Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.

For more information and upcoming events around #dominoforever, please visit our Destination Domino Page

ADD A NEW IDEA

Security

Showing 295

Check on server.id password (history ) like on users.

We would like to have the ability to check on server.id passwords. We would like to store the latest, and history, password on all server.id's so for security reasons like we see with users.
almost 6 years ago in Domino / Security 1 Assessment

Ability to journal already encrypted mail

Ability to journal already encrypted mail
almost 6 years ago in Domino / Security 0 Under Consideration

Cleanup of web certificates in the server ID is missing

Cleanup of web certificates in the server ID is missing
almost 6 years ago in Domino / Security 0 Under Consideration

Offline availability for Notes (client) in case of expired ADFS certificates

Offline availability for Notes (client) in case of expired ADFS certificates
almost 6 years ago in Domino / Security 0 Under Consideration

Allow mails from specific IP Addresses to be sent to Groups

Deny mails from outside to be sent to specific groups - You can following this path: From the Admin client - Configuration tab - Messaging - Router/SMTP - SMTP inbound controls - Inbound Intended Recipient Control - Deny messages intended for the ...
almost 6 years ago in Domino / Security 0 Under Consideration

Add logout endpoint to DRAPI's oauth system

The .well-known/openid-configuration in DRAPI does not show a logout endpoint. A client web application can use the /oauth/authorization and /oauth/token endpoints to authenticate and refresh the authorization token. A logout is currently only pos...
23 days ago in Domino / Security 0 Needs Review

Restart/maintenance shouldn't require user-reauthentication in HCL Verse. But make a setting for this

Today when restarting server (http service) users are required to reauthenticate to HCL Verse. This sets limitations when performing maintenance. Reauthentication should be a setting to be adjusted according to security guidelines.
about 1 month ago in Domino / Security 2 Needs Clarification

SAML user binding using email

Binding SAML user identity using email is an good way but insecure way.Because a user at an connected IDP could if open go in and change email address and then become another user. It would be good to increase security to add a secondary field tha...
about 2 months ago in Domino / Security 2 Needs Clarification

Server.id protection should not be a problem when creating ServiceProvider.xml in idpcat.nsf

You cannot create the ServiceProvider.xml when your server.id has protection. A see a popup "You are not authorized to perform that operation". This leads usto the server.id protection. When we disable it, we can create the ServiceProvider.xml in ...
3 months ago in Domino / Security 3 Needs Review

Move server.id into the IDVault

Move the server.id into the IDVault and protect the deployment. Let only the correct Domino server extract the server.id from the IDVault.
3 months ago in Domino / Security 2 Under Consideration