The certificate authority process removes
the need for Domino administrators to have access to certificate id files
to register users. The cert.id files are stored in an encrypted database
on the server. When a user is registered a special process (the CA
task) certifies the id file created for the user after a few moments using
a special administration request. This is an automated feature and
these days pretty standard in Domino shops (unless you use custom user
management tools).
Enter ND8.5. Any site I know using
this build on the server and clients (and yes, I do know a few) are either
playing with or deploying the ID Vault. If you are a domino administrator
and don’t know what this does, where have you been? Its
the answer to a significant amount of your helpdesk calls!
Once you have implemented the ID Vault, it will upload new id files
created as soon as they are registered.
Unless you are running the certificate
authority that is…
If you are running the CA process and
the ID Vault, and register a user, you will see this..
Because the user id file is not valid
upon registration (i.e. the CA process has not certified it just yet) the
ID Vault will not accept the file. IBM have a technote saying that
the
combination of two features is currently not supported.
The error message is not totally accurate though. The account
IS created and will work, and as soon as the user logs into Lotus Notes
for the first time, the ID Vault grabs the file as it should. This
error however, would make you think the account has not been created.