193 Lotus blogs updated hourly. Who will post next? Home | Blogs | Search | About 
 
Latest 7 Posts
Domino NIFNSF update - you probably don’t want to enable it
Fri, Mar 31st 2017 6
Moving Domino NIF indexes out of the NSF
Wed, Mar 29th 2017 9
2016 the annus horribilis review
Mon, Dec 19th 2016 9
Renewing LetsEncrypt SSL certificates automatically with NginX
Fri, Dec 9th 2016 25
WTF? A new podcast? If you liked This Week In Lotus, you should (at least) like ’WTF Tech’
Mon, Oct 31st 2016 11
Switched to Let’s Encrypt for the blog SSL certificate
Wed, Sep 21st 2016 8
iNotes and IE Standards mode now seems to work in 9.0.1 FP7
Wed, Sep 14th 2016 10
Top 10
Renewing LetsEncrypt SSL certificates automatically with NginX
Fri, Dec 9th 2016 25
How to disable SSLv3 in Domino
Fri, Dec 12th 2014 14
The Domino fixes for POODLE and TLS, you may not be done yet
Tue, Nov 4th 2014 11
WTF? A new podcast? If you liked This Week In Lotus, you should (at least) like ’WTF Tech’
Mon, Oct 31st 2016 11
iNotes and IE Standards mode now seems to work in 9.0.1 FP7
Wed, Sep 14th 2016 10
SOLUTION - Domino Directory Assistance to Active Directory when using SSL DOES NOT break with 9.0.1 FP4
Thu, Jul 16th 2015 9
2016 the annus horribilis review
Mon, Dec 19th 2016 9
Moving Domino NIF indexes out of the NSF
Wed, Mar 29th 2017 9
TLS 1.2 in Domino and the settings I use
Mon, Apr 6th 2015 8
iNotes, IE11 and copy and paste images from the clipboard. How to enable it.
Thu, Jul 14th 2016 8


TLS 1.2 in Domino and the settings I use
Twitter Google+ Facebook LinkedIn Addthis Email Gmail Flipboard Reddit Tumblr WhatsApp StumbleUpon Yammer Evernote Delicious
Darren Duke    

Unless you have been living under a rock somewhere you no doubt know that IBM finally gave use TLS 1.2 for IBM Domino servers. This means that Domino servers can now use SSLv3, TLS 1.0 and TLS 1.2. But it's IT, so just because you can does not mean you should......for example I would suggest most servers (I'll get the outliers further down the page) would probably want SSLv3 disabled. If you have been under a rock, then you need Domino 9.0.1 FP3 IF2 to get this new goodness.

Now this fix is only for Domino 9.0.1 FP3, so now you have a further reason to upgrade to R9 (SHA2 wasn't enough?) and is provided as an IF from fix central. There are other goodies in this release too like additional ciphers and forward secrecy (aka FS). Forward secrecy? Yes...via Wikipedia:

In cryptography, forward secrecy (FS; also known as perfect forward secrecy, or PFS and also key erasure) is a property of key-agreement protocols ensuring that a session key derived from a set of long-term keys cannot be compromised if one of the long-term keys is compromised in the future.

 
However (there's always a however), IBM has chosen to not enable FS by default. This is due to IBM not knowing how crap your servers are, as FS is "resource intensive". If you have crap servers, like a Pentium II running your production environment then FS is not for you (neither is IT for that matter). If you running a pretty recent CPU and plenty of RAM, then you should be OK. And you really want FS.....no really, you do.

So you've decided that your server hardware is up to the task, what do you do to get FS and the promise of Angels singing and the cries of despair from hackers now thwarted? Well you have use Notes.ini settings. See IBM are doing good stuff here....they are giving us new, very important features in fix packs and IF's....the cost of that is there are not yet any UI equivalents in the server and config docs yet. I'm good with that, good on yer IBM.

A few blog posts back, I mentioned the SSLCipherSpec notes.ini setting and it is this setting that once again gets to do all the work. Here's the thing though.....I would change the values in this setting based on the use of the Domino server. I'm not convinced there is "one setting to rule them all yet". I would suggest to you, dear reader, that a Traveler server needs different settings to a iNotes server which is different to a SMTP gateway server. Before that go read Daniel Nashed's excellently detailed post on all the new ciphers then come back here.....

