Expired ID
This is Lotus 6.5 and Domino Admin 6.5. FYI, take it easy on me I am new to lotus and now maintaining it. LoL.
Looking for relevant Lotus Domino Whitepapers? Visit the SearchDomino.com Research Library.
Brooklynegg | May 19 2008 2:13PM GMT
You should not create a new ID when they expire. You should re-certify the existing ID. Review the Admin Help database document titled “Recertifying a user ID.” It provides the process.
In our environment, we have created an additional view in the Directory that shows IDs by certificate expiration date. If you do this, you can recertify people proactively. If you start with the People view and have the UserModifier role, you will be able to see the Actions - Recertify Selected People action. Choose the people who are going to expire sometime in the future and recertify them. The next time they log on, their ID will be re-certified. If you do this on a regular basis, user will never be prompted again to request to be recertified and you will not have user IDs expiring and causing headaches.
Good Luck.
Maramor | May 29 2008 4:09PM GMT
Both solutions look good. I tested Derek’s and it works.
Brooklynegg, your suggestion it looks like I have something setup that shows expiring. Looks that that will work. Now when I recertify someone it does not disappear from list but I am going to give it some time maybe replication?
Domino Administrator > Configuration > Certificates > Certificate Expiration
According to what you have listed, it sounds that even if “ID” is expired when I “recertify” it will get the update. When the id is expired, the user cannot login unless I misunderstand.
I did read through the documentation in the help file thanks for pointing that out, it helped with understanding the maintenance.
FYI….
I am a new admin and have no experience…..
Maramor | May 29 2008 6:58PM GMT
Derek, What if by accident you go to past and the user is no longer in your clipboard? LoL
How would you add it back?
Mike Minter | May 30 2008 5:25PM GMT
The option to “Recertify” an existing user ID file is the preferred method. The reason for this is the built-in Notes/Domino PKI that is available for anyone in the Domino domain to use to encrypt and sign their emails.
When you re-certify a Notes user you are actually updating the certificate expiration dates that are used for this user. The admin may either re-certify the public key in the Domino directory or re-certify a local copy of the user’s id file as long as the password for that file is known. The Notes client will merge the new certificate information into the user’s current ID file from the directory when then next access the server.
When you create a new Notes Id file you have also created a new public/private key pair for that person. When you do that, they will no longer be able to open and read any old emails that may have been encrypted using the previous public/private key pair. If the users in the environment never use the Encryption feature then it is a moot point. Either method will work.
Derek Catanzaro | Jun 16 2008 2:20PM GMT
I agree that the preferred method is to simply recertify the id in the event that you have the users notes id file. It will save you time and is a much simpler process.
The question “how can I generate a new id file” was asked and that is what I provided an answer for. In the event that you do not have the users notes id file the instructions I provided would generate a new id file for the user. Sorry for any confusion this may have caused.
Maramor, If you lose the person doc that was attached to your clipboard the best thing to do would be to open a replica of your domino directory from another server and copy/paste the person doc from there.
GailVan | Jun 25 2008 4:51PM GMT
I’ve done the recertify method which is quick and easy. If they don’t have an id, I’d re-register them to create one, then delete the ‘old’ person doc.