Importing and cross-certifying the IdP Internet certificate
When configuring Notes clients for federated login using SAML, the clients must trust the certificate used by the Identity Provider (IdP). Import the IdP TLS certificate into the Domino directory and cross-certify it.
About this task
Some IdPs have different certificates for encrypting and decrypting assertions and for service communications (HTTPS communications). If you are unsure which certificate to trust, review the article Notes Federated Login: Which certificates should be trusted by the Notes client?
Procedure
- Connect to the IdP using the Firefox browser.
- Click the certificates lock icon in the address bar and view the certificates.
- Click the Details tab and select the Certificates KeyUsage field.
-
Verify that the Certificates KeyUsage field contains values for
Certificate Signer and CRL Signer. In the following example, the
values are missing:
- If the Certificates KeyUsage field does not include these values, select the certificate one level up in the certificate hierarchy and confirm that you see the values.
-
Export the selected certificate and save it as a Base 64 encoded X.509
Certificate (.cer) file. In ADFS, use the following steps:
-
Import the certificate into the Domino directory used by the ID vault and web servers and then
cross-certify it: