264 Lotus blogs updated hourly. Who will post next? Home | Blogs | Search | About 
 
Latest 7 Posts
Do you subscribe to the IBM daily product update newletter? Part deux - or why renaming your products sucks
Fri, Apr 10th 2015 23
TLS 1.2 in Domino and the settings I use
Mon, Apr 6th 2015 40
Domino and SSL ciphers. The server document may not be doing what we expect it to do
Tue, Feb 3rd 2015 15
ConnectED-sphere sudo review
Mon, Feb 2nd 2015 11
New-ish Domino Configuration Tuner (DCT) rules are available
Mon, Feb 2nd 2015 13
If you are using my Reverse Proxy, please change the SSH host key
Wed, Jan 14th 2015 15
Using IBM Lotus Traveler with a proxy....food for thought before you do this
Tue, Dec 16th 2014 12
Top 10
TLS 1.2 in Domino and the settings I use
Mon, Apr 6th 2015 40
How to disable SSLv3 in Domino
Fri, Dec 12th 2014 39
Do you subscribe to the IBM daily product update newletter? Part deux - or why renaming your products sucks
Fri, Apr 10th 2015 23
iNotes and IE11 - yes it is supported
Tue, Mar 18th 2014 20
STARTTLS and POODLE is this really an issue?
Thu, Oct 23rd 2014 18
The Domino fixes for POODLE and TLS, you may not be done yet
Tue, Nov 4th 2014 17
So Domino and SHA2.....There’s a SPR for that
Wed, Aug 20th 2014 16
POODLE TLS - The POODLE Strikes Back - change your settings now....
Tue, Dec 9th 2014 15
If you are using my Reverse Proxy, please change the SSH host key
Wed, Jan 14th 2015 15
Domino and SSL ciphers. The server document may not be doing what we expect it to do
Tue, Feb 3rd 2015 15




Recent Blog Posts
23
Do you subscribe to the IBM daily product update newletter? Part deux - or why renaming your products sucks
Fri, Apr 10th 2015 11:00a   Darren Duke
A few years ago I wrote about how to subscribe to the daily IBM product update newsletter. A few days ago some one asks me if I still used this service. I thought I did, but on recollection I hadn't gotten an email from them in ages (or "yonks" for a more technical definition). At first I thought it was getting stuck in spam.....nope. Hummm. OK Let me log in a see.... I had no subscriptions listed. None. Nada. Ziltch. WTF? So I started adding in my subscriptions again and realized that
40
TLS 1.2 in Domino and the settings I use
Mon, Apr 6th 2015 8:20a   Darren Duke
Unless you have been living under a rock somewhere you no doubt know that IBM finally gave use TLS 1.2 for IBM Domino servers. This means that Domino servers can now use SSLv3, TLS 1.0 and TLS 1.2. But it's IT, so just because you can does not mean you should......for example I would suggest most servers (I'll get the outliers further down the page) would probably want SSLv3 disabled. If you have been under a rock, then you need Domino 9.0.1 FP3 IF2 to get this new goodness. Now this fix is
15
Domino and SSL ciphers. The server document may not be doing what we expect it to do
Tue, Feb 3rd 2015 8:52a   Darren Duke
While sat in Daniel Nashed and David Kern's excellent Domino Security session at Connect, there was a comment and slide that made me tweet this: Domino SSL ciphers set in the Domino Server document are ONLY applicable to HTTP. Not SMTP, LDAP, et al.... Doh. You can set with note.ini— Darren Duke (@darrenduke) January 27, 2015 Now, I'm back in the office it's time to address this. So based on that session it seems as if LDAP, SMTP, DIIOP, POP3 and IMAP (and Remote debug monit
11
ConnectED-sphere sudo review
Mon, Feb 2nd 2015 2:43p   Darren Duke
I was fully expecting to write a "what a train wreck" review before I went. I was not expecting to say I had a metric shit ton of fun. But I did. And based on other posts I've perused it seems almost everyone else did. There are far more eloquent reviews elsewhere, so this will be bare bones. First the "ups", in no particular order: Much, much improved OGS. Flow, demos, people who care.....And a quintet, who doesn't like quintets? It doesn't seem to matter how many people don't turn
13
New-ish Domino Configuration Tuner (DCT) rules are available
Mon, Feb 2nd 2015 9:16a   Darren Duke
Somehow I missed this, so I'm guessing some of you did too....New rules dated 10/16/2014. Thank you IBM. Woohoo! Indeed!!
15
If you are using my Reverse Proxy, please change the SSH host key
Wed, Jan 14th 2015 7:10a   Darren Duke
Well, technically this is for any Linux VM appliance you download, not just my reverse proxy.... Anyway, every Linux host should have it's own unique host SSH key to ensure security and authenticity of the server you are connecting to. When you create a server from an OVF that doesn't happen automatically. In fact you get the SSH host key that is on the OVA at time of creation (in this case mine).....potentially opening you up to man in the middle attacks (potentially.....although unlikely
12
Using IBM Lotus Traveler with a proxy....food for thought before you do this
Tue, Dec 16th 2014 6:11a   Darren Duke
Over that past few weeks I've been banging my head against the wall trying to figure out why a Traveler server that has been relocated behind a proxy would not work (it was a standalone server that was working fine before it was moved behind the proxy). Everything seemed fine, except one couldn't get to the Traveler log on page and/or add devices to the servers. Existing users worked flawlessly. Needless to say this was extremely aggravating. I'd install another, new Traveler server and put i
39
How to disable SSLv3 in Domino
Fri, Dec 12th 2014 6:01a   Darren Duke
In my POODLE TLS post from a few days back, there was a comment asking how to fully disabling SSLv3 in Domino. You'll notice in the comments I mention that there is a way but at the time it was under NDA. Well, apparently not anymore.... Now, fair warning this may not yet be supported by IBM so if you choose to do this, you do it at your own risk (while under NDA on this, it was stated that is unsupported so YMMV). According to this post on the Domino wiki, you can use this server notes
9
Tis coming to the close of 2014, so it must be time for the snarky review
Wed, Dec 10th 2014 1:27p   Darren Duke
Firefox, started 27, ended 34 Chrome started 32, ended 39 IE....11 and 11 IBM finally realized the 2015 plan was imploding. Except they "realized" this in 2014, so the immense damage of the plan has already been done. Oh, and I doubt they will stop the culling. Talking of IBM....support. Oh, how I used to use thee as a unique selling point. Now? I routinely have 14+ day periods when the assignee of the PMR doesn't respond to multiple emails. At first I thought this was just me
15
POODLE TLS - The POODLE Strikes Back - change your settings now....
Tue, Dec 9th 2014 8:11a   Darren Duke
After a brief chat in the Lotus Notes Skype chat with Jim Casle, Declan Lynch, Steve Pridemore and Frederick Norling it has become apparent that Domino maybe susceptible to the newly discovered POODLE TLS issue (POODLE 2.0 if you will). You can read about the new issues here and here. Go scan your servers at SSL Labs. Anyway, provided you are using 9.0.1 FP IF1 (the TLS fix that IBM provided a while back) the apparent Domino fix is to disable AES and 3DES ciphers and run with only RC4:




Created and Maintained by Yancy Lent - About - Planet Lotus Blog - Advertising - Mobile Edition