Skip to Main Content
HCL Domino Ideas Portal

Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.

For more information and upcoming events around #dominoforever, please visit our Destination Domino Page

Status Assessment
Workspace Domino
Categories Security
Created by Guest
Created on Dec 10, 2018

SAML - Better cluster support

- Automatic authentication of servers against ADFS in a clustered environment
- Certificate management settings, Domino URL, single logout URL can't be edited when used in a clustered environment

  • Attach files
  • Guest
    Reply
    |
    Nov 23, 2020

    It is unclear to me what this original post is requesting. If the question is for web based SAML authentication, you can use a load balanced address if you have a proxy. The user would be re-directed to the proxy which would route them to an available cluster member. We recently published a whitepaper on how to achieve this with Verse, but the same concepts would apply to iNotes and perhaps other web applications. https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0084455

    In a configuration such as this one, you would add all the Domino cluster members to the same Internet Sites document (with SSO configured), and they would share the same idpcat configuration settings document. Each server would have to import the certificate from the certificate management tab of the idpcat configuration document. (details: https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0080181)

    It is best to open a case with HCL support, or visit the Community forum if you have any questions.