Remember, SSLCipherSpec will be used despite what you have in the server or internet document and it is server wide.

iNotes with XP and IE support
Let's start with iNotes. Some organizations still need XP with IE support. Yes they do. Get over it. This is a conniption free zone with regards to XP. If you do need XP with IE then use TLS 1.0 with Triple DES. Why? Well XP with IE does not support AES, so that cipher is out, RC4 is now frowned upon so that cipher is out, leaving us with 3DES. Given the use of XP with IE support and FS on other platforms, I would suggest this cipher list for an iNotes server and you'll get a A- on SSL Labs:

SSLCipherSpec=9D9C3D3C352F0A3339676B9E9F
DISABLE_SSLV3=1


(Firefox and Chrome on XP do not have the same issues as IE)

iNotes without XP and IE support
Drop the 3DES cipher (0A), but SSLv3 still disabled, and get a A- on SSL Labs:

SSLCipherSpec=9D9C3D3C352F3339676B9E9F
DISABLE_SSLV3=1


Traveler
Same as iNotes with no XP support:

SSLCipherSpec=9D9C3D3C352F3339676B9E9F
DISABLE_SSLV3=1


SMTP Domino Gateway
This is where it gets tricky if you're using STARTTLS (you are using STARTTLS right?) or your iNotes server is also your SMTP gateway.  I would love to be able to say kill off SSLv3 but that's only a decision you can make based on your findings of what breaks when others try to send you TLS messages, but I don't think there is one size fits all here. I would start with this and adjust as necessary (you may need to add RC4 ciphers back in):

SSLCipherSpec=9D9C3D3C352F0A3339676B9E9F
DISABLE_SSLV3=1
SSL_ENABLE_INSECURE_SSLV2_HELLO=1
RouterFallbackNonTLS=1


or (with SSLv3)

SSLCipherSpec=9D9C3D3C352F0A3339676B9E9F
SSL_ENABLE_INSECURE_SSLV2_HELLO=1
RouterFallbackNonTLS=1


or (with SSLv3 and RC4):

SSLCipherSpec=9D9C3D3C352F04050A3339676B9E9F
SSL_ENABLE_INSECURE_SSLV2_HELLO=1
RouterFallbackNonTLS=1


Domino LDAP for LDAPS Dir Sync
If you using any type of LDAP sync with cloud based services for things like Spam protection then this is difficult. You just need to try it and see. For instance SpamHero (which I like a lot...) only uses SSLv2 (yes....T. W. O) last I checked. I did email them for clarification and they did say they are addressing this. I have not checked in a few weeks. So if this is the case, you cannot go above 9.0.1 FP2 for this server. Again, test. adjust, test again, repeat

-------------------------------------

You may be wondering about the "A-" on the SSL Labs test. Well, it's to do with older browser support for FS and IBM choosing to not (yet?) implement ECDHE ciphers. I hope at some they will reconsider this as this does seem to be the current trend in ciphers, and well, we don't want to be left a decade or more behind again, right? I wonder what the (now new) top ranked,, not fixed PMR is now?

So there you have it. TLS 1.2 support in Domino. Not quite as simple as you thought.

References :
TLS/SSL support history of web browser - Wikipedia
Domino TLS Cipher Configuration - IBM




---------------------
http://blog.darrenduke.net/Darren/DDBZ.nsf/dx/tls-1.2-in-domino-and-the-settings-i-use.htm
Apr 06, 2015
9 hits



Recent Blog Posts
6
Domino NIFNSF update - you probably don’t want to enable it
Fri, Mar 31st 2017 2:33p   Darren Duke
In my last post about NIFNSF, Christian Hensler left this comment: I couldn't find anything on the internet, so off I went to the Design Partner forum. Now this is a NDA'd so I'm maybe skirting the rules here, but there is indeed an IBM reproduced issue with performance with NIFNSF. So this AM I did some testing and I was able to reproduce the issue. Base on my testing, on average, the current NIFNSF implementation is twice as slow as non-NIFNSF databases. So you many not want to impl
9
Moving Domino NIF indexes out of the NSF
Wed, Mar 29th 2017 4:16p   Darren Duke
New in Fix Pack Feature Pack 8 is the ability to move the view index files out of the NSF. NIF is the technical term for these index files and end with the file suffix of NDX. Doing this has several advantages including: Make the NSF smaller, so better backup times Help get more out of the 64GB limit....if 6GB of your NSF is NIF index, that's a logt of space Move NIF's to better performing storage, for example SSD's Allows concurrent access to to databases and views, so theoretically better
9
2016 the annus horribilis review
Mon, Dec 19th 2016 2:30p   Darren Duke
Firefox started at 43, ended at 50 (they are slowing down....) Chrome started at 47, ended at 55 (they are speeding up....) IE....you know what? F**k IE. Still using Chrome as my primary browser, although Vivaldi is slowly taking over Didn't go Connect 16. Won't be at Connect 17. I already know what's going to happen....IBM is going to tell you about all the products that they promise * cognitive* is being added too. Like Verse (2 years ago?) and Toscana. "No, really we are" the
25
Renewing LetsEncrypt SSL certificates automatically with NginX
Fri, Dec 9th 2016 4:06p   Darren Duke
A while back I blogged that I switched the SSL on this blog to Let's Encypt, the free SSL provider. I even linked to the Crontab post I used to renew the SSL certificate (they are only good for 90 days, so need to be renewed regularly). Except mine would not renew. Hum.... I eventually got around to looking at this before the certificate ran out on Dec 20th and it turns out I needed to do a few more steps. If you manually run the renew.sh on the server without these additional steps thi
11
WTF? A new podcast? If you liked This Week In Lotus, you should (at least) like ’WTF Tech’
Mon, Oct 31st 2016 10:14a   Darren Duke
A long time ago, before IBM came down like a hammer, there was a podcast. We really enjoyed doing This Week In Lotus, but it became a bit untenable as IBM threatened all kinds of stuff (including revoking *my* Champion status.....) so we stopped. But IBM kept doing "WTF?" kinds of things.....canceling 9.0.2, going to fix packs only, spreading Java 8 out over a year (from now). After getting together at MWLUG, Stuart and I started to reminisce and we started thinking about saddling up again.
8
Switched to Let’s Encrypt for the blog SSL certificate
Wed, Sep 21st 2016 12:25p   Darren Duke
I had switched the blog to SSL a while back (mainly due to Google threatening that non-SSL website will take a hit in searches). At the time Let's Encrypt (the free, yes free, CA SSL issuer) was just getting started and didn't have roots published to most of the browser root stores. Because of this I went with free certificate available from Start SSL. I'm not disappointed with StartSSL, it's just time to try something else when the StartSSL certificate expired. In fact if you need anything
10
iNotes and IE Standards mode now seems to work in 9.0.1 FP7
Wed, Sep 14th 2016 10:28a   Darren Duke
I had praised, then lamented the new-ish iNotes forms templates that allow you do copy and paste images from the clipboard into IE. Well, with FP7 IBM (so far) seem to have addressed the issue search issue that forced me to disable this again. It's now back on for my servers. Let's see how long before I lament this again. It is probably work pointing out that Ulrich Krause is reporting issues with the "normal" iNotes forms9.nsf shipped in FP7. I have not seen the issue he reported in t
8
9.0.1 FP7 and how to enable the new port encryption settings
Wed, Sep 14th 2016 4:59a   Darren Duke
9.0.1 FP7 has shipped. It's not all we hoped (only three new features, and no Java 8) but yet again the Domino security team has added stuff, this time the oft requested update to Notes client port encryption. But (at the time of writing) all the technotes on how to enable this either go to the wrong page (ICCA) or a nice looking, but still pointless 404 page. So how do you enable this? We'll after scouring the design partner forum I found a post from the lovely Dave Kern that outlined thi
4
The last ever (no really....) This Week In Lotus has been posted, number 115
Tue, Sep 6th 2016 9:26a   Darren Duke
Stuart, myself and Jesse Gallagher join for the weekly bi-annual podcast for one last time....listen to it here: http://thisweekinlotus.com/115-doing-a-three-way/ There is also an exciting announcement at the end.....
1
Using Hawthorn gold code? Want IBM to add SQL Server support? Here’s the SPR you’ll want to add your name to....
Mon, Aug 29th 2016 2:09p   Darren Duke
Hawthrorn 2.0, AKA IBM Mail Support for Microsoft Outlook, AKA IMSMO has recently been released. One of the main install differences between GA (2.0) and LA (1.0) code is that GA requires use of IBM DB2 as a state store for the IMSMO Domino server (whereas 1.0 had no such requirement). Most organizations can count on the fingers of no hands how may DB2 servers they have, so you'd expect IBM to support MS SQL server right? You'd be wrong. You along with me are a moron, and no one's ever ask




Created and Maintained by Yancy Lent - About - Planet Lotus Blog - Advertising - Mobile Edition