Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.

For more information and upcoming events around #dominoforever, please visit our Destination Domino Page

ADD A NEW IDEA

Clear

Security

Showing 329

Password policy functioning improvements with "Check vault first then directory"

ID vault is implemented on the server and in configuration document "Check vault first then directory" is enabled. All users authenticate to the server through ID vault successfully. Use case: The web user is able to login even though the warning ...
over 1 year ago in Domino / Security 0 Needs Review

Domino should support modern SMTP related protocols DANE, MTA-STS and TLS-RPT

Domino is a bit behind in implementing e-mail security protocols. While DMARC is waiting for implementation, new protocols are already around: DANE, MTA-STS and TLS-RPT. 1. DANE (DNS-Based Authentication of Named Entities) RFC 6698: The DNS-Based ...
over 1 year ago in Domino / Security 1 Under Consideration

Document that describes Domino HTTP security settings

There's a document created years ago: https://www.caicorp.com/2017/11/22/adding-security-http-response-headers-to-ibm-lotus-domino-server-to-get-an-a-rating/ HCL should have a similar document with more security settings.
over 1 year ago in Domino / Security 1 Needs Review

Autopopulated group must not resave group document, if content has not changed.

Now even if Autopopulated group content has not changed, server still Resave Document. It would be better, if content is actual, server does not resave group document. From ChangeManagement, Compliance prospective all changes should be logged, and...
over 1 year ago in Domino / Security 0 Under Consideration

Add logout endpoint to DRAPI's oauth system

The .well-known/openid-configuration in DRAPI does not show a logout endpoint. A client web application can use the /oauth/authorization and /oauth/token endpoints to authenticate and refresh the authorization token. A logout is currently only pos...
over 1 year ago in Domino / Security 0 Needs Review

Ability to enable "Enforce a consistent Access Control List across all replicas" through Domino policy.

Would like to enable "Enforce a consistent Access Control List across all replicas" through Domino policy to enable it on all database including local databases without a server copy.
over 1 year ago in Domino / Security 1 Under Consideration

'NSL' for Linux to be able to use password on server.id on Linux servers

I would like to have a way to secure a server.id on a Linux server with a password and not have to manually enter that password on start/restart. On Windows there is NSL, but on Linux we have nothing similar. Working with Information Security I se...
over 1 year ago in Domino / Security 1 Under Consideration

SAML user binding using email

Binding SAML user identity using email is an good way but insecure way.Because a user at an connected IDP could if open go in and change email address and then become another user. It would be good to increase security to add a secondary field tha...
over 1 year ago in Domino / Security 2 Needs Clarification

SSO/SAML Authentication Support with DIIOP

To support SAML authentication with DIIOP
over 1 year ago in Domino / Security 1 Needs Clarification

Time-based One Time Password (TOTP) two-factor authentication for Domino server

Currently, Multi Factor Authentification (MFA) is only possible via external service providers. However, components such as SMS gateways (e.g. SMSEagle) are already available in many server architectures. For this reason, support for the internall...
over 1 year ago in Domino / Security 4 Already Exists