SlideShare una empresa de Scribd logo
1 de 56
Descargar para leer sin conexión
Gabriella Davis - gabriella@turtlepartnership.com
IBM Lifetime Champion for Social Business
TheTurtle Partnership
1
SETTING UP A HYBRID DOMINO
ENVIRONMENT TO EASE YOUR
WAY TO THE CLOUD
WHO AM I?
Admin	of	all	things	and	especially	quite	complicated	things	where	the	fun	is	
Working	with	security	,	healthchecks,	single	sign	on,	design	and	deployment	of	
IBM	technologies	and	things	that	they	talk	to	
Stubborn	and	relentless	problem	solver	
Lives	in	London	about	half	of	the	Ame	
gabriella@turtlepartnership.com	
twiDer:	gabturtle	
Awarded	the	first	IBM	LifeAme	Achievement	Award	for	CollaboraAon	SoluAons
2
THE GOAL
All users continue working together regardless of whether they are assigned to on premises or
cloud servers
Applications hosted on on premises servers can be accessed by any user
Administration continues to be handled by corporate Domino administrators
All users have access to Notes,Verse,Traveler, Connections, Sametime
3
4
ARCHITECTURE
HYBRID SERVER ROLES
Directory Server - synchronises directories into the cloud
Directories can be used to provision users or purely for lookups
Mail Hub server - all mail inbound for cloud users and mail between cloud and on premises users
is routed through the Mail Hub(s)
Passthru server - in an isolated domain. The Cloud servers connect to the Passthru server to
reach the Directory and Mail Hub
The passthru server(s) are often in the DMZ
5
6
ON PREMISES TURTLE
DOMAIN
Mail Server1
Mail Server2
Mail Hub
Directory Server
CLOUD DOMAIN
Smartcloud Server1
Smartcloud Server2
ON PREMISES PASSTHRU
DOMAIN
Passthru Server
Assigned servers in IBM Cloud
These are managed for you
Mail Hub Server:All mail between on premises and cloud users route
through this server
Directory Server: Synchronising directories (and populating users) in the
cloud
Smartcloud servers connect to the Mail
Hub and Directory Servers via the
Passthru
ON PREMISES OPEN PORTS
Inbound
NRPC 1352 for service users to access on premises server applications
SMTP (25) if you have configured Smartcloud to route all outbound mail via on premises servers
Outbound
NRPC 1352 for Notes client to access Cloud servers
HTTPS 443 forTraveler, Connections
Instant Messaging 1533
7
PLANNING
How many Passthru, Directory and Mail Hub servers will you have
Servers are connected to from the Cloud, they do not connect to the Cloud
They are connected to in a failover, not load balanced, configuration
How will outbound mail route
By default IBM routes outbound mail sent by service users out through its own servers
You can configure your IBM Cloud account to sent outbound mail via your Mail Hub instead
Which users will be in the cloud vs on premises
8
DIRECTORY SYNCHRONISATION
What directories replicate to Smartcloud
Directories containing Smartcloud users must be replicated
Directories containing on premises users must be replicated if smart cloud users are going to schedule
meetings / work seamlessly with them
LDAP directories cannot be used in Smartcloud environments
Group and Policy names must be unique if you have multiple directories (that’s true regardless of
Smartcloud)
Multiple servers must use identical file names / paths for directories
9
MAIL ROUTING
Internal Users route internally via on premises servers
Smartcloud to On Premises routes via Passthru server(s) to Mail Hub
Smartcloud to extended directory users routes via Passthru to Mail Hub
On premises to Internet routes out via SMTP on internal network routing
Smartcloud to Internet routes directly out via IBM’s cloud servers by default
Customer SMTP routing is an optional alternative
10
DOMAINS
The passthru server should be in its own domain
A domain is separate from an organisational certifier
Servers can be in different domains but have the same certifier
Having a server in its own domain minimises the risk of exposing internal configuration details and
provides a layer of “opt in” security
11
CREATING AN OU CERTIFIER
The Cloud servers will be created by the IBM Smartcloud service and named automatically
They will use an OU certifier you create that must be separate from any other use in your
organisation
Must be a child of your organisational certifier
The server certifier used for the Smartcloud server must be a downstream OU, not a different O
The server ID can have a password but only one
The OU name must be at least 3 characters long
12
UNIQUENESS
Your Organisational certifier will be verified for uniqueness within the cloud service
Your top level certifier name must be unique within Smartcloud..
If there’s another “Turtle” out there then I have to use a different certifier for my cloud and
passthru servers.
13
BEFORE STARTING
Build your Passthru server(s) in its own domain
Build your mail hub and directory server(s) within your existing internal domain
Replicate the directories you want to use in the cloud to the directory server(s)
Create the OU certifier to be used by the cloud servers
Ensure the correct domain is defined in the Directory Profile (Actions - Edit Directory Profile)
14
15
CONFIGURATION
16
17
This is our starting point.We
have configured nothing.
We can keep coming back to this point
to check what needs to be done
next
18
Flores/Turtle
We can add multiple
Domino directories to use
They don’t need to be configured
as directories on the Directory
sync server Each directory can have a
failover server but this doesn’t use
Domino clustering to failover
19
20
The Cloud servers that will
be created for you will use this base
name + # + OU e.g.
TurtleMail1/TTL/Turtle
TurtleMail2/TTL/Cloud
21
“Cloud” is the OU I
setup to be used by the
cloud servers
ptserver.turtlehost.net
22
Upload the dedicated
OU certifier and submit its
password so Smartcloud can
use it
23
Once all the steps are
complete click on the pre-
configuration tool which downloads
an NSF called
liveservercheck.nsf
24
Open
liveservercheck.nsf in
Domino Administrator. Make sure
you can connect to all servers
with Admin rights
Flores/Turtle
25
Once all the tests are successful you can Enable the
Smartcloud Notes account and that will reveal the
Domino ConfigurationTool menu
26
downloads
liveserverconfig.nsf which you
should open through Domino
Administrator
1. 2. 3.
27
28
For each domain in your
Global Domain Document a unique
key will be created that you must use to
create a CNAME DNS entry
29
30
Once your Smartcloud
account is activated these
management menu options
appear
31
MANAGEMENT
PROVISIONING USERS
Automatically from a directory
The Smartcloud servers connect to your Directory Servers to replicate the directory(ies)
You can configure multiple directories to be populated into Smartcloud
specifying “do not provision from this directory’ prevents the Smartcloud server creating user
accounts from person documents
32
USER PROVISIONING
Registered in a Directory synchronisation server
Creates a temporary mail file
User appears in the provisioning view once synchronisation is complete
33
34
Users who are synchronised
and ready to be provisioned
All users
35
Search and find a user to
provision
36
Default mail
template
37
38
Provisioned user
39
Management
options.
The ID is automatically uploaded
from the on premises ID
Vault
40
REPLICATION OF DIRECTORY
Pull
Person documents not including mail server and mail file name
Policies (not including organisational policies)
Groups
Rooms and Resources
Push
Mail file, server and SaasIdentityID fields in person documents (the last representing the Connections cloud account
Specific server groups used by Smartcloud
IDVault information for the Smartcloud vault
41
DUPLICATE NAMES
Domino directory takes priority of Extended Catalog
First person entry is the one used
Public key checking won’t work
42
RESERVED GROUPS AND ALL ENTRIES
Directory Synchronisation servers - Manager access including delete rights
Server Group “LLNServers” - Editor rights with roles [UserModifier] [GroupCreator] [GroupModifier]
LLNMailHubs is reserved for Smartcloud
Certifiers_ or SAAS are group prefixes used by Smartcloud
Server Group “SaaSLocalDomainServers” - Manager with delete rights
Wildcard naming in group names aren’t supported e.g */Turtle
43
POLICIES
On premise Domino administrators can use policies to manage both on premise and cloud users
Policies in a synchronised directory are applied to cloud users
Only explicit policies are recognised, organisational ones are ignored
Policy names should be unique across all directories
44
45
46
47
48
49
50
SECURITY
SUPPORTED LOGINS
Notes ID - Notes client access
Cloud Service Account - iNotes,Verse, Traveler, Sametime
Federated SAML Login - iNotes,Verse, Traveler for Android only
Application Passwords -Traveler, Sametime
51
USER LOGINS
IDVault
Syncing ID passwords when service passwords are changed
Password settings can be controlled by a security policy that applies to Cloud assigned users
52
53
FEDERATED LOGINS
SmartCloud Notes support SAML Federation
You must configure SAML in your on premises environment first then contact customer services to
provide them the information for the Smartcloud servers
If SAML is enabled then service login passwords are no longer used and application passwords must be
used instead
54
APPLICATION PASSWORDS
Application Passwords vs Service Passwords
Application passwords are 16 characters long and generated automatically on user request
they are shown to the user once
users can generate new ones or disable the existing one
Restricting access to the service for an ip range will most likely preventTraveler or mobile applications
from working and requires an application password
55
QUESTIONS?
56
Gab Davis
gabriella@turtlepartnership.com
http://turtleblog.info
twitter: gabturtle
skype: gabrielladavis

Más contenido relacionado

La actualidad más candente

Rock Solid Sametime for High Availability
Rock Solid Sametime for High AvailabilityRock Solid Sametime for High Availability
Rock Solid Sametime for High AvailabilityGabriella Davis
 
An Introduction To Docker
An Introduction To  DockerAn Introduction To  Docker
An Introduction To DockerGabriella Davis
 
Planning and Completing an IBM Connections Upgrade
Planning and Completing an IBM Connections UpgradePlanning and Completing an IBM Connections Upgrade
Planning and Completing an IBM Connections UpgradeGabriella Davis
 
An introduction to configuring Domino for Docker
An introduction to configuring Domino for DockerAn introduction to configuring Domino for Docker
An introduction to configuring Domino for DockerGabriella Davis
 
HTTP - The Other Face Of Domino
HTTP - The Other Face Of DominoHTTP - The Other Face Of Domino
HTTP - The Other Face Of DominoGabriella Davis
 
An Introduction to Configuring Domino for Docker
An Introduction to Configuring Domino for DockerAn Introduction to Configuring Domino for Docker
An Introduction to Configuring Domino for DockerGabriella Davis
 
IAmLUG presentation: Domino Admin Best Practices - Hunting the Gremlins
IAmLUG presentation: Domino Admin Best Practices - Hunting the GremlinsIAmLUG presentation: Domino Admin Best Practices - Hunting the Gremlins
IAmLUG presentation: Domino Admin Best Practices - Hunting the GremlinsDavid Hablewitz
 
Str02. IBM Application Modernization with panagenda ApplicationInsights
Str02. IBM Application Modernization with panagenda ApplicationInsightsStr02. IBM Application Modernization with panagenda ApplicationInsights
Str02. IBM Application Modernization with panagenda ApplicationInsightspanagenda
 
Adm02. IBM Connections Adminblast
Adm02. IBM Connections AdminblastAdm02. IBM Connections Adminblast
Adm02. IBM Connections Adminblastpanagenda
 
Fixing Domino Server Sickness
Fixing Domino Server SicknessFixing Domino Server Sickness
Fixing Domino Server SicknessGabriella Davis
 
Adminlicious - A Guide To TCO Features In Domino v10
Adminlicious - A Guide To TCO Features In Domino v10Adminlicious - A Guide To TCO Features In Domino v10
Adminlicious - A Guide To TCO Features In Domino v10Gabriella Davis
 
What's New in Notes, Sametime and Verse On-Premises
What's New in Notes, Sametime and Verse On-PremisesWhat's New in Notes, Sametime and Verse On-Premises
What's New in Notes, Sametime and Verse On-PremisesGabriella Davis
 
Inform2015 - What's New in Domino 9 & 9.0.1 for Admins
Inform2015 - What's New in Domino 9 & 9.0.1 for AdminsInform2015 - What's New in Domino 9 & 9.0.1 for Admins
Inform2015 - What's New in Domino 9 & 9.0.1 for AdminsJared Roberts
 
Taking IBM Sametime Mobile
Taking IBM Sametime MobileTaking IBM Sametime Mobile
Taking IBM Sametime MobileGabriella Davis
 
A Guide To Sametime 9.0.1 Audio & Video
A Guide To Sametime 9.0.1 Audio & VideoA Guide To Sametime 9.0.1 Audio & Video
A Guide To Sametime 9.0.1 Audio & VideoGabriella Davis
 
Face Off Domino vs Exchange On Premises
Face Off Domino vs Exchange On PremisesFace Off Domino vs Exchange On Premises
Face Off Domino vs Exchange On PremisesGabriella Davis
 
The SSL Problem and How to Deploy SHA2 Certificates
The SSL Problem and How to Deploy SHA2 CertificatesThe SSL Problem and How to Deploy SHA2 Certificates
The SSL Problem and How to Deploy SHA2 CertificatesGabriella Davis
 
What We Wish We Had Known: Becoming an IBM Connections Administrator
What We Wish We Had Known: Becoming an IBM Connections AdministratorWhat We Wish We Had Known: Becoming an IBM Connections Administrator
What We Wish We Had Known: Becoming an IBM Connections AdministratorGabriella Davis
 

La actualidad más candente (20)

Rock Solid Sametime for High Availability
Rock Solid Sametime for High AvailabilityRock Solid Sametime for High Availability
Rock Solid Sametime for High Availability
 
An Introduction To Docker
An Introduction To  DockerAn Introduction To  Docker
An Introduction To Docker
 
Planning and Completing an IBM Connections Upgrade
Planning and Completing an IBM Connections UpgradePlanning and Completing an IBM Connections Upgrade
Planning and Completing an IBM Connections Upgrade
 
An introduction to configuring Domino for Docker
An introduction to configuring Domino for DockerAn introduction to configuring Domino for Docker
An introduction to configuring Domino for Docker
 
Domino Adminblast
Domino AdminblastDomino Adminblast
Domino Adminblast
 
HTTP - The Other Face Of Domino
HTTP - The Other Face Of DominoHTTP - The Other Face Of Domino
HTTP - The Other Face Of Domino
 
An Introduction to Configuring Domino for Docker
An Introduction to Configuring Domino for DockerAn Introduction to Configuring Domino for Docker
An Introduction to Configuring Domino for Docker
 
IAmLUG presentation: Domino Admin Best Practices - Hunting the Gremlins
IAmLUG presentation: Domino Admin Best Practices - Hunting the GremlinsIAmLUG presentation: Domino Admin Best Practices - Hunting the Gremlins
IAmLUG presentation: Domino Admin Best Practices - Hunting the Gremlins
 
Str02. IBM Application Modernization with panagenda ApplicationInsights
Str02. IBM Application Modernization with panagenda ApplicationInsightsStr02. IBM Application Modernization with panagenda ApplicationInsights
Str02. IBM Application Modernization with panagenda ApplicationInsights
 
Adm02. IBM Connections Adminblast
Adm02. IBM Connections AdminblastAdm02. IBM Connections Adminblast
Adm02. IBM Connections Adminblast
 
Fixing Domino Server Sickness
Fixing Domino Server SicknessFixing Domino Server Sickness
Fixing Domino Server Sickness
 
Adminlicious - A Guide To TCO Features In Domino v10
Adminlicious - A Guide To TCO Features In Domino v10Adminlicious - A Guide To TCO Features In Domino v10
Adminlicious - A Guide To TCO Features In Domino v10
 
What's New in Notes, Sametime and Verse On-Premises
What's New in Notes, Sametime and Verse On-PremisesWhat's New in Notes, Sametime and Verse On-Premises
What's New in Notes, Sametime and Verse On-Premises
 
Inform2015 - What's New in Domino 9 & 9.0.1 for Admins
Inform2015 - What's New in Domino 9 & 9.0.1 for AdminsInform2015 - What's New in Domino 9 & 9.0.1 for Admins
Inform2015 - What's New in Domino 9 & 9.0.1 for Admins
 
Taking IBM Sametime Mobile
Taking IBM Sametime MobileTaking IBM Sametime Mobile
Taking IBM Sametime Mobile
 
A Guide To Sametime 9.0.1 Audio & Video
A Guide To Sametime 9.0.1 Audio & VideoA Guide To Sametime 9.0.1 Audio & Video
A Guide To Sametime 9.0.1 Audio & Video
 
Face Off Domino vs Exchange On Premises
Face Off Domino vs Exchange On PremisesFace Off Domino vs Exchange On Premises
Face Off Domino vs Exchange On Premises
 
The SSL Problem and How to Deploy SHA2 Certificates
The SSL Problem and How to Deploy SHA2 CertificatesThe SSL Problem and How to Deploy SHA2 Certificates
The SSL Problem and How to Deploy SHA2 Certificates
 
Spnego configuration
Spnego configurationSpnego configuration
Spnego configuration
 
What We Wish We Had Known: Becoming an IBM Connections Administrator
What We Wish We Had Known: Becoming an IBM Connections AdministratorWhat We Wish We Had Known: Becoming an IBM Connections Administrator
What We Wish We Had Known: Becoming an IBM Connections Administrator
 

Similar a Setting Up a Hybrid Domino Environment to Ease your Way to the Cloud

Best Practices for Integrating Active Directory with AWS Workloads
Best Practices for Integrating Active Directory with AWS WorkloadsBest Practices for Integrating Active Directory with AWS Workloads
Best Practices for Integrating Active Directory with AWS WorkloadsAmazon Web Services
 
Becoming a Microsoft Specialist in Microsoft Azure Infrastructure
Becoming a Microsoft Specialist in Microsoft Azure InfrastructureBecoming a Microsoft Specialist in Microsoft Azure Infrastructure
Becoming a Microsoft Specialist in Microsoft Azure InfrastructureSyed Irtaza Ali
 
เอกสาร แนวทาง การอินติเกรท Mac OS X เข้ากับ ระบบ Active Directory อย่างไร Bes...
เอกสาร แนวทาง การอินติเกรท Mac OS X เข้ากับ ระบบ Active Directory อย่างไร Bes...เอกสาร แนวทาง การอินติเกรท Mac OS X เข้ากับ ระบบ Active Directory อย่างไร Bes...
เอกสาร แนวทาง การอินติเกรท Mac OS X เข้ากับ ระบบ Active Directory อย่างไร Bes...Tũi Wichets
 
Cloud Identity and Access Management
Cloud Identity and Access ManagementCloud Identity and Access Management
Cloud Identity and Access ManagementJarek Sokolnicki
 
Montreal MuleSoft_Meetup_16-Aug.pptx
Montreal MuleSoft_Meetup_16-Aug.pptxMontreal MuleSoft_Meetup_16-Aug.pptx
Montreal MuleSoft_Meetup_16-Aug.pptxshubhamkalsi2
 
Features of SmartCloud Notes in Hosted and Hybrid Environments
Features of SmartCloud Notes in Hosted and Hybrid EnvironmentsFeatures of SmartCloud Notes in Hosted and Hybrid Environments
Features of SmartCloud Notes in Hosted and Hybrid EnvironmentsRanjit Rai
 
Directory Synchronization Single Sign-On in Office 365
Directory Synchronization Single Sign-On in Office 365Directory Synchronization Single Sign-On in Office 365
Directory Synchronization Single Sign-On in Office 365InnoTech
 
29041329 interview-questions-for-server-2003
29041329 interview-questions-for-server-200329041329 interview-questions-for-server-2003
29041329 interview-questions-for-server-2003rafiq123
 
New Features Lotus Domino Administration 8.5
New Features Lotus Domino Administration 8.5New Features Lotus Domino Administration 8.5
New Features Lotus Domino Administration 8.5Rolf Kremer
 
server configuration concepts in system admin
server configuration concepts in system adminserver configuration concepts in system admin
server configuration concepts in system adminsdsm2
 
Deploying DAOS and ID Vault
Deploying DAOS and ID VaultDeploying DAOS and ID Vault
Deploying DAOS and ID VaultLuis Guirigay
 
CloverDX for IBM Infosphere MDM (for 11.4 and later)
CloverDX for IBM Infosphere MDM (for 11.4 and later)CloverDX for IBM Infosphere MDM (for 11.4 and later)
CloverDX for IBM Infosphere MDM (for 11.4 and later)CloverDX
 
MuleSoft Surat Virtual Meetup#35 - Setting up MuleSoft Runtime and Anypoint C...
MuleSoft Surat Virtual Meetup#35 - Setting up MuleSoft Runtime and Anypoint C...MuleSoft Surat Virtual Meetup#35 - Setting up MuleSoft Runtime and Anypoint C...
MuleSoft Surat Virtual Meetup#35 - Setting up MuleSoft Runtime and Anypoint C...Jitendra Bafna
 
48. Azure Active Directory - Part 1
48. Azure Active Directory - Part 148. Azure Active Directory - Part 1
48. Azure Active Directory - Part 1Shawn Ismail
 
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdf
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdfDumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdf
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdfDumps Cafe
 
Us sbsc aurora presentation
Us sbsc   aurora presentationUs sbsc   aurora presentation
Us sbsc aurora presentationRick Bahl
 

Similar a Setting Up a Hybrid Domino Environment to Ease your Way to the Cloud (20)

Best Practices for Integrating Active Directory with AWS Workloads
Best Practices for Integrating Active Directory with AWS WorkloadsBest Practices for Integrating Active Directory with AWS Workloads
Best Practices for Integrating Active Directory with AWS Workloads
 
Becoming a Microsoft Specialist in Microsoft Azure Infrastructure
Becoming a Microsoft Specialist in Microsoft Azure InfrastructureBecoming a Microsoft Specialist in Microsoft Azure Infrastructure
Becoming a Microsoft Specialist in Microsoft Azure Infrastructure
 
เอกสาร แนวทาง การอินติเกรท Mac OS X เข้ากับ ระบบ Active Directory อย่างไร Bes...
เอกสาร แนวทาง การอินติเกรท Mac OS X เข้ากับ ระบบ Active Directory อย่างไร Bes...เอกสาร แนวทาง การอินติเกรท Mac OS X เข้ากับ ระบบ Active Directory อย่างไร Bes...
เอกสาร แนวทาง การอินติเกรท Mac OS X เข้ากับ ระบบ Active Directory อย่างไร Bes...
 
Cloud Identity and Access Management
Cloud Identity and Access ManagementCloud Identity and Access Management
Cloud Identity and Access Management
 
The Docker Training in Bangalore From myTectra,Online
The Docker Training in Bangalore From myTectra,OnlineThe Docker Training in Bangalore From myTectra,Online
The Docker Training in Bangalore From myTectra,Online
 
Montreal MuleSoft_Meetup_16-Aug.pptx
Montreal MuleSoft_Meetup_16-Aug.pptxMontreal MuleSoft_Meetup_16-Aug.pptx
Montreal MuleSoft_Meetup_16-Aug.pptx
 
Features of SmartCloud Notes in Hosted and Hybrid Environments
Features of SmartCloud Notes in Hosted and Hybrid EnvironmentsFeatures of SmartCloud Notes in Hosted and Hybrid Environments
Features of SmartCloud Notes in Hosted and Hybrid Environments
 
Understanding Azure AD
Understanding Azure ADUnderstanding Azure AD
Understanding Azure AD
 
Directory Synchronization Single Sign-On in Office 365
Directory Synchronization Single Sign-On in Office 365Directory Synchronization Single Sign-On in Office 365
Directory Synchronization Single Sign-On in Office 365
 
29041329 interview-questions-for-server-2003
29041329 interview-questions-for-server-200329041329 interview-questions-for-server-2003
29041329 interview-questions-for-server-2003
 
New Features Lotus Domino Administration 8.5
New Features Lotus Domino Administration 8.5New Features Lotus Domino Administration 8.5
New Features Lotus Domino Administration 8.5
 
server configuration concepts in system admin
server configuration concepts in system adminserver configuration concepts in system admin
server configuration concepts in system admin
 
Cloud Computing
Cloud ComputingCloud Computing
Cloud Computing
 
Deploying DAOS and ID Vault
Deploying DAOS and ID VaultDeploying DAOS and ID Vault
Deploying DAOS and ID Vault
 
CloverDX for IBM Infosphere MDM (for 11.4 and later)
CloverDX for IBM Infosphere MDM (for 11.4 and later)CloverDX for IBM Infosphere MDM (for 11.4 and later)
CloverDX for IBM Infosphere MDM (for 11.4 and later)
 
MuleSoft Surat Virtual Meetup#35 - Setting up MuleSoft Runtime and Anypoint C...
MuleSoft Surat Virtual Meetup#35 - Setting up MuleSoft Runtime and Anypoint C...MuleSoft Surat Virtual Meetup#35 - Setting up MuleSoft Runtime and Anypoint C...
MuleSoft Surat Virtual Meetup#35 - Setting up MuleSoft Runtime and Anypoint C...
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
48. Azure Active Directory - Part 1
48. Azure Active Directory - Part 148. Azure Active Directory - Part 1
48. Azure Active Directory - Part 1
 
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdf
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdfDumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdf
DumpsCafe Microsoft-AZ-104 Free Exam Dumps Demo.pdf
 
Us sbsc aurora presentation
Us sbsc   aurora presentationUs sbsc   aurora presentation
Us sbsc aurora presentation
 

Más de Gabriella Davis

A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Engage2022 - Domino Admin Tips
Engage2022 - Domino Admin TipsEngage2022 - Domino Admin Tips
Engage2022 - Domino Admin TipsGabriella Davis
 
. Design Decisions: Developing for Mobile - The Template Experience Project
. Design Decisions: Developing for Mobile - The Template Experience Project. Design Decisions: Developing for Mobile - The Template Experience Project
. Design Decisions: Developing for Mobile - The Template Experience ProjectGabriella Davis
 
Domino Server Health - Monitoring and Managing
 Domino Server Health - Monitoring and Managing Domino Server Health - Monitoring and Managing
Domino Server Health - Monitoring and ManagingGabriella Davis
 
An Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation RequirementsAn Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation RequirementsGabriella Davis
 
× The Road To A #Perfect10 - How To Get Ready For Domino, Sametime, VOP and T...
× The Road To A #Perfect10 - How To Get Ready For Domino, Sametime, VOP and T...× The Road To A #Perfect10 - How To Get Ready For Domino, Sametime, VOP and T...
× The Road To A #Perfect10 - How To Get Ready For Domino, Sametime, VOP and T...Gabriella Davis
 
How To Approach GDPR Preparation & Discovery
How To Approach GDPR Preparation & DiscoveryHow To Approach GDPR Preparation & Discovery
How To Approach GDPR Preparation & DiscoveryGabriella Davis
 
An Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation RequirementsAn Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation RequirementsGabriella Davis
 
A Guide To Single Sign-On for IBM Collaboration Solutions
A Guide To Single Sign-On for IBM Collaboration SolutionsA Guide To Single Sign-On for IBM Collaboration Solutions
A Guide To Single Sign-On for IBM Collaboration SolutionsGabriella Davis
 
Embracing iot in the enterprise
Embracing iot in the enterpriseEmbracing iot in the enterprise
Embracing iot in the enterpriseGabriella Davis
 
Benefits and Risks of a Single Identity - IBM Connect 2017
Benefits and Risks of a Single Identity - IBM Connect 2017Benefits and Risks of a Single Identity - IBM Connect 2017
Benefits and Risks of a Single Identity - IBM Connect 2017Gabriella Davis
 
Domino in the Back, Party In The Front
Domino in the Back, Party In The FrontDomino in the Back, Party In The Front
Domino in the Back, Party In The FrontGabriella Davis
 

Más de Gabriella Davis (17)

A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Engage2022 - Domino Admin Tips
Engage2022 - Domino Admin TipsEngage2022 - Domino Admin Tips
Engage2022 - Domino Admin Tips
 
. Design Decisions: Developing for Mobile - The Template Experience Project
. Design Decisions: Developing for Mobile - The Template Experience Project. Design Decisions: Developing for Mobile - The Template Experience Project
. Design Decisions: Developing for Mobile - The Template Experience Project
 
Domino Server Health - Monitoring and Managing
 Domino Server Health - Monitoring and Managing Domino Server Health - Monitoring and Managing
Domino Server Health - Monitoring and Managing
 
60 Admin Tips
60 Admin Tips60 Admin Tips
60 Admin Tips
 
An Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation RequirementsAn Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation Requirements
 
× The Road To A #Perfect10 - How To Get Ready For Domino, Sametime, VOP and T...
× The Road To A #Perfect10 - How To Get Ready For Domino, Sametime, VOP and T...× The Road To A #Perfect10 - How To Get Ready For Domino, Sametime, VOP and T...
× The Road To A #Perfect10 - How To Get Ready For Domino, Sametime, VOP and T...
 
How To Approach GDPR Preparation & Discovery
How To Approach GDPR Preparation & DiscoveryHow To Approach GDPR Preparation & Discovery
How To Approach GDPR Preparation & Discovery
 
An Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation RequirementsAn Introduction To The DMARC SMTP Validation Requirements
An Introduction To The DMARC SMTP Validation Requirements
 
Brand Yourself
Brand YourselfBrand Yourself
Brand Yourself
 
Home Working
Home WorkingHome Working
Home Working
 
A Guide To Single Sign-On for IBM Collaboration Solutions
A Guide To Single Sign-On for IBM Collaboration SolutionsA Guide To Single Sign-On for IBM Collaboration Solutions
A Guide To Single Sign-On for IBM Collaboration Solutions
 
The Imposter Syndrome
The Imposter SyndromeThe Imposter Syndrome
The Imposter Syndrome
 
Embracing iot in the enterprise
Embracing iot in the enterpriseEmbracing iot in the enterprise
Embracing iot in the enterprise
 
Benefits and Risks of a Single Identity - IBM Connect 2017
Benefits and Risks of a Single Identity - IBM Connect 2017Benefits and Risks of a Single Identity - IBM Connect 2017
Benefits and Risks of a Single Identity - IBM Connect 2017
 
Domino in the Back, Party In The Front
Domino in the Back, Party In The FrontDomino in the Back, Party In The Front
Domino in the Back, Party In The Front
 
Penumbra briefing
Penumbra briefingPenumbra briefing
Penumbra briefing
 

Último

Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 

Último (20)

Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 

Setting Up a Hybrid Domino Environment to Ease your Way to the Cloud

  • 1. Gabriella Davis - gabriella@turtlepartnership.com IBM Lifetime Champion for Social Business TheTurtle Partnership 1 SETTING UP A HYBRID DOMINO ENVIRONMENT TO EASE YOUR WAY TO THE CLOUD
  • 3. THE GOAL All users continue working together regardless of whether they are assigned to on premises or cloud servers Applications hosted on on premises servers can be accessed by any user Administration continues to be handled by corporate Domino administrators All users have access to Notes,Verse,Traveler, Connections, Sametime 3
  • 5. HYBRID SERVER ROLES Directory Server - synchronises directories into the cloud Directories can be used to provision users or purely for lookups Mail Hub server - all mail inbound for cloud users and mail between cloud and on premises users is routed through the Mail Hub(s) Passthru server - in an isolated domain. The Cloud servers connect to the Passthru server to reach the Directory and Mail Hub The passthru server(s) are often in the DMZ 5
  • 6. 6 ON PREMISES TURTLE DOMAIN Mail Server1 Mail Server2 Mail Hub Directory Server CLOUD DOMAIN Smartcloud Server1 Smartcloud Server2 ON PREMISES PASSTHRU DOMAIN Passthru Server Assigned servers in IBM Cloud These are managed for you Mail Hub Server:All mail between on premises and cloud users route through this server Directory Server: Synchronising directories (and populating users) in the cloud Smartcloud servers connect to the Mail Hub and Directory Servers via the Passthru
  • 7. ON PREMISES OPEN PORTS Inbound NRPC 1352 for service users to access on premises server applications SMTP (25) if you have configured Smartcloud to route all outbound mail via on premises servers Outbound NRPC 1352 for Notes client to access Cloud servers HTTPS 443 forTraveler, Connections Instant Messaging 1533 7
  • 8. PLANNING How many Passthru, Directory and Mail Hub servers will you have Servers are connected to from the Cloud, they do not connect to the Cloud They are connected to in a failover, not load balanced, configuration How will outbound mail route By default IBM routes outbound mail sent by service users out through its own servers You can configure your IBM Cloud account to sent outbound mail via your Mail Hub instead Which users will be in the cloud vs on premises 8
  • 9. DIRECTORY SYNCHRONISATION What directories replicate to Smartcloud Directories containing Smartcloud users must be replicated Directories containing on premises users must be replicated if smart cloud users are going to schedule meetings / work seamlessly with them LDAP directories cannot be used in Smartcloud environments Group and Policy names must be unique if you have multiple directories (that’s true regardless of Smartcloud) Multiple servers must use identical file names / paths for directories 9
  • 10. MAIL ROUTING Internal Users route internally via on premises servers Smartcloud to On Premises routes via Passthru server(s) to Mail Hub Smartcloud to extended directory users routes via Passthru to Mail Hub On premises to Internet routes out via SMTP on internal network routing Smartcloud to Internet routes directly out via IBM’s cloud servers by default Customer SMTP routing is an optional alternative 10
  • 11. DOMAINS The passthru server should be in its own domain A domain is separate from an organisational certifier Servers can be in different domains but have the same certifier Having a server in its own domain minimises the risk of exposing internal configuration details and provides a layer of “opt in” security 11
  • 12. CREATING AN OU CERTIFIER The Cloud servers will be created by the IBM Smartcloud service and named automatically They will use an OU certifier you create that must be separate from any other use in your organisation Must be a child of your organisational certifier The server certifier used for the Smartcloud server must be a downstream OU, not a different O The server ID can have a password but only one The OU name must be at least 3 characters long 12
  • 13. UNIQUENESS Your Organisational certifier will be verified for uniqueness within the cloud service Your top level certifier name must be unique within Smartcloud.. If there’s another “Turtle” out there then I have to use a different certifier for my cloud and passthru servers. 13
  • 14. BEFORE STARTING Build your Passthru server(s) in its own domain Build your mail hub and directory server(s) within your existing internal domain Replicate the directories you want to use in the cloud to the directory server(s) Create the OU certifier to be used by the cloud servers Ensure the correct domain is defined in the Directory Profile (Actions - Edit Directory Profile) 14
  • 16. 16
  • 17. 17 This is our starting point.We have configured nothing. We can keep coming back to this point to check what needs to be done next
  • 18. 18 Flores/Turtle We can add multiple Domino directories to use They don’t need to be configured as directories on the Directory sync server Each directory can have a failover server but this doesn’t use Domino clustering to failover
  • 19. 19
  • 20. 20 The Cloud servers that will be created for you will use this base name + # + OU e.g. TurtleMail1/TTL/Turtle TurtleMail2/TTL/Cloud
  • 21. 21 “Cloud” is the OU I setup to be used by the cloud servers ptserver.turtlehost.net
  • 22. 22 Upload the dedicated OU certifier and submit its password so Smartcloud can use it
  • 23. 23 Once all the steps are complete click on the pre- configuration tool which downloads an NSF called liveservercheck.nsf
  • 24. 24 Open liveservercheck.nsf in Domino Administrator. Make sure you can connect to all servers with Admin rights Flores/Turtle
  • 25. 25 Once all the tests are successful you can Enable the Smartcloud Notes account and that will reveal the Domino ConfigurationTool menu
  • 26. 26 downloads liveserverconfig.nsf which you should open through Domino Administrator 1. 2. 3.
  • 27. 27
  • 28. 28 For each domain in your Global Domain Document a unique key will be created that you must use to create a CNAME DNS entry
  • 29. 29
  • 30. 30 Once your Smartcloud account is activated these management menu options appear
  • 32. PROVISIONING USERS Automatically from a directory The Smartcloud servers connect to your Directory Servers to replicate the directory(ies) You can configure multiple directories to be populated into Smartcloud specifying “do not provision from this directory’ prevents the Smartcloud server creating user accounts from person documents 32
  • 33. USER PROVISIONING Registered in a Directory synchronisation server Creates a temporary mail file User appears in the provisioning view once synchronisation is complete 33
  • 34. 34 Users who are synchronised and ready to be provisioned All users
  • 35. 35 Search and find a user to provision
  • 37. 37
  • 39. 39 Management options. The ID is automatically uploaded from the on premises ID Vault
  • 40. 40
  • 41. REPLICATION OF DIRECTORY Pull Person documents not including mail server and mail file name Policies (not including organisational policies) Groups Rooms and Resources Push Mail file, server and SaasIdentityID fields in person documents (the last representing the Connections cloud account Specific server groups used by Smartcloud IDVault information for the Smartcloud vault 41
  • 42. DUPLICATE NAMES Domino directory takes priority of Extended Catalog First person entry is the one used Public key checking won’t work 42
  • 43. RESERVED GROUPS AND ALL ENTRIES Directory Synchronisation servers - Manager access including delete rights Server Group “LLNServers” - Editor rights with roles [UserModifier] [GroupCreator] [GroupModifier] LLNMailHubs is reserved for Smartcloud Certifiers_ or SAAS are group prefixes used by Smartcloud Server Group “SaaSLocalDomainServers” - Manager with delete rights Wildcard naming in group names aren’t supported e.g */Turtle 43
  • 44. POLICIES On premise Domino administrators can use policies to manage both on premise and cloud users Policies in a synchronised directory are applied to cloud users Only explicit policies are recognised, organisational ones are ignored Policy names should be unique across all directories 44
  • 45. 45
  • 46. 46
  • 47. 47
  • 48. 48
  • 49. 49
  • 51. SUPPORTED LOGINS Notes ID - Notes client access Cloud Service Account - iNotes,Verse, Traveler, Sametime Federated SAML Login - iNotes,Verse, Traveler for Android only Application Passwords -Traveler, Sametime 51
  • 52. USER LOGINS IDVault Syncing ID passwords when service passwords are changed Password settings can be controlled by a security policy that applies to Cloud assigned users 52
  • 53. 53
  • 54. FEDERATED LOGINS SmartCloud Notes support SAML Federation You must configure SAML in your on premises environment first then contact customer services to provide them the information for the Smartcloud servers If SAML is enabled then service login passwords are no longer used and application passwords must be used instead 54
  • 55. APPLICATION PASSWORDS Application Passwords vs Service Passwords Application passwords are 16 characters long and generated automatically on user request they are shown to the user once users can generate new ones or disable the existing one Restricting access to the service for an ip range will most likely preventTraveler or mobile applications from working and requires an application password 55