Importing and cross-certifying the IdP Internet certificate
When SSL is used between an IdP and Domino, import the IdP SSL certificate into the Domino directory and cross-certify it.
Procedure
- Connect to the IdP using the Firefox browser.
- Click the certificates lock icon in the address bar and view the certificates.
- Click the Details tab and select the Certificates KeyUsage field.
-
Verify that the Certificates KeyUsage field contains values for
Certificate Signer and CRL Signer. In the following example, the
values are missing:
- If the Certificates KeyUsage field does not include these values, select the certificate one level up in the certificate hierarchy and confirm that you see the values.
-
Export the selected certificate and save it as a Base 64 encoded X.509
Certificate (.cer) file. In ADFS, use the following steps:
-
Import the certificate into the Domino directory used by the ID vault and web servers and then
cross-certify it: