Before upgrading to Domino 12

This topic describes things to consider related to DAOS object encryption features in HCL Domino® 12 and the ability to revert to an earlier Domino version.

Starting with Domino 12, Domino uses stronger AES-128 encryption for DAOS objects by default. This encryption creates objects that cannot be opened by previous versions of Domino. If you need to ensure backward compatibility, set the following notes.ini setting before upgrading the server to force Domino to use the legacy encryption:
DAOS_NLO_ENCRYPTION_METHOD=0

Also starting in Domino 12, DAOS tier 2 objects can be shared across servers. Sharing tier 2 objects requires creation of a shared key that is used to encrypt them. The shared key can also be used to encrypt tier 1 objects. If you were to use the shared keys and then revert to an earlier Domino version, the server may not be able to decrypt DAOS objects encrypted with the shared keys. We recommend that you use DAOS shared keys only if you are willing to commit to using Domino 12 and later versions.

Most new releases of Domino upgrade the design of the DAOS catalog (daoscat.nsf). If you need to downgrade a server to a previous version of Domino, delete the daoscat.nsf file. This file is rebuilt automatically with the correct design appropriate to the version of Domino you install. After the downgrade, use the tell daosmgr resync force command to resync the DAOS catalog.