7.3 Special considerations

This section describes considerations in authenticating Lotus Notes users.

7.3.1 Basic Authentication and Microsoft Internet Explorer Security Patch

Microsoft Security Patch MS04-004 Cumulative Security Update disallows URLs in the form http://username:password@server. This negates basic authentication functionality in this case. See http://support.microsoft.com/default.aspx?scid=kb;en-us;834489 for details on uninstalling the patch. A more secure option is to implement form-based authentication (set Notes preferences to form-based authentication) if the destination server makes this available.

7.3.2 Form Authentication and Notes Server R6+

Using an R6 or newer version of the Notes server and form authentication requires the installation of the domcfg.nsf database. See the Notes database administrator help for detailed instructions.

When using form authentication in current versions of Internet Explorer, the browser settings may need to be changed to allow session cookies.