Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.

For more information and upcoming events around #dominoforever, please visit our Destination Domino Page

ADD A NEW IDEA

Search results: Security

Showing 11 of 205

Ability to login DRAPI using Java/LS bindings in Domino

DRAPI is expanding capabilities beyond what we can do using standard Domino programming. For instance, we can launch a co-editing, OData integration through the Domino Rest API or running background agents asynchronously. We could use these capabi...
4 months ago in Domino / Security 0 Needs Review

Support FIDO2 for Two-Factor Authentication in Nomad/Notes/Traveler/Web

FIDO2 enables users to leverage common devices to easily authenticate to online services in both mobile and desktop environments. The FIDO2 specifications are the World Wide Web Consortium’s (W3C) Web Authentication (WebAuthn) specification and FI...
almost 6 years ago in Domino / Security 3 Shipped

API-Key Authentication for Domino Web Applications

Provide ability to create a API-Key records in names.nsf for third party applications to connect to Domino resources for various reasons (Mostly REST-API, Web agents, DAS, etc.) Right now customers provide a separate username password and the othe...
over 3 years ago in Domino / Security 5 Under Consideration

Make Keycloak a supported SAML IdP for Domino

Domino Web SSO is a mess - several different login mechanisms for various endpoints and we can't integrate alle aspects in one IdP solution so far. Keycloak as an open source IdP offers OIDC and SAML services for HTTP-Access to Domino, OIDC access...
over 3 years ago in Domino / Security 0 Shipped

Let's Encrypt certificate manager program to be available for IBM i

Certificate Manager (CertMgr) server task. This task runs on one server in a Domino domain and handles the certificate processing. It leverages new back-end security APIs and requires a HCL Domino® version 12 or higher server running on Docker, Wi...
over 4 years ago in Domino / Security 4 No Plans to Implement

Disable core REST API

If Rest API are disabled on the server, this Core API - hostname/api/core/nonce should not be accessible or not available when a user generated the request from browser.
over 5 years ago in Domino / Security 4 Needs Clarification

Provide an SDK cal to validate HTTP passwords against the new HTTP ID Vault implementation

Now that we can use Vault for HTTP authentication, the existing C-API calls don't work any more. It makes sense to have a central call to be leveraged in back-end applications.
over 5 years ago in Domino / Security 0 Under Consideration

Support PEM in addtion to KYR for Lotus Script/Java AddInternetCertificateToUser()

There are a couple of use-cases where importing certificates into a person document are important. Beside this Lotus Script method the only other method would be the C-API (SECNABAddCertificate() which only supports DER format by the way). Now tha...
over 2 years ago in Domino / Security 0 Under Consideration

Rate limiting protections for Domino

An authentication endpoint without rate limiting protections can be susceptible to innumerable amounts of credential stuffing and eventual guessing of set of credentials used for authentication. API endpoints can also be used to attack further inf...
about 3 years ago in Domino / Security 1 Needs Clarification

Turn off responding on / api

If I haven't turned on Data Services in Domino this endpoint should on respond at all. It's an unnecessary security risk to keep it open if not used, common practice is to have endpoints closed if they are not used. Also to be able to enable it fo...
over 4 years ago in Domino / Security 0 Under Consideration