Completing Domino prerequisites for SAML
Complete the following Domino configuration that is required by SAML.
Single Sign-on
If users will access more than one Domino server or WebSphere and Domino servers, single sign-on is required. Configure single sign-on and test that it works before configuring SAML authentication. Using multi-server session authentication rather than single-server session authentication is a best practice. For more information, see Multi-server session-based authentication (single sign-on).
TLS certificate
Security settings
- Disable the field Enforce Internet Password Lockout on the Security tab of the server Configuration document.
- Disable any Web password management settings, such as synchronizing the Notes® client password with the Internet password, that are enabled in security policies that are assigned to SAML users.
Domino Web server testing (Recommended)
Because SAML configuration requires cooperating configuration for Domino® and for the identity provider (IdP), Domino® Web server configuration should first be fundamentally sound when being used independently of an IdP. Therefore, before configuring SAML, consider setting up the Domino® HTTP server for single-server session authentication. This task includes configuring Domino® to log in as a Web user (for example, the Domino® administrator that has been configured in the Domino® Directory during the Domino® server setup). After you as this administrator are able to log in as the Domino® user, successfully browsing to URLs on the Domino® server, the server is ready for SAML configuration and enablement.