Get started Bring yourself up to speed with our introductory content.

How can I automate the addition of a user cert to that user's person doc?

The client I work for is implementing PKI/x.509 certificate authentication (using third-party DoD certificates), and we are using the certpub.nsf database to collect and register certificates for Web users. I'm trying to automate the button in the certpub.nsf that "accepts" and adds the user cert to the user's person doc in the Names and Address Book (NAB/Directory) via AdminP. There is an @Formula that only works from the Notes Client:

I would like to either figure out a way in Script to duplicate the formula or figure out what the AdminP process does to add the cert to the person doc in the NAB. I need to know what fields it sets and what fields/data is populated in the NAB. I also need to know how to format the cert itself. The data in the certificate field contains a string. Once AdminP processes the request and adds the cert to the NAB, is it converted to hex or some other format?

I'm at a loss in finding any kind of documentation on this subject.
I looked into something like this a while ago. I believe that this is a very hard programming problem that you outline. I am not saying it is impossible, but it is tricky. The only specific suggestion I have is that there may be a couple existing 3rd party products that do what you want (or almost what you want). Buying one of these might be easier than re-inventing the wheel. Here's one that may help you.

Dig Deeper on Lotus Notes Domino Access, Permissions and Authentication

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.




  • iSeries tutorials

    Search400.com's tutorials provide in-depth information on the iSeries. Our iSeries tutorials address areas you need to know about...

  • V6R1 upgrade planning checklist

    When upgrading to V6R1, make sure your software will be supported, your programs will function and the correct PTFs have been ...

  • Connecting multiple iSeries systems through DDM

    Working with databases over multiple iSeries systems can be simple when remotely connecting logical partitions with distributed ...