We have 3 server configured with SSO wich works fine. Now the company is split in two organisations one with the old domain and one with a new domain.
I tried to configure SSO by copying the SSO document and changing the domain into the new domain, thus keeping the same keys, but this doesn’t seem to work (at least not for 1 single server)
Any suggestions / tips?
Subject: Active Internet Sites
You must to activate, Internet sites option in Server Document.
Before create Internet Sites AND SSO for Internet Sites.
Regards, sorry for my English
Subject: internet sites is running
Thanks for your response.
I have internet sites enabled.
we have a domain “firstdomain.nl” wich is used on multiple servers for intranet, sametime and webmail. (intranet.firstdomain.nl, sametime.firstdomain.nl and webmail.firstdomain.nl) with SSO working.
now we also have domain “seconddomain.nl”.
I started with intranet.seconddomain.nl and have the site up and running on the intranet server. But I’m not able to get SSO working with firstdomain.nl. I followed some steps i found on the internet by copying the SSO and changing the domain in the copied document, but this doesn’t work ( in the example they are talking about different servers as well, so this might be the reason )
Subject: Not possible
Hi, you cannot use SSO between 2 different DNS domains. You can use SSO between 2 DOMINO domains if the sites hosted uses the same DNS domain.
You can however set up 2 different SSO documents, but then logging onto domain1 will NOT automatically log you onto domain2.
From admin help (the last line holds the answer):
This procedure lets you enable servers in your current IBM® Lotus® Domino® domain for SSO with servers in another Domino domain, by setting up both domains to use the same key information. Two conditions must exist in order to do this:
You must be a registered IBM® Lotus® Notes® user and your server must be a registered server. This gives you and the server the rights to decrypt the Web SSO Configuration document in your current domain, and the right to create documents in the Domino Directory for the new domain. It may be necessary to have administrative IDs cross-certified for operating in the two domains.
The server document and the administrator’s person document must exist in the domain for which you will be creating the Web SSO Configuration, as the public keys that are used for encryption are stored in each registered person and server document.
Participating SSO servers must still reside in the same DNS domain – for example, acme.com.