matnewman.com

Domino Administrators ID file certificate has expired ... No Problem

Mat Newman  22 February 2011 09:13:25 AM
Came across this at a new client site today, the client knows the Domino Administrators password, but cannot use the Administration client (or any Notes client) with the Administrators ID file, because the Administrators ID file certificates have expired.

It's a pretty simple thing to fix.

EITHER:
  • Use your server's Notes client to recertify the Administrator.

OR
  • Get hold of an ID file for a user who hasn't expired,
  • Add that user to the 'LocalDomainAdmins' group,
  • Access the Domino Directory on the server and recertify the Admin ID,
  • Remove the user from the 'LocalDomainAdmins' group,
  • Done.

The details:

Using a server.
  • Go to the physical domino server,
  • Browse to the Domino program folder,
  • Locate nlnotes.exe,
  • Run it.

Yes I KNOW this is not a 'supported configuration' but hey, it Domino - #ThisS***JustWorks.

 
  • You now have a notes client, which you can use to access the names.nsf locally (the Domino Directory),
  • Go to 'People',
  • Choose (highlight) the Administrator,
  • Choose (from the menu) ACTIONS -> Recertify Selected People,
  • Choose the Administrators organization certifier,
  • Enter the certifier password.
  • Choose a date a long time from now (you WANT your Admin ID file to expire every two years???),
  • Done.

The Long way - elevate another user.


If you know the Administrators password, there is a fair chance you can still access the Domino Web Administrator using that password:
  • Log-in to the Webadmin using: http://yourserver.com/webadmin.nsf and the Administrators Username and Password,
  • Go to 'People and Groups',
  • Edit the 'LocalDomainAdmins' group to include the users name who's ID file has not expired,
  • On the Domino Console, 'load updall -r names.nsf', then 'dbcache flush',
  • Start the users Notes client,
  • Open the Domino Directory (names.nsf) on the server,
  • Choose People from the navigator,
  • Highlight the Administrator,
  • Choose (from the menu) ACTIONS -> Recertify Selected People,
  • Choose the Administrators organization certifier,
  • Enter the certifier password.
  • Choose a date a long time from now (you WANT your Admin ID file to expire every two years???),
  • Using any method you want (you've got a recertified Admin now), remove the user from the 'LocalDomainAdmins' group,
  • Done.


Hope this helps someone, this has happened a few times in the last couple of months when we pick up a new (old) Notes customer who hasn't needed to use the Admin ID in a while.

Domino Administrators ID file certificates have expired? No Problem.


Comments

1Paul Mooney  22/02/2011 10:53:07 AM  Domino Administrators ID file certificate has expired ... No Problem

Mat - nlnotes can seriously screw up policies. Depending on the version of domino / notes. Doesn't always "just work".

Of course, you could always do the time travel trick ;)

2Mat Newman  22/02/2011 10:55:15 AM  Domino Administrators ID file certificate has expired ... No Problem

@1, Paul: Noted, thanks mate. Client was actually on R5 (no comments please!) so no issue, versions R6 & 7 are safe for above, but yes - there *can* potentially be problems doing the 'server fix' with 8.*. In that case, use the 'Elevated User' method to resolve.

3Blonde  22/02/2011 8:44:36 PM  Domino Administrators ID file certificate has expired ... No Problem

huhuuuu, it´s great! Thanks for tip!

4Albert Buendia  22/02/2011 9:54:49 PM  Domino Administrators ID file certificate has expired ... No Problem

I think nlnotes.exe is no longer available into the domino program directory for security reasons. We installed a new instance of Domino 8.5.2 the last weekend and there is no nlnotes.exe.

So this option is only available for "legacy" Domino versions ;)

5Gregg Eldred  23/02/2011 12:44:12 AM  Another Option

Mat, here's one more method to resolve this issue:

{ Link }

6Keith Brooks  23/02/2011 1:27:29 AM  Domino Administrators ID file certificate has expired ... No Problem

Mat,

I agree with Paul, don't advocate nlnotes unless no other option is feasible.

That said, if NONE of your IDs are still valid(yes it can happen), you will need to follow what I went through at a client a few years back.

Suffice it to say recreating a cert ID is not for the junior admin.

Blog post here: { Link }

7Keith Brooks  23/02/2011 1:35:29 AM  Domino Administrators ID file certificate has expired ... No Problem

Sorry, that was not the right post, this is the one: { Link }

The Technote found here:

{ Link }

Is titled:

What to do when a Certifier ID is stolen, lost or compromised

Which is where sometimes we end up because someone created IDs in batch.

8Mat Newman  23/02/2011 7:14:49 AM  Domino Administrators ID file certificate has expired ... No Problem

@3, Blonde: No Problem :-)

@4, Albert: No NlNotes is not icluded in Domino server install anymore. You will only find it after an upgrade from previous releses.

@5, 6, 7: Keith and Greg, that's what makes our community so LEGENDARY! Post a solution and get more in reply. Do you guys mind if I consolidate these into a Wiki article on Notes.net (ldd)?

And yes folks the quick'n'dirty nlnotes.exe on the server solution as highlighted by Paul and Keith - IF it's avalaible - *may* cause issues with your system. The longer - but safer - solution is the 'elevated user' option, especially in an 8.* environment.

9MatD  24/10/2012 5:15:41 PM  Domino Administrators ID file certificate has expired ... No Problem

Thank you Mat, that saved my life! ;)

Cheers, MatD

10Lina   21/03/2013 11:00:17 AM  Domino Administrators ID file certificate has expired ... No Problem

Hello Mat,

I have a strange situation. We have a Domino Traveler server 8.5 in a standalone domain since our organization is still on R7. Admin ID was certified before it expired on it, but it is still giving error message, "Server error: Certificate has expired." I have followed all the procedures to recertify the admin ID in the local server through Admin console and replaced the old ID file with the newly certified ID. I am still unable to open up Names.nsf with this ID file. Also another thing that when I recertify admin ID it shows expiration date for 2050 and new certify date for 2015. Thus ID should work and system should not prompt for expiration. What should I do to correct this error message?? Any help will be appreciated.

thanks,

Lina

Mat Newman

THE Lotus Notes Guy. Productivity Guru. Social Evangelist. IBM Champion for IBM Collaboration Solutions, 2011/2012/2013.

#GetProductive #GetLotusNotes

Mat Newman

New to IBM Lotus Notes? START HERE



I'm attending. IBM Software.
      Lotusphere 2012. Business. Made Social. January 15 - 19. Orlando,
      FL. Drive Adoption for IBM Connections



Home  | 

Get Serious. Get Domino.