199 Lotus blogs updated hourly. Who will post next? Home | Blogs | Search | About 
 
Latest 7 Posts
Notes/Domino 9.0.1 Feature Pack 9 shipped
Sun, Aug 20th 2017 138
Blog Certificate updated and Let’s Encrypt Update
Tue, Aug 8th 2017 8
SLES 12 SP2 Issues with Domino running with Systemd
Mon, Jul 24th 2017 7
Microsoft fixes Notes Client Windows 10 Creators Crash
Wed, Jun 28th 2017 4
Traveler 9.0.1.18 with new Security Mode for Mail-File Access
Thu, Jun 22nd 2017 9
Notes Client/Windows Crash with Windows 10 Creators update
Thu, Jun 1st 2017 13
Security Bulletin: IBM Domino TLS server Diffie-Hellman key validation vulnerability (CVE-2016-6087)
Thu, Jun 1st 2017 4
Top 10
Notes/Domino 9.0.1 Feature Pack 9 shipped
Sun, Aug 20th 2017 138
IBM Notes V9.0.1 Mac 64 Bit English (CN6VDEN )
Tue, Sep 29th 2015 25
Details about JVM 1.8 Update in Notes/Domino 9.0.1 FP8
Sun, Feb 5th 2017 25
TLS 1.2 Connection Issues with mail.protection.outlook.COM
Thu, Jan 7th 2016 16
Notes Client/Windows Crash with Windows 10 Creators update
Thu, Jun 1st 2017 13
Solution for Notes/Domino related process is still running when applying a Fixpack or Hotfix
Wed, Mar 25th 2015 12
IBM Notes/Domino 9.0.1 Feature Pack 8 Preliminary Release Notice
Fri, Jan 27th 2017 11
Passing a document to an agent without saving it first
Sun, Apr 6th 2014 9
Notes/Domino 9.0.1 FP3 - Java Console/Controller Incompatibility
Wed, Feb 18th 2015 9
Traveler 9.0.1.18 with new Security Mode for Mail-File Access
Thu, Jun 22nd 2017 9


Security Bulletin: IBM Domino TLS server Diffie-Hellman key validation vulnerability (CVE-2016-6087)
Twitter Google+ Facebook LinkedIn Addthis Email Gmail Flipboard Reddit Tumblr WhatsApp StumbleUpon Yammer Evernote Delicious
Daniel Nashed    

There is a vulnerability in the TLS stack which could lead an exploit which could lead a less secure connection.
The good news is that the fix is already included in FP8. So you should upgrade to 9.0.1 FP8 if you have a public facing Domino Server with HTTPS.

See the details and reference below.

-- Daniel

A vulnerability in the IBM Domino TLS server's Diffie-Hellman parameter validation could potentially be exploited in a small subgroup attack which could result in a less secure connection.
An attacker may be able to exploit this vulnerability to obtain user authentication credentials.

Vulnerability Details

CVEID: CVE-2016-6087 / DESCRIPTION: IBM Domino could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange validation.

CVE-2016-6087 is tracked as SPR# DKEN9WGMYE.


http://www.ibm.com/support/docview.wss?uid=swg22002808


---------------------
http://blog.nashcom.de/nashcomblog.nsf/dx/security-bulletin-ibm-domino-tls-server-diffie-hellman-key-validation-vulnerability.htm
Jun 01, 2017
5 hits



Recent Blog Posts
138
Notes/Domino 9.0.1 Feature Pack 9 shipped
Sun, Aug 20th 2017 9:39p   Daniel Nashed
Notes and Domino 9.0.1 Feature Pack 9 is available. The client side and server-side introduces fixes and also new features. The official "flixlist" can be found here --> http://www.lotus.com/ldd/fixlist.nsf/0/12d957b7c277fc728525816300434c53 Here are the highlights and some important comments. JVM Update in Notes Client & Domino Server The security fixed version introduced with a JVM patch for FP8 is included in FP9: Notes/Domino - Java 1.8 SR4 FP5 But this is sti
8
Blog Certificate updated and Let’s Encrypt Update
Tue, Aug 8th 2017 9:30a   Daniel Nashed
My certificate expired after 90 days because I did not track it. And the Let's Encrypt original client configuration did not work any more when I was looking into renewal today. The client was Python based and there is a newer client --> https://certbot.eff.org/ which is officially recommended by Let's Encrypt. It's still complicated to use and you need to have Python installed. But since I first implemented it there are many other ACME clients that properly integrate with Let's Encr
7
SLES 12 SP2 Issues with Domino running with Systemd
Mon, Jul 24th 2017 10:01a   Daniel Nashed
There is a new feature introduced in SLES 12 SP2 which could lead to issues with larger Domino or Traveler servers. The default nproc size is still set to 7400. So in most cases this tunable does still not need to be set in your Domino service file. But there is a new security feature introduced in SLES 12 SP2 which will cause processes fail to start or not able to span more threads. The error you might see is the following: Jul 20 11:02:41 dom-srv kernel: cgroup: fork rejected by pi
4
Microsoft fixes Notes Client Windows 10 Creators Crash
Wed, Jun 28th 2017 8:16p   Daniel Nashed
Today I got feedback from IBM that the fix that Microsoft releases does solve the blue screen issue with Notes and the customized home page issue. There have been multiple situations in which the client crashed or caused a blue screen because of some Windows UI calls in Notes after the Windows creators update. I am interested to get feedback if the fix does solve all your Notes Client on Windows creators update. Here is a link for the update: https://support.microsoft.com/en-in/help/
9
Traveler 9.0.1.18 with new Security Mode for Mail-File Access
Thu, Jun 22nd 2017 9:07a   Daniel Nashed
Traveler 9.0.1.18 comes with a couple of minor fixes and a big change in the way Traveler Server access mail-databases. In 9.0.1.15 IBM introduced a new check if the Traveler server is listed in Trusted Servers (Server Security Tab) to show a warning if not. Now we know what IBM was preparing for. The server now acts as the user instead of the server. That's only possible if listed in Trusted Servers. You still need the Traveler server to be listed in the ACL of the mail databases. Trus
13
Notes Client/Windows Crash with Windows 10 Creators update
Thu, Jun 1st 2017 12:00p   Daniel Nashed
Just got that question today at DNUG. There is an issue with the Notes Client with the current Windows 10 Update - aka Creators Update (Build 1703). According to the responsible person who is at DNUG today, this happens because of changed Windows graphics APIs. IBM is working on a fix which will be available in FP9. FP9 will also have full High Resolution support! We saw a demo with FP9 which really looked great! Here are the two relevant SPRs: SPR LHEYALMCEP : Domino Designer cra
5
Security Bulletin: IBM Domino TLS server Diffie-Hellman key validation vulnerability (CVE-2016-6087)
Thu, Jun 1st 2017 6:27a   Daniel Nashed
There is a vulnerability in the TLS stack which could lead an exploit which could lead a less secure connection. The good news is that the fix is already included in FP8. So you should upgrade to 9.0.1 FP8 if you have a public facing Domino Server with HTTPS. See the details and reference below. -- Daniel A vulnerability in the IBM Domino TLS server's Diffie-Hellman parameter validation could potentially be exploited in a small subgroup attack which could result in a less secure conne
2
Important Security Fix for IMAP
Sat, Apr 22nd 2017 9:13a   Daniel Nashed
In case you are running IMAP on a server that is reachable over the internet you should look into this fix ASAP. It might not be that critical for internal services. See details about this vulnerability here --> http://www.ibm.com/support/docview.wss?uid=swg22002280 All versions of Domino are affected!
1
NIFNSF Supported Maximum Size above 64 GB!
Fri, Apr 21st 2017 9:02p   Daniel Nashed
After getting that question offline and having a discussion on my blog, I checked with IBM if they plan support NIFNSF sizes above 64 GB. Since it is kind of a database container and needs a database handle someone could think that the maximum limit is also 64 GB. That would give us at least 64 GB room for the NIF index -- which would be already a big improvement. But from what I recall from some comments at Connect some years ago the maximum limit was not around 64 GB when they designed it
6
Disclaimer Attachment Issue not yet fixed in IF1
Fri, Apr 14th 2017 6:28p   Daniel Nashed
As Rob Kirkland commented in one of my last blog posted, the fix in IF1 does not solve the iusse. We both checked with IBM and got the reply that the SPR just changes back the default and disables the change introduced in FP8 for Google calender integration. IBM is working on a fix hopefully makes it into FP9. So for now you should keep the notes.ini Parameter MIMEDisclaimersNoEncode=0 disabled. Thanks to Rob to bring this up! -- Daniel TPONAKFJLP After upgrade to FP8, with




Created and Maintained by Yancy Lent - About - Planet Lotus Blog - Advertising - Mobile Edition