Limitations when Notes IDs are not in the vault

There are advantages to using and storing IBM® Notes® ID files in a vault in the service. All Notes client users have a Notes ID, which is automatically uploaded to the vault at some point after the client connects to the service. Users who will not use a Notes client to access the service are not a required to have a Notes ID. However, these users are limited if they do not have a Notes ID in the service vault.

Service users who will use only the web client or IBM Verse , and who do not have a Notes ID stored in the vault, cannot perform secure mail operations (signing mail, and reading or sending encrypted mail). These limitations also apply to IBM Notes Traveler and BlackBerry® smartphone users. If your users do not now and never have had a Notes ID, and they do not need to perform secure operations, then they do not require Notes IDs.

If, however, they previously had a Notes ID, but it will not be stored in the service vault, then these additional limitations apply:
  • If the mail file is transferred to the service without an imported Notes ID, then users cannot read old encrypted messages if there are any.
  • Administrators cannot reset the Notes password
  • Notes ID password resets and ID recovery are not available.
  • If the user's name changes, the user's Notes name cannot be changed.

If you are transferring mail files of users who currently have a Notes ID, users can import their Notes ID into the mail file before you transfer mail files. The Notes ID is uploaded to the vault the first time a user performs a secure mail operation, such as sending signed mail or reading encrypted mail. Alternatively, users can use the web client to upload the ID file to the service after they have been provisioned, or administrators can upload ID files.

If a user has a Notes ID, but the Notes ID is not stored in the vault in the service, you cannot rename the user. If however, you want to be able to rename a user, but do not want to store the user's Notes ID in the vault, you can modify the user's Person document to reflect that the user will not use a Notes ID file again. Then, you can rename the user on premises using the Rename feature in the Domino® Administrator client. To allow renames to succeed, remove the following items from the user's Person document in the Domino Directory on a server that you synchronize with the service:
  • Certificate
  • CertificateExpiration
  • CertificateIssuer