199 Lotus blogs updated hourly. Who will post next? Home | Blogs | Search | About 
 
Latest 7 Posts
Our story continues.....
Tue, Dec 13th 2016 7
#employed
Tue, Nov 15th 2016 9
An iOS10 gotcha for the 16GB'ers
Thu, Sep 15th 2016 8
Missed the blog-o-versery
Tue, Aug 16th 2016 9
My updated birthday edicts! - OBEY!
Tue, Jun 28th 2016 6
With my boots on
Thu, Apr 14th 2016 8
The Curious Case Of The Configuration Document
Sun, Feb 7th 2016 7
Top 10
The horrors of migrating to Domino when Single Item Recovery is in use on Exchange
Mon, Mar 16th 2015 11
A friendly reminder about iOS9, Traveler and self-signed certificates on Domino
Fri, Aug 14th 2015 10
Unable to find where I am in Sametime
Fri, Jan 9th 2015 10
A mystery......
Wed, Dec 4th 2013 10
Missed the blog-o-versery
Tue, Aug 16th 2016 9
Migrating Traveler to HA Error
Sat, Mar 15th 2014 9
The annoyance that is encrypted internet mail
Wed, Jan 22nd 2014 9
#employed
Tue, Nov 15th 2016 9
An iOS10 gotcha for the 16GB'ers
Thu, Sep 15th 2016 8
With my boots on
Thu, Apr 14th 2016 8


The Curious Case Of The Configuration Document
Twitter Google+ Facebook LinkedIn Addthis Email Gmail Flipboard Reddit Tumblr WhatsApp StumbleUpon Yammer Evernote Delicious
   

Wow, had to blow the dust off of the old blog here so that I could share something I learned over the weekend.  And it was a bitter lesson, indeed.

Here's the scenario:
Had to stand up a new Domino server in my domain that would allow for SMTP traffic between us and our cloud based anti-spam/malware service.  A requirement of this mail flow topology is that the connectivity between my on-prem and cloud solution must have TLS connectivity.  Okay, not a big deal, right?  Well, it didn't work out that smooth.

First, I followed Gab's steps on how to create a secure SSL certificate with Domino.  Yes, Gab is awesome for writing these steps up.  Then, I went through and followed the standards that IBM has had set for years on setting your configuration document up to allow for TLS to work.  Okay, no worries, right?  Well just like in life, things don't always work the way you want them to.  When we started testing of the mail flow, we were getting repeated messages from the vendor in the cloud that they Domino server was not allowing for a STARTTLS session.  So I opened a ticket with IBM, I opened a ticket with the vendor, I had people at work much more knowledgeable then me try to hack into the servers connection and they were able to get a STARTTLS, but nothing I did with anyone , vendor, consultant worked.  

And that's when it hit me.

I deleted the configuration document for that particular Domino server, replicated that delete around, then went back in and recreated it from scratch.  Brand new document.  Made sure all my settings were set correctly, (based on the IBM doc and a server that is already doing this in my enviroment), and then walked away from it for a while.  After a bit, I started seeing STARTTLS, (we had logging on), start flashing across my server console.  Yes Virgina, there is a STARTTLS Santa Claus!  

So, why did that work?  The simple answer is, I don't know.  It's Domino.  Domino, while it's a powerful server platform, does fall prey at times to corruption in documents.  My thought was creating a brand new server config document from the ground up may help.  In this case it did.

My word to the wise, when all else fails, go back to the basics and start over.  In this case, it paid off and we are securely communicating.




---------------------
http://macian.blogspot.com/2016/02/the-curious-case-of-configuration.html
Feb 07, 2016
8 hits



Recent Blog Posts
7
Our story continues.....
Tue, Dec 13th 2016 2:32a   Andy Donaldson
In The Next Chapter....... (the new blog)
9
#employed
Tue, Nov 15th 2016 10:46p   Andy Donaldson
It happened. Finally. I landed another position. This time, it really has nothing to do with IBM Notes/Domino being a prominent part of the position. More details later on what it is I'm doing, but I do get to stay within the IT field and utilize ALL of the skills I've gained over the past 20+ years I've been in it. I've learned a lot over these past few months. Hell, this past year. It was right around this time last year, October 29th, 2015 to be exact, that my wife Denise had the ma
8
An iOS10 gotcha for the 16GB'ers
Thu, Sep 15th 2016 2:08p   Andy Donaldson
16Gb iPhones suck.There, I've said it. They do. There is no other way around it but to state the obvious. The OS takes up around 4GB of real estate and then if you're like me, you take a whole lot of pictures and have your apps on there. You can forget about any music existing on your device because there just isn't any space for it. Yes, this has all been stated by others 1000 times over, but when you employer, former in my case, purchases the device for you saving you hundreds of dollar
9
Missed the blog-o-versery
Tue, Aug 16th 2016 9:13p   Andy Donaldson
Yesterday was the blog's 13th birthday. It's now officially a teenager. Boy has a lot gone on in my life since I started this. Really, it was almost like an official log of my career as a Lotus Notes administrator. I learned an awful lot over the years and tried to share what happened with me with others here. Even the stoopid mistakes, because those are the ones you learn the most from. I don't blog like I used to. Heck, a lot of the Yellow-verse doesn't seem to either. Most of what
6
My updated birthday edicts! - OBEY!
Tue, Jun 28th 2016 10:13a   Andy Donaldson
(Three years ago, I wrote this blog post as I was feeling reflective on my life. I have updated it with a few new things and will likely to update this yearly) So today I celebrate the 47th anniversary of my birth. Still am amazed I made it this far. But with the love of a good women at your side, two wonderful kids, a soon to be daughter-in-law, a grandson on his way and two ornery Beagles, it's not all that hard. But this morning after I awoke, I had a revelation. One day, the birthdays f
8
With my boots on
Thu, Apr 14th 2016 7:14p   Andy Donaldson
Today wasn't the best of days. After 17 years at the company I had been working for, my position was eliminated. The writing had been on the wall for some time that changes and cuts were coming to all departments and with the migration away from the Notes/Domino stack, I knew it was a matter of time. Well, times up. I truly hold no ill will to my former employers, they really are good people and a good company. It's just surprising and sad when you get the news. It's purely business. So
8
The Curious Case Of The Configuration Document
Sun, Feb 7th 2016 11:44a   Andy Donaldson
Wow, had to blow the dust off of the old blog here so that I could share something I learned over the weekend. And it was a bitter lesson, indeed. Here's the scenario:Had to stand up a new Domino server in my domain that would allow for SMTP traffic between us and our cloud based anti-spam/malware service. A requirement of this mail flow topology is that the connectivity between my on-prem and cloud solution must have TLS connectivity. Okay, not a big deal, right? Well, it didn't work out
10
A friendly reminder about iOS9, Traveler and self-signed certificates on Domino
Fri, Aug 14th 2015 10:28p   Andy Donaldson
Hey gang! It's your old pal Andy here with a friendly reminder on the 12th anniversary of the old House O' Blog. If you have a IBM Traveler server running and you are using a self-signed certificate on the Domino portion of the server, you better make sure you fix that before iOS9 launches! One of the features that iOS9 offers is that if you make an HTTPS call to a server, any server, and the certificate of that server is not signed by a trusted authority the connection will fail. I verifie
8
My Birthday Edicts - Obey!!! (Updated!)
Sun, Jun 28th 2015 11:38a   Andy Donaldson
(Two years ago, I wrote this blog post as I was feeling reflective on my life. I have updated it with a few new things) So today I celebrate the 46th anniversary of my birth. Still am amazed I made it this far. But with the love of a good women at your side, two wonderful kids and two ornery Beagles, it's not all that hard. But this morning after I awoke, I had a revelation. One day, the birthdays for me will end. Okay, I'm not saying that to be morbid, so stick with me here. But yes, on
6
Issues with IBM Verse (Traveler) App
Thu, Jun 11th 2015 10:32a   Andy Donaldson
Feels a little weird being in here. Haven't blogged in a while. Smells kind of musty. Better open a window.There. That's better.Hey kids, Andy here with a brand new blog update. Seems that last week our pals over at IBM decided that the Traveler app for Android devices needed a new coat of paint and a shiny new name. Yup, they went ahead and called the latest update to the app Verse (insert heavenly angelic chorus here). That's all fine and good, but, soon after the update hit Google Play




Created and Maintained by Yancy Lent - About - Planet Lotus Blog - Advertising - Mobile Edition