This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal


Jul 1, 2015, 3:07 PM
39 Posts

Disable use of HTTP password on a single Domino Server

  • Category: Administration
  • Platform: All Platforms
  • Release: 9.0.1
  • Role: Administrator
  • Tags:
  • Replies: 3

Question: Is it possible to stop a single Domino-server from using HTTP/Internet password specified in Person-document and only use passwords from an LDAP source in Directory Assistance?

 

The goal is to have the end-user to only have 1 single secure password for several IT-systems (windows log-in, webmail, traveler, etc)

Scenario:

  • An Active Directory policy password policy is active (and the passwords in AD are now "secure")
  • Domino HTTP-passwords are in this case considered as insecure in this Domino Directory (Password sync between Domino and AD is not an option)
  • Domino can be set up to use Active Directory passwords with Directory Assistance

Result: The end-user can log in using either password in Domino HTTP or Active Directory on a Domino server. 

Can we stop the Domino server from using Domino HTTP-password so that only the Active Directory password is used? (for services like Traveler, Sametime, Webmail and some web based apps).

Jul 2, 2015, 12:27 AM
191 Posts
Are you saying users can currently use either password?
If so, why not just write an agent to remove the internet passwords from the Domino directory?
Jul 8, 2015, 1:52 PM
15 Posts
You can...

For web authentication you have to remove the HTTP password from the person document ( like Chad mentioned just clear it with an agent ).

With Sametime you need to have "LDAP authentication" enabled in your Community Server, not Domino !! Then you can also authenticate with

Sametime against the AD..

Jul 9, 2015, 3:56 PM
39 Posts
Thanks for the answers

Thanks all for the updates!

Idea: Is there any Notes.ini parameter to disable HTTP-password from Domino Person Documents on one server?  This would solve the problem that the Passwords are exposed (in theory) in the Internet Facing servers, but it the HTTP-password could be used on the companys internal network.


This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal