual server/Internet Site/Web Site not per entire Domino server.
11 months ago in Domino / Security 1 Already Exists

Support PEM in addtion to KYR for Lotus Script/Java AddInternetCertificateToUser()

There are a couple of use-cases where importing certificates into a person document are important. Beside this Lotus Script method the only other method would be the C-API (SECNABAddCertificate() which only supports DER format by the way). Now tha...
about 1 year ago in Domino / Security 0 Under Consideration

Samesite attributes to be strict or lax for the sessionID this is usually found on the application that uses XPAGES.

After following the article below, only DomAuthSessId can only be setup to strict or lax. The samesite attributes of the sessionID have no value. https://help.hcltechsw.com/domino/12.0.0/admin/conf_samesite_cookie.html
about 1 year ago in Domino / Security 2 Already Exists

Web site rules document allows to apply wildcard (*) for HTTP response codes with exceptional codes

This feature is created as requested by customer. There are many HTTP response codes, so it will be much more efficient if the feature of " internet site document allows to apply wildcard (*) for HTTP response codes with exceptional codes" can be ...
over 1 year ago in Domino / Security 0 Needs Review

To Disable Backward/Forward arrow from the iNotes browser window

Hello Team, This is regards with iNotes web Access. Currently we can see the Backward Arrow Active and end users are able to use Backward and forward arrow in the browser. Customer would like to Disable the Backward/Forward arrow from the Browser ...
over 1 year ago in Domino / Security 1 No Plans to Implement

Disabling wink to be used as a potential attack vector

Seeing more and more attempts to use Wink as an attack vector (see example below). Looking into possibility to disable wink so that it wont cause any potential security risk. 03/17/2022 10:04:27 AM HTTP JVM: 1399490 [Thread-11] INFO org.apache.win...
over 1 year ago in Domino / Security 2 Already Exists