198 Lotus blogs updated hourly. Who will post next? Home | Blogs | Search | About 
 
Latest 7 Posts
Did you know that we are experts in Security Solutions
Wed, Oct 11th 2017 63
DomainPatrol Social with support for IBM Connections 6
Thu, Sep 28th 2017 4
Join Tobias Gruvfält at Social Connections in Vienna
Mon, Sep 18th 2017 4
Join Tobias Gruvfält at Social Connections in Vienna
Mon, Sep 18th 2017 2
Infoware is Gold sponsor at Social Connections in Vienna
Fri, Sep 15th 2017 2
Infoware is Gold sponsor at Social Connections in Vienna
Wed, Sep 13th 2017 2
Infoware’s Ulf Stider is speaking at the Social Connections conference in Chicago
Tue, May 23rd 2017 4
Top 10
Did you know that we are experts in Security Solutions
Wed, Oct 11th 2017 63
DomainPatrol Social 10 – beyond Merge Communities
Mon, Oct 3rd 2016 9
Phonegap / Cordova 3.6.3 & CDVPlugin class CDVNotification (pluginName: Notification) does not exist
Tue, Sep 23rd 2014 8
Free your mind – Infoware Innovation and Idea Jam is here!
Tue, May 19th 2015 8
Strategic Alliance between Infoware and panagenda
Thu, Jun 2nd 2016 8
IBM Connections experts available for you
Wed, Mar 30th 2016 7
DomainPatrol Social 11 introducing user roles and IBM Connections 5.5 CR2
Mon, Dec 5th 2016 7
Dictionaries in IBM Notes. Changing and Signing with JDK 1.8, no questions asked
Fri, Mar 10th 2017 7
Merry Christmas & Happy New Year from Infoware
Fri, Dec 18th 2015 6
Fantastic Social Connections 10 in Toronto
Fri, Jun 17th 2016 6


Dictionaries in IBM Notes. Changing and Signing with JDK 1.8, no questions asked
Twitter Google+ Facebook LinkedIn Addthis Email Gmail Flipboard Reddit Tumblr WhatsApp StumbleUpon Yammer Evernote Delicious
Mats    

Case:
Dictionaries where missing from client installation on Windows machines.
Client is multi user and users are not allowed to write in Program Directories (non admin on their PCs).
Client is IBM Notes 9.0.1FP6, because this is the one rolled out to end users.
This means that nothing can be installed via Widgets in frameworkrpc or frameworkshared because both are under Program Directory.
Objective is to provide all of the dictionaries to the end users to choose from from the Widgets catalog. Installation should progress without any questions asked.

Description:
I downloaded the Dictionaries provided by IBM (Notes_XTAF_Dictionaries_V9.0_Win_ML.zip).
For a full description of this package, please read Tomas Hampels blog at
(https://blog.thomashampel.com/blog/tomcat2000.nsf/dx/deploying-xtaf-dictionaries-as-widgets.htm

The problem I got was that the Feature jar files configured to install in frameworkrpc which is fine if you include them during installation of the original package running with administrative rights on the computer.

Only way in my scenario was to make sure that the installation was made in a user context meaning Dataworkspaceapplications

Solution:
Change configuration of the Feature jar to make sure that the installation is done in a user context.

Unpacking the jar file in the features directory of any given dictionary reveals that the feature.xml file contains <feature colocation-affinity="com.ibm.rcp.platform.feature"
this needs to be changed to this <feature colocation-affinity="com.ibm.rcp.site.anchor.user.feature" to make sure that installation will go to Dataworkspaceapplications where the end user is allowed to write.

To unpack and repack i use PeaZip (http://www.peazip.org/peazip-64bit.html and as an Editor I use Notepad++ (https://notepad-plus-plus.org/download/v7.3.3.html

Explanation of the different options could be found here:
https://www.ibm.com/support/knowledgecenter/en//SSVHEW_6.2.0/com.ibm.rcp.tools.doc.admin/controllingfeatureinstallocation.html
http://www-01.ibm.com/support/docview.wss?uid=swg21497657
http://www-01.ibm.com/support/docview.wss?uid=swg21440976

Also when doing this it will break the signatures and this means that a resigning (after repackage) is necessary for security reasons (you should not allow anything that you have not trusted)
If you want to include your own signed jars files during installation of the client, this can be done following this instruction (http://www-01.ibm.com/support/docview.wss?uid=swg21305165)
You could also use iKeyman to do this if You prefer.

If you look at Tomas Hampels blog above You will find that there are a lot of files that needs to be changed and signed before importing to an update site.

Changing:
In every features directory in every updateSite_xx directory the file feature.xml needs to be changed according to the above solution.
IMPORTANT!!!
Also, preparing for signing, 3 files need to be deleted from a subdirectory called META-INF also in the features catalog:
IBM_WPLC.RSA
IBM_WPLC.SF
MANIFEST.MF
IMPORTANT!!!

Preparing:
Repack all files in each Directory e.g. com.ibm.langware.v5.dic.af_ZA.feature_7.2.0.201111100545 to com.ibm.langware.v5.dic.af_ZA.feature_7.2.0.201111100545.zip
Move (cut) the zip file to where the original jar file is located rename the original jar file with an extension .org instead of .jar end the rename the newly moved .zip file to .jar
A features catalog could then look like this:
Capture

Signing:
To sign I downloaded JDK 1.8 from
(http://www.oracle.com/technetwork/java/javase/downloads/jdk8-downloads-2133151.html Windows x64 because I am using W10 64-bit.

IMPORTANT!!!
Only sing jar files that you have made changes to. The others are already signed with valid signatures.
Only sign 1 time with 1 signature for each jar file. Signing a second time could cause unexpected results.
IMPORTANT!!!

First I examined the file that was signed by IBM, this is now <filename>.org if the instructions where followed.
C:Program FilesJavajdk1.8.0_121bin>
jarsigner -verify -verbose "C:updateSite_affeaturescom.ibm.langware.v5.dic.af_ZA.feature_7.2.0.201111100545.org"

I got:
– Signed by "CN=International Business Machines Corporation, OU=Lotus Software Group, OU=Digital ID Class 3 – Java Object Signing, O=International Business Machines Corporation, L=Littleton, ST=Massachusetts, C=US"
    Digest algorithm: SHA1
    Signature algorithm: MD5withRSA, 2048-bit key
  Timestamped by "CN=GeoTrust Timestamping Signer 1, O=GeoTrust Inc, C=US" on lö feb 02 04:31:44 UTC 2013
    Timestamp digest algorithm: SHA-1
    Timestamp signature algorithm: SHA1withRSA, 1024-bit key

jar verified.

This meant that I need to sign with MD5withRSA and also SHA-1 where needed.
I tried all of the possible combinations of signing and digest and did the provisioning to the IBM Notes Client for all the different cases (puh this was hard and took a lot of time!) just to make sure.
I found only 1 configuration that worked all of the times.

IMPORTANT!!!
To sign You must first create a signer and also You need to import the certificate of the signer and crosscertify it with Your Notescertificate and push that crosscertificate to the client thru your security policy.
This done is done in Your Domino Directory of the server.
Signing the jar file with this signature is the trusted to be installed on the client.
IMPORTANT!!!

Inspired by Tomas Hampel (again) and the blog entry (https://blog.thomashampel.com/blog/tomcat2000.nsf/dx/untitled.htm?opendocument&comments). I decided to make my own script to help me out with this task.

Script Solution:
I decided to make 2 types of script, 1 for creating the necessary JKS file used for signing and 1 for the actual signing.
Both solutions consists of a command file an a property file containing values needed for the execution.

Code and samples will be provided here for download.Cool_Signing

Keytool:
Signing_mykeytool.cmd Cool_Signer.keytool
in the sample provided and this will create a JKS file and a CER file in the C:temp directory.

To customize for your own needs you can creating you own .keytool file using Cool_Signer.keytool as a template. Read the included Readme.txt file for explanation.

IMPORTANT!!!
You must change/customize this if You want to use this in your own environment, because sample provided here is not intended for other purposes than demonstrating the code.
IMPORTANT!!!

Jarsigner:
Signing_myjarsigner.cmd Cool_Signing_with_XTAF_MD5.jarsigner
in the sample provided will sign all jar files that ends with *.feature_7.2.0.201111100545.jar from the catalog C:Notes_XTAF_Dictionaries_V9.0_Win_ML and down.
It also contains the parameters that where tested to work with these features. I will recommend You to use these for the Dictionaries provided by IBM.

To customize for your own needs you can creating you own .jarsigner file using Cool_Signing_with_XTAF_MD5.jarsigner as a template. Read the included Readme.txt file for explanation.

Conclusion:
Changing and Signing is hard work but script at least provides you with organising your stuff and easy the burden of signing.

 



---------------------
http://www.infoware.eu/dictionaries-in-ibm-notes-changing-and-signing-with-jdk-1-8-no-questions-asked
Mar 10, 2017
8 hits



