Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.

For more information and upcoming events around #dominoforever, please visit our Destination Domino Page

ADD A NEW IDEA

Security

Showing 35

Disable core REST API

If Rest API are disabled on the server, this Core API - hostname/api/core/nonce should not be accessible or not available when a user generated the request from browser.
about 5 years ago in Domino / Security 4 Needs Clarification

TOTP (MFA) Scratch code - set expiry date and limit number of codes generated

When Scratch codes are generated for TOTP setup there are 10 codes generated with no expiry date and I have the following suggestions : 1) Add an "Scratch Code Expiry Time (hrs)" so administrators can set the code to expire for example after 48 ho...
about 4 years ago in Domino / Security 1 Needs Clarification

SAML user binding using email

Binding SAML user identity using email is an good way but insecure way.Because a user at an connected IDP could if open go in and change email address and then become another user. It would be good to increase security to add a secondary field tha...
about 1 year ago in Domino / Security 2 Needs Clarification

Configure at least 3 SMTP ports for Domino

Recent Internet providers are OP25B and cannot connect to port 25. Domino allows you to set up additional ports for SSL, but you can only set up to two ports for SMTP, and you cannot use port 25, 465, and a submission port (587) together. https:...
over 2 years ago in Domino / Security 2 Needs Clarification

Option to relocate ../data/cacert.pem outside Domino data

We added several certificates into cacert.pem when using NotesHTTPrequest call in LotusScript. After a update or upgrade, this file is renewed. Please introduce a notes.ini parameter to relocate this file to ( example ) /local/cacerts/cacert.pem
about 1 year ago in Domino / Security 3 Needs Clarification

Prevent Off-Site Redirects

To have a configuration option that prevents off-site redirects, enhancing security against potential threats. This option could be implemented as an .ini setting or a field in the server document or Internet site document for "Do not allow off-si...
over 1 year ago in Domino / Security 1 Needs Clarification

SAML2 self service integration

In a saml2 world getting rid of ldaps and also auto deploy to groups would be an dream. The idea is that you enable auto creation of users with a certain email domain or attribute with a secretkey from adfs. You also specify some group access ri...
over 5 years ago in Domino / Security 2 Needs Clarification

Error with the return path in the email header

The Mail-In database has the sending domain "acme24.com". The user that sends the mail has the sending domain "acme-online.com". So the From address is "user.n24@acme24.de" and the return-path domain is "acme-online.de". This behaviour seem...
over 1 year ago in Domino / Security 2 Needs Clarification

Mail rule setup that will lookup groups in the rule

This feature will allow the user to set mail rule on the notes client and able to look up groups that is included in the rules
over 5 years ago in Domino / Security 2 Needs Clarification

Limit the number of concurrent sessions per user

Domino allows the possibility to set the maximum number of users on a server. However, it does not allow limiting the number of concurrent sessions per user on the server.
over 1 year ago in Domino / Security 1 Needs Clarification