Skip to main content link. Accesskey S
  • Anonymous
  • Log on
  • Help
  • IBM logo
  • Lotus Notes and Domino wiki
  • All Wikis
  • Home
  • Community Articles
  • Product Documentation
  • Learning Center


Search

Advanced Search

Categories

Tag Cloud

  • 6.0
  • 6.5
  • 6.5.4
  • 6.x
  • 7.0
  • 7.0.2
  • 7.5
  • 7.x
  • 8.0
  • 8.0.1
  • 8.0.2
  • 8.5
  • 8.5.1
  • 8.5.2
  • 8.5.3
  • 8.5.x
  • 8.x
  • address
  • admin
  • administering
  • administration
  • administrator
  • attachment
  • best practice
  • Blackberry
  • cache
  • calendar
  • Client deployment
  • contacts
  • DAOS
  • database
  • database properties
  • db2
  • DCT
  • demo
  • deployment
  • deployment Notes
  • directory
  • document
  • documents
  • Domino
  • Domino Server
  • Domino Web Access
  • dwa
  • email
  • getting started
  • http
  • IMAP
  • inotes
  • install
  • iPhone
  • LDAP
  • logging
  • Lotus iNotes
  • Lotus Notes
  • Lotus Notes Traveler
  • Lotus Traveler
  • mail
  • mail file
  • max
  • media_notes
  • memory
  • message
  • messaging
  • MIME
  • moving_advanced
  • moving_cal
  • moving_mail
  • ND6
  • notes
  • Notes ID Vault
  • notes.ini
  • NotesBench
  • performance
  • plug-ins
  • Policies
  • preferences
  • R5
  • reference card
  • replication
  • router
  • Sametime
  • search
  • Security
  • server
  • smtp
  • table
  • text
  • tips
  • to do
  • Traveler
  • troubleshooting
  • upgrade
  • user
  • using
  • video
  • videofest
  • web
  • Widgets and Live Text
  • Windows
InformationInformation
You are currently viewing machine translated content. IBM translation might be available. Click IBM Translated Product Documentation to see what is available.X


Home > Domino security > ID vault overview FAQ
Rate this article 1 starRate this article 2 starsRate this article 3 starsRate this article 4 starsRate this article 5 stars

ID vault overview FAQ 

expanded Abstract
collapsed Abstract
No abstract provided.
What is the ID vault?

The Notes® ID vault is an optional, server-based application that holds protected copies of Notes user IDs. An ID vault allows administrators and users to easily manage Notes user IDs, reducing user downtime and help desk costs. Users are assigned to a vault through policy configuration, and copies of user IDs are uploaded to a vault automatically once the policy has taken effect.

The benefits of using an ID vault include:
  • Ability for authorized personnel to change (reset) passwords on IDs stored in a vault when users forget them, without access to the ID files or the vault database
  • Support for the use of a custom application to reset passwords
  • Easy recovery of lost or damaged user IDs
  • Automatic synchronization of multiple ID copies
  • No user involvement during ID renames or ID key rollover. The use of an ID file with Notes is made virtually transparent.
  • “Auditor” function to extract ID files for legal discovery/access to encrypted data


How is the ID vault configured?


To create and configure an ID vault, you perform the following required steps from the Domino Administrator:
  • Create the vault database on a server
  • Create the vault ID file, which is initially stored on the local computer. The vault ID file should be treated as securely as a certifier ID.  Back up copies should be securely stored.  
  • Specify at least one vault administrator. Additional administrators are recommended for administrative backup.
  • Specify which user organizations trust the vault . At least one user organization certifier or organizational unit certifier issues a Vault Trust Certificate to the vault.
  • Assign password reset authority.  Password Reset Certificates are issued by the certifiers that also have issued Vault Trust Certificates.
  • Use Security Settings policy configuration to assign users to the vault. To be assigned to a vault, users must be in an organization that has issued a Vault Trust Certificate.

Optionally you can replicate the vault (add vault servers), specify forgotten password instructions to display in the Notes login prompt, specify whether users must change passwords that have been reset, and require authorization for ID file downloads from the vault.  


How does password reset work?


A benefit of the vault is the ability to easily reset passwords on IDs when users forget them. There are two models available for resetting passwords: authorized personnel can use the Domino Administrator to reset passwords for users, or users or authorized personnel can reset passwords using a custom application. One or both models may be implemented.

People who log in to the Domino Administrator under an identity with password reset authority can reset user passwords using the Reset Password tool in the Domino Administrator. To give password reset authority to these people, a Domino administrator creates Password Reset Certificates for individuals or organizational units. This step requires use of the certifier ID.
People who reset passwords through Domino Administrator have two options for conveying the new passwords to users. They can pick the new password or generate a random one and then inform the user of it themselves. It's important that they have a method to confirm the user's identity. Alternatively, they can generate a random new password and send it by encrypted e-mail to someone, for example a user's manager,who could then convey the password to the user.

Developers can use the ResetUserPassword method available in C, Java®, JavaScript® or LotusScript® to develop a custom application for resetting passwords. This can be a self-service application that allows users to reset their own passwords or an application that help desk personnel use to reset user passwords. Domino comes with a sample self-service application that uses the ResetUserPassword method in a LotusScript agent that you can customize for your environment.


How will this save time and money?


The Notes ID vault can replace time-consuming, expensive ID file and password recovery systems. Administrators provide instructions in the Notes login window (which can include a URL link to a Web site) for users who have forgotten their passwords. Passwords are easily reset using the Domino Administrator or a custom application, and users can use the new passwords automatically from any computer. If ID files are lost or damaged, users are not hindered because copies of the IDs are immediately downloaded from the vault when users provide the passwords.

In addition, tasks involving the ID file, such as ID file synchronization, user renames, and user key rollovers, will no longer require any user involvement and will automatically be handled by the ID vault, reducing complexity and saving time.

The "Auditor” function can be used to extract ID files for legal discovery/access to encrypted data, preventing the loss of any valuable information.


What release of Domino and Notes is required to use an ID vault?


To use a vault IBM® Lotus® Notes® clients must run Release 8.5 or later. Vault servers must run Release 8.5 or later. A user's home server or at least one server in a home server cluster must run Release 8.5 or later but does not have to be a vault server. The Domino Directory administration server must run Release 8.5 or later but does not have to be a vault server.

expanded Article information
collapsed Article information
Category:
Domino security, Lotus Domino,
Tags:
Notes ID Vault

This Version: Version 6 January 6, 2009 3:02:55 PM by Nancy E Kho  IBMer

expanded Attachments (0)
collapsed Attachments (0)

 


expanded Versions (1)
collapsed Versions (1)
Version Comparison     
Version Date Changed by               Summary of changes
This version (6) Jan 6, 2009 3:02:55 PM Nancy E Kho  
expanded Comments (0)
collapsed Comments (0)
Copy and paste this wiki markup to link to this article from another article in this wiki.
Go ElsewhereStay ConnectedSubscribe to RSSHelpAbout
  • All Lotus and WebSphere Portal wikis
  • IBM developerWorks
  • IBM Software support
  • IBM Social Business User Experience Blog
  • IBMSocialBizUX on Twitter
  • IBMSocialBizUX on Facebook
  • Lotus product forums
  • IBMSocialBizUX blog
  • IBM Collaboration Solutions
  • Recently added feedRecently added
  • Recently edited feedRecently edited
  • Recently added comments feedRecently Added Comments
  • Wiki Help
  • Forgot user name/password
  • Wiki design feedback
  • Content feedback
  • About the wiki
  • About IBM
  • Privacy
  • Contact IBM
  • IBM Terms of use
  • Wiki terms of use