#Admin
Posts tagged #Admin · 16 posts
- XPages: Documents Don't Show When a Multi-Column Category's Next Column Is Also a Category — the 12.0.2 Regression
An XPages view categorized on multiple columns: you apply a filter, and where the next column is still a category, the screen shows the category but the documents under it disappear — in 12.0.2, though 12.0.1 works. It's an HCL-acknowledged regression (KB0102504 / SPR# MNIACMGKUV), introduced when 12.0.2 fixed another bug (SPR# PJONB7GRUL). The workaround is DISABLE_REFIND_IN_READENTRIES=1 in the server notes.ini; the real fix is 12.0.2 FP3 or 14.0. This covers the symptom, why it happens, the workaround and fix, and the wider family of 12.0.2 sub-category-display regressions (like the @PickList variant in KB0102042, which needs a different parameter and fix version) so you can match the right one.
2026.10.06 - Field Notes from panagenda's MakeNotesFaster Webinar: Slow Notes Is Usually Configuration, Not Old Laptops
In panagenda's MakeNotesFaster webinar, Christoph Adler breaks HCL Notes 14.5.1 FP1 client performance on Windows down to two decisions: run the right version, configure it right. Here are the points most useful to admins — one brutal real-world customer number, why ODS quietly steals startup time on every open, whether you should delete cache.ndk regularly (he debunks the myth outright), keeping the data directory off network shares, the three traps in an antivirus exclusion set, and the Monday-morning checklist he closes with.
2026.09.26 - The Two Jobs of dircat: You Think It Only Builds the Directory Catalog — Since Domino 12 It Also Runs Entitlement Auditing
See dircat (Directory Cataloger) in show tasks and most people think 'directory catalog' — aggregating multiple Domino Directories into one lookup-friendly directory. That's its day job. But since Domino 12 the task quietly took a second one: aggregating each server's entitlement data into entitlements.nsf, a licensing-compliance audit with nothing to do with directories. This covers dircat's real job (condensed vs extended catalogs, and why DIRCAT5.NTF isn't CATALOG.NTF), its hidden second role since Domino 12, and how one task with two jobs bites.
2026.09.25 - Who Is the Domain Administration Server? One Domino ACL Setting Behind Entitlement Aggregation, CertMgr, and AdminP
An additional server cold-boots and floods the console every 5 seconds with 'Error connecting to server…', trying to reach every server in the domain. The culprit wasn't entitlement config at all — it was a single ACL setting that had quietly made this server the 'domain administration server.' This piece covers how many meanings 'administration server' has in Domino, what actually decides the domain-admin identity, which subsystems it silently drives (domain-wide entitlement aggregation, CertMgr, AdminP), and how to split those responsibilities apart.
2026.09.24 - Why Deleted Documents Come Back: Deletion Stubs, the Purge Interval, and Two Ways They Resurrect
You delete a document and days later it's back — not a haunting. In Domino a delete doesn't erase the document; it leaves a deletion stub, a marker that lets replication carry "this one was deleted" to the other replicas. Stubs get cleaned up on the purge interval (default 90 days). Documents "resurrect" for one of two reasons: the stub was purged before it replicated, or the same document was edited on one replica and deleted on another and the edit won. This piece explains the mechanism, both causes, and the settings that prevent it.
2026.09.19 - updall, fixup, compact: Which One to Run When a Database Is Broken, Bloated, or Its Views Are Wrong
Domino's three database-maintenance commands are the easiest to reach for blindly: run fixup because a view is stale, run fixup because the file got fat, run compact because it won't open — and get nowhere. Each treats a different illness: updall handles indexes (views / full-text), fixup repairs corruption (documents / structure), compact reclaims space (bloat). This piece sorts them by symptom, plus the official escalation order for corruption: updall first, then fixup, then compact -c.
2026.09.18 - Domino Server Troubleshooting: Before You Restart the Whole Server, Run These Console Commands
Something's off with the server — a feature stopped working, a task looks stuck, memory or disk is tight. The reflex is to restart the whole server, but that's blunt and wipes the scene. This piece organizes the most useful Domino console commands by the problem you're facing: show tasks to see what's running/stuck, show server for overall health, restart task <task> to restart just the one misbehaving task (e.g. restart task http, not the whole box), tell http show thread state to find a stuck thread, and dbcache show/flush/disable for the database cache. Look first, then decide what to touch.
2026.09.17 - Wiring Domino CertMgr to Let's Encrypt: Automatic TLS Certificate Requests and Renewals over ACME
Manual certificate import still means swapping every 90 days, and still means forgetting. This piece (part two of the certstore series) covers CertMgr's real killer feature: requesting, configuring, and renewing free, trusted TLS certificates from Let's Encrypt automatically over the ACME protocol. Set up the two ACME account profiles (Staging/Production) and Global Settings, walk the request flow and the six things CertMgr does automatically after Submit, understand HTTP-01 vs DNS-01 challenges, and see why the micro CA is test-only, plus ECDSA and key rollover.
2026.09.03 - Getting Started with Domino Certificate Management: CertMgr and certstore.nsf Instead of Scattered .kyr Keyrings
Since Domino 12, TLS certificates no longer live as .kyr keyring files scattered across each server's disk — one CertMgr server task plus one certstore.nsf database manages them all: certificates stored in TLS Credentials documents, private keys encrypted with 256-bit AES, protected by the database ACL, and readable only by the servers you choose. Part one of the certstore series: the model, how to stand certstore.nsf up, what a TLS Credentials document holds, and the full steps to import an existing third-party CA certificate.
2026.09.02 - Managing the Full-Text Index from Code: CreateFTIndex, UpdateFTIndex, and the Local-vs-Server Split
FTSearch needs a full-text index to be fast — and to support wildcards and relevance ranking — and NotesDatabase can create, update, and remove one from LotusScript. The catch is a split almost nobody expects: CreateFTIndex / UpdateFTIndex / RemoveFTIndex work on LOCAL databases only, while FTIndexFrequency is server-only, and server indexes are actually managed by the Updall task (updall -X rebuilds, it doesn't create). This article covers the options bitmask, the create-vs-update distinction, and that split.
2026.07.17 - NotesAdministrationProcess: Filing AdminP Requests from LotusScript
Renaming a user, deleting one cleanly, recertifying, moving a mail file, changing an Internet password — these are AdminP jobs you'd normally click through in the Administration client. NotesAdministrationProcess files those same requests from code into admin4.nsf. This article covers session.CreateAdministrationProcess, the request methods and their note-ID return value, the certifier properties, and the three things that trip people up: it needs unrestricted rights, it's asynchronous, and '*' means 'no change'.
2026.06.29 - NotesIDVault: Pulling IDs from the ID Vault, Syncing, and Resetting Passwords in Code
The ID Vault is Domino's policy-based facility for centrally storing user ID files. NotesIDVault lets you operate it from code — pull a user's ID file out of the vault, sync a local ID back, check whether someone's ID is in the vault, even reset a vault password. This article covers getting it, the GetUserIDFile / SyncUserIDFile / IsIDInVault / ResetUserPassword / PutUserIDFile methods, its relationship to NotesUserID, and the permission prerequisites for these operations.
2026.06.25 - The ODS Developers Rarely Notice: Domino's Database Format Versions, and What Actually Triggers an Upgrade
You write LotusScript / XPages all day and probably never think about a database's ODS (on-disk structure) version — until a feature like LargeSummary needs a certain ODS, or you move an old database between servers and aren't sure whether its ODS follows. This article covers the ODS-to-release mapping from a developer's angle, the most counterintuitive point (upgrading the server version does not upgrade the ODS), and exactly what triggers an ODS change and what governs it — then answers a concrete case: an R9 ODS51 database, new-copied from an R12 client to an R12 server, does its ODS change automatically?
2026.06.21 - Domino REST API: v1.1.7 Is the Current Latest — New Endpoints and Fixes
HCL Domino REST API's current latest release is v1.1.7 (shipped April 7, 2026), adding endpoints for calendar profiles, PIM unread state, and message updates, plus fixes for attachment download, Microsoft Entra ID auth, and meeting invitations.
2026.05.04 - Domino V12 lets notes.ini hold multiple HTTPAdditionalRespHeader entries
Older Domino releases let you put exactly one HTTPAdditionalRespHeader in notes.ini — a second line silently overwrote the first. HCL added a numbered convention (HTTPAdditionalRespHeader01, 02, …) in V12.0.x so you can ship a full security-header baseline through notes.ini alone, which is the only path that still works when HTTP won't start and the Internet Site documents are unreachable.
2026.04.28 - HCL Domino REST API Quickstart Guide
This guide walks you through installing, configuring, and starting with the HCL Domino REST API, enabling access to Domino databases via a modern RESTful interface.
2026.04.28