SECURING


Enabling the Domino Web server to provide SAML authentication
You enable Security Assertion Markup language (SAML) authentication on Domino® using the IdP Catalog application. If the Domino server is password-protected, there may be additional tasks.

Before you begin


About this task

The IdP Configuration document includes several fields whose values are supplied automatically when you import the metadata.xml file from the IdP.

Important: If the Domino server has a server.id file protected by a password, the administrator cannot use the Create Certificate button (Step 9) to create a metadata file. Instead, see the task in this sequence on creating the Domino metadata file if the server.id file is password-protected.

Important: If you later modify an existing SAML IdP Configuration document or add a new one, restart the HTTP process on the Domino Web server so that the changes are recognized.

Note: Enabling SAML authentication may have unexpected results with RSS feeds if your organization uses them.

Procedure

1. From the Domino Administrator client, create the IdP Catalog application (idpcat.nsf), using the template with the file name idpcat.ntf, or open the application if it already exists.


2. Assign access in the ACL only to any Domino SAML administrator(s) and to the server.
3. Click Add IdP Config to create a new configuration document.
4. On the Basics tab, in the Host names or addresses mapped to this site field, enter either an IP address or Web address (DNS hostname, or Internet site name) representing a service provider's Web site, or both. If you enter both, separate the IP from the Web address using a semicolon, for example, n.nn.nnn.n; www.renovations.com. The order of addresses does not matter, and you can enter multiple items, separated by semicolons.
5. In the IdP name field, enter a name to identify the Web site of the identity provider; the name does not have to be exact, and is only for your administrative convenience.
6. In the Protocol version field, select a SAML version.
7. Leave State for this Configuration document as Enabled (the default).

8. In the Federation product field, select either TFIM for IBM Tivoli Federated Identity Manager or ADFS for Microsoft Active Directory Federation Services, depending on which federation service you intend to use for SAML authentication. The default is ADFS.

9. In the Service provider ID field, enter the string that identifies Domino as a service provider partner with the IdP.


10. Click Import XML file, and specify the metadata.xml file exported from the IdP.
11. On the Client Settings tab, perform all of the following substeps:
12. If you are using SAML 2.0 and need to export a certificate from Domino to use at the IdP, on the Certificate Management tab, perform all of the following substeps: 13. At the beginning of the form, click the Export XML button to save the created idp.xml file as an attachment to the document.
14. Save and close the IdP Configuration document.

What to do next

If you use Internet Site documents, follow the steps in the related topics on them, to enable SAML and to specify the preferred session cookie.

Note: If you later change the authentication type in the Internet Site document to remove SAML, your change has no effect to disable SAML unless this IdP Configuration document is either disabled or deleted.

Parent topic: Configuring SAML in Domino
Next topic: Creating a Domino metadata file manually

Related tasks
Setting up a TFIM server as the identity provider (IdP)
Setting up Microsoft Active Directory Federated Services (ADFS) as the federation for a Domino partner
Using Domino as a SAML-based security provider with SSL
Configuring SAML from the Internet Site (Web Site) document
Creating a Domino metadata file manually

Related reference
Cautioning client users about SAML and logout

Related information
Supplementary information on Security Assertion Markup Language (SAML) configuration combinations of IBM Domino and other products