Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.

For more information and upcoming events around #dominoforever, please visit our Destination Domino Page


My ideas: Security

Showing 301

IDVault:Need increase one view to display all these archived user id file document Now all user ID file documents display under the default "Vault Users" view For these archived user ID file, which display as ~UserName also in th...
almost 3 years ago in Domino / Security 0 Needs Review

Prompt for user content before configuring notes client.

This is to control & monitor user and admin activity in terms of account access. ( just want user consent before configuring notes client on behalf of the user.). Basically, customer have MFA for notes, but none for lotus notes client security...
almost 3 years ago in Domino / Security 1 No Plans to Implement

Option to select whether the LTPAToken should be completely removed/or usable when session has been completely ended.

When enabling Session authentication across servers, the token issued by a server can still be used even after the session has been completely ended on the server and on the browser. If a user issues a request to the server using the same token, y...
almost 3 years ago in Domino / Security 1 Under Consideration

Setting not to display the Access Control List settings

Notes users who don't have administrator privileges cannot change ACLs of Database but can view the settings of Access Control List. We do not want to show the group names, server names, user name etc. displayed in the Access Control List to them...
almost 3 years ago in Domino / Security 0 Under Consideration

Tool to remove the internet certificate from the server ID

The "Delete from ID file" action from the User Security (in Notes) or ID Properties (in Admin client > Configuration tab) is greyed out when trying to remove an internet certificate from the server ID. We would like to request a tool that will ...
almost 3 years ago in Domino / Security 0 Under Consideration

Block users that dont have a smartcard enabled ID-file

Today it is possible for users to smartcard enable their own ID-file and then use the smartcard to login to the Notes environment. Make it possible to block users that dont have a smartcard-enabled ID. Or in some way force users that they must use...
almost 3 years ago in Domino / Security 0 Under Consideration

Internet Lockout not per server, but per website or per domain.

When you have a clustered Domino backend for hosting websites or web-apps, and you have a loadbalancer in front of them......and internet lockout only occurs per's possible that you end up on another cluster-member and can continue t...
about 3 years ago in Domino / Security 2 Assessment

Force logout web mail users (i.e. Verse & iNotes)

Customer wants to apply a force logout to users whose accounts are compromised. Changing their password or restarting http task does not automatically logout the user. Waiting for token expiration could be risky if set for a long duration. Current...
about 3 years ago in Domino / Security 1 Under Consideration

Restrict the number of messages a single user can send in 24 hours to a maximum number of messages

Sometimes users are victims of clever phishing emails sent to them. Unfortunately this opens up the use of their valuable credentials to potential hackers. These hackers can then send email using their credentials. If Domino would have an internal...
about 3 years ago in Domino / Security 3 Under Consideration

SMTP Inbound Certificate validation

Today Domino accepts mail from hosts with any x.509 certificate. there is no verification. It's difficult to only allow mails from trusted certificates. But it would be important to have the information if the connection was coming from a connecti...
about 3 years ago in Domino / Security 0 Under Consideration