This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal


Jun 17, 2015, 8:55 AM
7 Posts

ADFS 3.0 - SAML 2.1

  • Category: Security
  • Platform: All Platforms
  • Release: 9.0.1
  • Role: Administrator
  • Tags: ADFS SAML
  • Replies: 5

Some of our customers are asking for SAML 2.1 (ADFS 3.0) support. Since 9.0.1 FP3 supports SHA-2 certificates, which are required by SAML 2.1, it should be possible to use SAML 2.1. Will Domino/Notes supports SAML2.1 with a future release?

Jun 19, 2015, 12:25 PM
7 Posts
Which version of certificates SHA-1 or SHA-2?

Per default, ADFS 3.0 is using SHA-2 certificates. Most of my customers prefers SHA-2 certificates, which is also the default certificate format if they request new certificate from their CA: Are you using SHA-1 or SHA-2 certificates?

Jun 19, 2015, 4:46 PM
191 Posts
Which certificates?
I'm not sure which certs you're referring to. I'm 99 percent sure I've used SHA-2 exclusively in this environment, but I can check a particular cert to verify.
Jun 19, 2015, 12:25 PM
7 Posts
Which version of certificates SHA-1 or SHA-2?

Per default, ADFS 3.0 is using SHA-2 certificates. Most of my customers prefers SHA-2 certificates, which is also the default certificate format if they request new certificate from their CA: Are you using SHA-1 or SHA-2 certificates?

Jun 19, 2015, 7:11 PM
94 Posts
I'm not aware of any issues caused by using SHA-2 certs for SAML
In fact, the X.509 certificates are only used to contain the RSA keys when establishing a partnership - the SAML spec allows for raw keys to be used as well as certificates.

Domino's SAML SP functionality also supports use of SHA-2 for signing Assertions and Responses.

See the SAML section of this article for specifics on supported algorithms:
http://www-10.lotus.com/ldd/dominowiki.nsf/dx/supported-key-sizes-in-notesdomino

And the SAML tag in the Notes/Domino wiki for cookbooks and more.
http://www-10.lotus.com/ldd/dominowiki.nsf/xpViewTags.xsp?categoryFilter=SAML

This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal