This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal


Jan 9, 2018, 3:25 PM
15 Posts

Return Of Bleichenbacher's Oracle Threat (ROBOT) Information Disclosure

  • Category: Domino Server
  • Platform: Windows
  • Release: 9.0.1
  • Role: Administrator
  • Tags:
  • Replies: 5

My Domino servers have the security finding:
 "Return Of Bleichenbacher's Oracle Threat (ROBOT) Information Disclosure"
How am I supposed to fix this? Does IBM have a published fix? If not,
does anyone know when a fix will be forthcoming?
Thanks.

Jan 10, 2018, 11:05 AM
55 Posts
Me too...

We have just upgraded customer servers to the latest 9.0.1FP9 and are also getting these alerts when testing the SSL config via Qualys Labs.

Anyone from IBM care to advise how to mitigate/fix this?

Jan 10, 2018, 12:15 PM
55 Posts
Workaround...

By only enabling ECDHE & DHE cyphers this appears to have worked around the issue and I no longer get the ROBOT errors.

FYI this is the notes.ini I used: SSLCipherSpec=C030009FC02F009EC028006BC0140039C0270067C013

Jan 10, 2018, 3:17 PM
15 Posts
Work around works for me

Thanks. This work around worked. My SSLCipherSpec looks like this:  SSLCipherSpec=C030009FC028006BC0140039

I only enabled the 256 bit ciphers.

Jan 15, 2018, 11:00 AM
90 Posts
Here is the list I used
SSLCipherSpec=C030009FC02F009EC028006BC0270067C014

Per SSL Labs that allows support for IE 8-10.

Howard


This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal