SECURITY
This extra level of key verification protects against misuse of a lost or compromised ID file. Typically, if an ID file is lost, its owner needs to be registered to create a new ID file and directory entry; and if the ID file has been compromised then the owner's public and private keys need to be rolled-over and that new set of keys need to be certified (thus updating the directory entry). By enabling directory-level key checking, an attacker in possession of the old ID file will not be able to use it to access the server, even though that old ID file may contain a valid certificate.
You can also choose to control whether a log message is generated if authentication succeeds but a mismatch is detected. This allows admistrators to detect when the ID file contents have gotten out of sync with directory entries, but to do so without preventing those users from authenticating because of public key mismatches.
For more information, see Public key security.
1. From the Domino Administrator, click the Configuration tab, and open the Server document.
2. Click the Security tab.
3. In the Security Settings section, click the drop-down list next to "Compare public keys" and choose one of the following options: