This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal


Jul 26, 2016, 2:14 AM
12 Posts

Help: 3rd Party CA for Domino and IOS Devices

  • Category: Domino Server
  • Platform: Windows
  • Release: 9.0
  • Role: Administrator
  • Tags: Domino,Traveler,Notes,IOS,Verse
  • Replies: 3

Hi Admins,

 

As per checking, kyrtool only supports Domino 9.0.1 and onward.

But I have tried the tool on our environment, we are using Domino 9.0, Traveler 9 and Sametime Standard 9. I needed to deploy and utilize Sametime Standard licensing so I am stuck with 9.0 versions.

I was able to request for an SSL trial from GeoTrust and was able to create a certificate (root, intermediate, signed certificate) still there are problems encountered.

 

I have also encountered subsequent crash for kyrtool during checking and verification of certificates using kyrtool. [kyrtool =d:\domino\notes.ini show certs -k d:\domino\data\mykeyring2.kyr PANIC: Lookup Handle: handle out of range].

 

But using this command, kyrtool =c:\lotus\notes\notes.ini verify c:\lotus\notes\data\ssl\server.txt there are no errors founds.

 

I am hoping anyone who were able to deploy SSL with 3rd Party CA (trial if possible) on Domino 9.0. I am currently on testing with IOS devices and IBM Traveler / Verse.

I am also trying to trace and debug all SSL logs and events during the handshake of server and client. But I would like also to clarify if kyrtool can be used on Domino 9.0.0?



Hoping for your consideration.

 

Thank you.

 

Best regards,
Mike

 

Aug 1, 2016, 1:35 PM
11 Posts
Kyrtool

Hi Mike,

In relation to the crash, can you confirm that you are using a 9.0 IF6 or 9.0.1 FP2 IF1 version of the Notes Administration client to run the kyrtool. I have seen recommendations to upgrade to 9.0.1 FP3 IF4
http://www-10.lotus.com/ldd/ndseforum.nsf/xpTopicThread.xsp?documentId=DB78CFCC736BFD3785257E3F004531E7

Also what version of Domino are you running exactly as SHA-2 certificates should only be created for specific versions of Domino 9.0 but will only use SSLv3 unless you are running 9.0 IF6 while will use TLSv1.0

While the kyrtool can create SHA-1 certificates however due to the cessation of SHA-1 support you may not be able to purchase such as certificate from a third party supplier.

Any major issues I'd suggest opening a PMR with Domino support.

 

 

Aug 18, 2016, 9:05 AM
12 Posts
Re: Kyrtool

The crash was resolved with proper Notes \ Domino version 9.0.1.

I was able to simulate and play around with Domino cipher and notes.ini settings and it is now working properly. I have also updated the Domino server to 9.0.1 and apply patches. But as per checking with https://www.ssllabs.com/ there are still vulnerabilities, it showed that SSLv3 is still working interchangeability that can be exploited if used. I have already updated the latest fixes and added some settings on notes.ini still shows the same case.

Thanks in advance for helping me.

Aug 18, 2016, 12:53 PM
328 Posts
DISABLE_SSLV3=1

Make sure that you have the Notes.ini paramater 'DISABLE_SSLV3=1' set - it disables SSLv3 - but that parm isn't supported if you're running a version of Domino below 9.0.1 FP3.


This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal