Client-certified http://www.aliyun.com/zixun/aggregation/9807.html "> workflow
Typically, Lotus Quickr for Domino (hereinafter referred to as QUICKR) uses server-side authentication. Quickr is a product based on Lotus Domino Server (Domino), and part of his certification is done through Domino. Domino supports client certification, so Quickr can also use Domino to configure client authentication.
By installing Domino issued certificates and using the certificate when connecting to Quickr, the server can identify which user it is, and if it is a legitimate user, the user can access the contents of the Quickr site without having to log in.
Figure 1. Client Authentication Work Flow chart
Procedures for configuring Client authentication
This article takes Domino 8.5.1, Quickr 8.5.1 1 As an example, focusing on the entire process of client configuration. The premise of client authentication is that the server-side SSL configuration is complete, so we will first describe how to configure server-side SSL and then describe how to configure client authentication.
Domino-Side Configuration CA (certificate authority)
Open the Domino Admin application and create a new application (creator) in it. In creating a new application, first select the server to use and select the "Show advanced templates" option to create a CA application based on the Domino Certificate Authority (cca50.ntf) template, where we name it CERTCA, as shown in Figure 2 Shown.
Figure 2. To create a CA
The next step is to create the CA key ring file certificate in the application of the CA. This is the basis for all certifications. As shown in Figure 3, click "Create Certificate Authority Key Ring & Certificate".
Figure 3. Select Create CA File certificate
Fill in the key file name, password, and other DN information.
Figure 4. Fill in Key ring information
Click the "Create Certificate Authority Key Ring" to create the key ring. Note the Cakey.kyr storage path and copy it to the user's <dominodir>\data path, "Dominodir" refers to the Domino installation path.