Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.

For more information and upcoming events around #dominoforever, please visit our Destination Domino Page

ADD A NEW IDEA

Clear

Security

Showing 322

SAML user binding using email

Binding SAML user identity using email is an good way but insecure way.Because a user at an connected IDP could if open go in and change email address and then become another user. It would be good to increase security to add a secondary field tha...
about 1 year ago in Domino / Security 2 Needs Clarification

SSO/SAML Authentication Support with DIIOP

To support SAML authentication with DIIOP
over 1 year ago in Domino / Security 1 Needs Clarification

Time-based One Time Password (TOTP) two-factor authentication for Domino server

Currently, Multi Factor Authentification (MFA) is only possible via external service providers. However, components such as SMS gateways (e.g. SMSEagle) are already available in many server architectures. For this reason, support for the internall...
over 1 year ago in Domino / Security 4 Already Exists

Server.id protection should not be a problem when creating ServiceProvider.xml in idpcat.nsf

You cannot create the ServiceProvider.xml when your server.id has protection. A see a popup "You are not authorized to perform that operation". This leads usto the server.id protection. When we disable it, we can create the ServiceProvider.xml in ...
over 1 year ago in Domino / Security 3 Needs Review

Move server.id into the IDVault

Move the server.id into the IDVault and protect the deployment. Let only the correct Domino server extract the server.id from the IDVault.
over 1 year ago in Domino / Security 2 Under Consideration

Server-Rules for E-Mail-Header

Our provider uses anti-spam software that writes the SPAM probability in the email header. Example: X-Spam-Level: ***** There should be a central way to evaluate the email header in Domino, for example to add a keyword to the subject line of affec...
over 1 year ago in Domino / Security 2 Needs Review

Hide connecting server IP address in a response to helo command

When connecting to Domino Server and after issuing helo command it provided the IP address of the connecting server. Customer would like to hide the connecting server IP address. 220 mail.acme.com ESMTP Service (HCL Domino Release 12.0.2) ready at...
over 1 year ago in Domino / Security 2 No Plans to Implement

Option to relocate ../data/cacert.pem outside Domino data

We added several certificates into cacert.pem when using NotesHTTPrequest call in LotusScript. After a update or upgrade, this file is renewed. Please introduce a notes.ini parameter to relocate this file to ( example ) /local/cacerts/cacert.pem
over 1 year ago in Domino / Security 3 Needs Clarification

Allow to distinguish between HTTP requests without database access privileges

When summarizing database web access, we count requests in domlog.nsf or access log (text), but we cannot distinguish between requests from users without access privileges and those with privileges. Please be able to distinguish requests from user...
over 1 year ago in Domino / Security 0 Needs Review

Internet Lockout - Option to mark or manually lock out User or Addresses

I'm currently missing an option to mark locked out users and/or IP-Adresses in Internet-Lockout DB to prevent them from beeing deleted accidentally. Let's asume in Domino Serverconfigurationdocument the Internet Lockout feature is configured to au...
over 1 year ago in Domino / Security 1 Needs Review