Dear Team,
Currently, it is neither possible nor supported to activate Notes Federated Login (NFL) at the setup stage of the HCL Notes client when using the OIDC protocol. As stated in KB0134355, activating NFL during client setup is currently restricted to the SAML protocol.
We are requesting a feature enhancement to support NFL activation via OIDC immediately during the initial client setup, bypassing the need for a traditional ID file password.
Current Behavior (OIDC)
During the initial client setup, the user is prompted to enter their username and Domino server name. The client then contacts the Domino server and connects to the ID vault to locate the corresponding ID file. If found, the user is forced to enter a valid password for that ID file to continue configuration. Only after the client configuration is complete and the security policies are pushed to Notes does NFL with OIDC activate. The user then receives a pop-up prompting them to restart Notes. Upon restart, OIDC authentication finally takes over.
Current Behavior (SAML Workaround)
As described in KB0134355, KB0029854, and related documentation, administrators can currently bypass the password prompt for SAML by creating a deploy.nsf database containing exported trust certificates, copying it into the client installation package, and pushing the FORCE_PROCESS_DEPLOY_NSF=1 parameter in the notes.ini. This process is highly cumbersome and leaves room for optimization.
Expected Behavior / Proposed Solution
OIDC Support at Setup: Immediately after the user enters their username and Domino Server name, the Notes client should query if NFL with OIDC is activated for that user. If true, the client should directly initiate the OIDC authentication flow. No ID-Password query should occur.
Streamlined Trust Mechanism: The client should automatically check if NFL with OIDC is activated and verify if the necessary certificates are trusted natively —without requiring a deploy.nsf database to be injected into the client beforehand. If some of the certificates are not trusted, the users should not get an error message, rather than that, the client should silently fall back to the "standard" authentication without NFL. The deploy.nsf mechanism should only be mandated as a fallback for environments using self-signed TLS certificates or CAs not trusted by default by HCL Notes.
Business Impact & Value
Enabling NFL with OIDC at the setup stage heavily reduces the complexity of deploying Notes Federated Login. This delivers several concrete enterprise benefits:
Strict MFA & Zero Trust Compliance: By triggering OIDC at the very first step of configuration, the client immediately enforces the organization's Conditional Access and Multi-Factor Authentication (MFA) policies via the centralized IdP.
Alignment with Modern IAM Strategy: Native OIDC setup brings the Notes client in line with modern web and mobile application standards, ensuring seamless integration with enterprise Identity Providers (like Microsoft Entra ID, Okta, etc.).
Improved Security Posture: IT no longer needs to generate, transmit, or manage initial ID file passwords for end-users, eliminating a common vulnerability during user provisioning.
Accelerated Time-to-Productivity: Streamlines onboarding by allowing new hires to configure their client using their standard SSO credentials, moving closer to a true zero-touch deployment model.
Reduced IT Overhead & Measurable Cost Savings: Lowers the documentation burden for IT administrators and significantly reduces setup-related and password-reset helpdesk tickets, generating immediate ROI.
Higher Acceptance: Provides a frictionless, unified authentication experience that improves both end-user satisfaction and IT's acceptance of the platform.
Thank you in advance!