Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.

For more information and upcoming events around #dominoforever, please visit our Destination Domino Page

ADD A NEW IDEA

Security

Showing 289

Automatically add "secure" flag to all cookies, when https is used

When a Domino server serves http requests through encrypted https, it should automatically add the " secure " flag to all cookies. There should be a global flag to enable/disable this feature. (default: enabled) In reality, most Domino servers wit...
9 months ago in Domino / Security 0 Needs Review

Domino Inbound SMTP STARTTLS -- Log TLS Version and used Cipher

Most other applications add the TLS Version and used cipher to the received header.Example: from xyz.acme.local (10.100.1.234) by abc.acme.local (10.100.109.233) with Acme SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P...
about 6 years ago in Domino / Security 3 Assessment

SAML configuration for Internet site with multiple hostnames

When you configure a SAML for an internet site shared by multiple sites, the SAML authentication leads to a redirect to the first server in the configuration as the response url is always pointing to that server. We tried to set it up with AAD. Th...
about 1 year ago in Domino / Security 1 Under Consideration

API-Key Authentication for Domino Web Applications

Provide ability to create a API-Key records in names.nsf for third party applications to connect to Domino resources for various reasons (Mostly REST-API, Web agents, DAS, etc.) Right now customers provide a separate username password and the othe...
about 2 years ago in Domino / Security 5 Under Consideration

Ability to send trusted certificate list even if destination endpoint sends empty DN

Domino currently is designed to decline sending any certificate and requires the destination endpoint to send a list of trusted DN CAs. As per EXO "Exchange sends its certificate along with the certificate request to Domino. In our certificate req...
5 months ago in Domino / Security 1 Assessment

Evolve management of Java Security Policy on Domino Server

Domino mandates java security controls to avoid code from performing privileged operation. Control of policies is defined by java.policy files. This is a burden for customer, partners and admins. The proposal is to implement a new Java policy prov...
about 3 years ago in Domino / Security 0 Under Consideration

Improve SAML - We need act also as a Idp Provider

Currently, Domino can use SAML for authentication, but NOT to act as an IdP provider. There is a lot of product on cloud that in order to do SSO, they do require an IdP, an your are forced to use ADFS or Tivoli for that. On the same way that Domin...
about 6 years ago in Domino / Security 7 Assessment

Website Documents with ability to select Directories

Overview This idea is related to the way in which multiple directories in Domino can be used. Currently, Domino supports multiple Directories in the form of Directory Assistance , which allows to add multiple directories to the whole server. All s...
9 months ago in Domino / Security 0 Needs Review

Passkey only authentication for Domino

Currently passkeys are an option but cannot made required once a user registered a passkey. There should be an option to not allow password authentication for a user once a passkey is available. Passkeys are more secure than passwords. Keeping the...
about 1 month ago in Domino / Security 0 Assessment

Server-Rules for E-Mail-Header

Our provider uses anti-spam software that writes the SPAM probability in the email header. Example: X-Spam-Level: ***** There should be a central way to evaluate the email header in Domino, for example to add a keyword to the subject line of affec...
about 1 month ago in Domino / Security 0 Needs Review