Enabling Smartcards for Notes login
Smartcards resemble credit cards, but instead of containing a magnetic strip they contain a microprocessor and memory. You can use a Smartcard with your User ID to login to HCL Notes®, provided you have a Smartcard reader installed on your computer. Once your User ID is enabled for Smartcard login, you are prompted for your Smartcard Personal Identification Number (PIN) in place of your Notes password.
About this task
The advantage of using a Smartcard with Notes is that you use a Smartcard to lock your User ID. Without a Smartcard, you only need your User ID and your Notes password to access Notes. When using a Smartcard, you need your User ID, your Smartcard, and your Smartcard PIN to access Notes. Also, because you carry your Smartcard with you (just as you would carry a credit card with you), you are much less vulnerable to User ID theft.
Two ways to enable Smartcard login
About this task
There are two ways to enable Smartcard login. The preferred way secures the ID file using a private key from a personal Internet certificate stored on the Smartcard. Because this method supports the use of a Smartcard on which the Internet certificate and keys are preloaded, it does not require changes to a Smartcard, so allows the use of read-only Smartcards. It also enables users to easily secure multiple copies of their ID files with a Smartcard. The second way secures the ID file using a secret that is added to the Smartcard. This method does not offer the advantages of the preferred method, but is supported for compatibility with Domino® release 6.
If you synchronize your Microsoft™ Windows™ password with your Notes password or if you synchronize your Notes password with your HCL Domino Web/Internet password password, you need to disable the synchronization before enabling Smartcard login with Notes.
Enabling Smartcard login by securing the ID file with an Internet certificate key (preferred)
About this task
Procedure
Results
Enabling Smartcard login by securing the ID file with a secret stored on the Smartcard
About this task
Procedure
Results
Moving Internet keys to a Smartcard
About this task
You can store on your Smartcard any Internet public and private keys from personal Internet certificates that you may have (not from Internet certificate authority certificates). Storing your Internet keys on your Smartcard adds an extra level of protection for them than storing them in your User ID. Once a set of Internet keys is moved to a Smartcard, it is only possible to export the certificate itself, without including the private key, to a separate file.
Note that you may not be able to store some keys on a Smartcard, including 630-bit private keys.
The X.509 certificate associated with the Internet keys is also stored on the Smartcard. You can view this certificate and its associated keys in the User Security dialog box, when you click Your Certificates and select Your Internet Certificates in the drop-down list.
Procedure
Using pre-loaded Internet certificates on a Smartcard
About this task
If your Smartcard was given to you with Internet certificates already stored on it, Notes supports the ability to find and use those certificates without having to import them into the Notes client. These certificates must conform to the PKCS#11: Conformance Profile Specification for RSA Asymmetric Client Signing. If they do not, you must manually import them into your ID file.
When Notes searches for Internet certificates to display in the User Security dialog box, or to use the certificates for decrypting Internet mail or for SSL client authentication, the Internet certificates loaded on your Smartcard will be available for use, along with the Internet certificates in your ID file.
When you sign Internet email, and you have Internet certificates in your Smartcard that are not already contained in your ID file, you will have the option of choosing a new signing certificate from those on the Smartcard, through a dialog box prompt. If no new certificates are found on your Smartcard, your default signing certificate will be used and you will not be prompted.
If you have copies of Internet certificates in your ID file and on your Smartcard, Notes will use the copy of the certificate in the ID file.
To import Internet certificates from a Smartcard
About this task
You can import Internet certificates and store them in the Notes ID file so that they can be found by, and used with, Notes.
Procedure
To view Smartcard configuration details
About this task
You can view all of the configuration information for any Smartcard or cryptographic token you have configured to use with Notes.
Procedure
- Click .
- Enter your PIN when prompted.
- Click .
- Click Configuration Details. The Smartcard Configuration dialog box appears.
- Optional: Click Select Slot. The Select Slot dialog box appears. In addition to information about the cryptographic token, it provides a list box of all of the slots in your PC that are being used by Smartcard or cryptographic token readers. Select a number from the list to view details about the Smartcard or token that is being used by that slot.