Recent Blog Posts
63
Did you know that we are experts in Security Solutions
Wed, Oct 11th 2017 8:12a   Maria Nordin
Together with our partner SecureDevice, who is leading in IT security in the Nordic region, we offer services and tools to help you protect your business. Today, it is unavoidable that business critical infrastructure is exposed to attacks. You are most certainly attacked daily and probably without knowing it. The solution is to make the attacks visible to have a chance to protect yourself from intrusion and theft of business-critical business information. What does the new data protection regul
4
DomainPatrol Social with support for IBM Connections 6
Thu, Sep 28th 2017 8:42a   Maria Nordin
You know IBM Connections right? What you might not know is, that we make it even more powerful, useful, better, tidier with DomainPatrol Social And now it’s soon available for IBM Connections 6. We can in 4 clicks merge two whole Communities. With everything in it! Neat and tidy. With the same function you can move and merge almost all content, like Wikis, Files, Communities, Activities, Users etc. All solving complex questions and issues from users and admins. In our session we show real
4
Join Tobias Gruvfält at Social Connections in Vienna
Mon, Sep 18th 2017 1:49p   Maria Nordin
We are presenting an inspiring customer case on how to achieve adoption without working with adoption. Join our customer story session at the IBM Collaboration Conference Social Connections 16-17 October in Vienna. Infoware's Tobias Gruvf&auml;lt talks about how SEB can see trends and analyze the user behavior in IBM Connections beyond what is in Metrics reports. Top management at SEB use IBM Connections for information sharing via blogs and bank office branches use it for knowled
2
Join Tobias Gruvfält at Social Connections in Vienna
Mon, Sep 18th 2017 1:38p   Maria Nordin
We are presenting an inspiring customer case on how to achieve adoption without working with adoption. Join our customer story session at the IBM Collaboration Conference Social Connections 16-17 October in Vienna. Infoware’s Tobias Gruvfält talks about how SEB can see trends and analyze the user behavior in IBM Connections beyond what is in Metrics reports.  Top management at SEB use IBM Connections for information sharing via blogs and bank office branches use it for knowledge sharing.
2
Infoware is Gold sponsor at Social Connections in Vienna
Fri, Sep 15th 2017 1:50p   Maria Nordin
When Social Connections comes to Vienna it was an easy choice for us at Infoware to be there too. Not only will we have a fresh release of DomainPatrol Social, the administration tool for IBM Connections, to show in our exhibitors booth. But we also want to take the opportunity to see our customers and network with colleagues from our partners and friends. We have worked with IBM collaboration solutions for a long time, and with this new path IBM is taking by implementing what they call the Pi
2
Infoware is Gold sponsor at Social Connections in Vienna
Wed, Sep 13th 2017 4:08p   Maria Nordin
When Social Connections comes to Vienna it was an easy choice for us at Infoware to be there too. Not only will we have a fresh release of DomainPatrol Social, the administration tool for IBM Connections, to show in our exhibitors booth. But we also want to take the opportunity to see our customers and network with colleagues from our partners and friends. We have worked with IBM collaboration solutions for a long time, and with this new path IBM is taking by implementing what they call the P
4
Infoware’s Ulf Stider is speaking at the Social Connections conference in Chicago
Tue, May 23rd 2017 3:48p   Maria Enderstam
We are happy to announce we are going to Chicago and conference Social Connections. The conference which is all about IBM Connections and collaboration solutions. The event include separate tracks with keynote sessions, case studies, administration, future of work, development, and includes speakers from IBM, business partners and customers. To top it off a Gala night with extra specials. Register here and take part in a 2 day conference networking with others in the same field "Full throt
1
Learn how to optimize the value of your IBM licenses by attending our seminar on May 4, 2017 in Stockholm
Tue, Apr 11th 2017 10:59a   Maria Enderstam
Does your company own IBM licenses? Are you certain that your company is proberly licensed? Do you as many others feel that IBM licensing can be a difficult and complex to learn? Do you want to lower your costs for IBM licenses? We invite you to attend our seminar with breakfast on May 4th 2017 at the Infoware office in Stockholm, where we will talk about everything there is to know about the various license forms IBM has to offer. Infoware has over 20 years of experience when it comes to IBM
4
Summer is coming, but relax, Infoware can take care of your IBM platform while you are away
Fri, Mar 31st 2017 11:18a   Maria Enderstam
Are you scratching your head thinking of who will take care of your IBM platform during the summer vacation period? Planning for the summer can be stressful, especially as you want to give your staff the vacation they need but also maintain a high quality in service acound your IBM platform. Be calm! Infoware offers you rescue and control. All summer long! Infoware's team of experienced IBM experts is your service every day. Many organizatiosn have troubles on how to solve their sta
8
Dictionaries in IBM Notes. Changing and Signing with JDK 1.8, no questions asked
Fri, Mar 10th 2017 4:10p   Mats
Case: Dictionaries where missing from client installation on Windows machines. Client is multi user and users are not allowed to write in Program Directories (non admin on their PCs). Client is IBM Notes 9.0.1FP6, because this is the one rolled out to end users. This means that nothing can be installed via Widgets in frameworkrpc or frameworkshared because both are under Program Directory. Objective is to provide all of the dictionaries to the end users to choose from from the Widgets




Created and Maintained by Yancy Lent - About - Planet Lotus Blog - Advertising - Mobile Edition