Testing Web federated login

After enabling Web federated login in the ID vault policy, do a test login.

About this task

Log in as a test HCL Verse® user to confirm that Web federated login is enabled. To do so, open a browser and enter the URL for Verse® on the Domino® Web server running Verse.

If the home URL of the server or internet site is a Verse redirect database, enter the URL for the Domino® Web server running Verse, for example: https://mai14.us.renovations.com.

The test user's browser is redirected to the IdP for login. After authenticating with the IdP, the browser is redirected to the originally requested Domino® URL. When the Verse redirect database is the home URL, the test user's mail is displayed in the browser. If this completes successfully, SAML authentication is properly configured at the Domino® server.

If Web federated login is also properly configured, the test Verse user should no longer see a password prompt for access to encrypted mail.

Some typical problems are:
  • Missing IdP relying party trust for the ID Vault.
  • Incorrect IdP entries.
  • Invalid metadata imported into the IdP catalog.
  • No cross-certificate for accessing the ID Vault.
  • ID not found in vault