Requiring authorization for ID downloads

To help thwart unauthorized downloads of Notes client ID files from a vault, require authorization for ID downloads.

Procedure

  1. Open the Security Settings document used in users' policies in edit mode and click the ID Vault tab.
  2. Edit the following fields and then save the document.
    Table 1. ID Vault tab fields

    Field

    Description

    Allow automatic ID downloads

    Select No. (Default is Yes).

    Allow trusted server ID downloads If you select No for Allow automatic ID downloads,you must select Yes in this field to allow the IDs of iNotes and Verse users to continue to be used without download restriction. Starting in V12.0.1, when iNotes and Verse users have IDs in the vault, the vaulted IDs rather than the IDs in user mail files are always used for secure mail operations. When you select Yes in this field, you must also complete the following steps to specify which servers you allow the IDs to be obtained from:
    1. Open the vault database.
    2. Open the Configuration document.
    3. In the Non iDP authentication login field, specify the names of the ID vault servers that you trust for Verse or iNotes ID downloads.

    Allow ID downloads for

    Specify a period of time in days and hours within which Notes users are allowed to download new copies of IDs to recover from a forgotten password or missing local ID file.

    Note: Specify the number of downloads allowed on a per-user basis when resetting passwords or by using the Set ID Download Count tool.

    ID download authorization failure message

    Type the text to display to users who have exceeded the download time limit or download count limit. For example:

    Please call 123-4567 to authorize the download of your ID from the ID vault.
    Note: When SAML Notes federated login or SAML Web federated login is the authentication method used to extract Notes ID files from the ID vault, the value for the ID Vault policy setting Allow automatic ID downloads is ignored because SAML authentication requires unrestricted download access to ID files from the vault.

    If the Allow password authentication with the ID vault setting is enabled for federated login, the Allow automatic ID downloads setting is still used for the password authentication. Allow password authentication with the ID vault setting is found in the Federated Login > Additional settings for Federated Login (Notes or Web) section of the Security Settings policy document.