Sunteți pe pagina 1din 3

Paul Mooney’s article on Lotus Domino ID Vault

Courtesy: http://www.pmooney.net/pmooney/pmooneynet.nsf/d6plinks/PMOY-
7HUEHA

Sneak peak - the Domino 8.5 id vault


Category
This, in short, is a feature that will have Domino administrators, help desk staff
and help desk managers dancing in the aisle at Lotusphere. While playing around
with the beta, I setup and configured the id vault and thought I would post some
screenshots/thoughts. And, of course its a beta, so what you see here may not be
what you get!
It requires Notes 8.5 on the server and client.
Im not going to go into details on how it works just yet, but I had it up and running
in about 10 minutes in a lab.
Administrators can create one, or multiple vault databases to store passwords,
and assign id files created by specific Organisation units to the databases.
Admins have to also be assigned rights to reset passwords, and these rights can
be vault specific.

From a users' perspective, what does the id vault let you do. Well, two simple
things at the moment.
1 - It allows you to change your password on your Notes client, and that, in turn
means your password is changed on any other copy of your id file from now on.
2 - It allows you to easily get your password reset.

From an administrator's perspective, it gives us the functionality to:


Keep an storage of id files in an encrypted database on the server. These id files
are provisioned to the notes clients upon logon (i.e. the id file is sent down to the
client). When a user changes his password, the id file goes up to the
vault/database with the new password, so if he logs on from another machine, the
updated id file is sent down (ergo - password syncing accross Lotus Notes
clients).
Have custom, policy based information given to users telling them how to ask to
have their password reset.
Reset the password in two clicks.
Here are some pictures of what the user can see:

Note the Forgotton password button! We can give customised messages to the
clients based on policies applied, for example:

Now, what does an administrator have?, well, from the people tab of the client, permitted
Administrators are allowed do this:

And then do this:


And, it works... even in beta. I have reset the password and immediately the user can log
in using that password. Nice eh?

S-ar putea să vă placă și