This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal


Mar 17, 2015, 5:37 PM
151 Posts

DOMCFG vs IBM security audit

  • Category: Domino Administrator
  • Platform: All Platforms
  • Release: 9.0.1
  • Role: Administrator
  • Tags:
  • Replies: 9

I have a security audit report which states:

3.1.7. Lotus Notes/Domino Anonymous Access to Domino Configuration Database (http-domino-0016)
Description:
The Domino server has been configured to allow anonymous access to the Domino Configuration Database (domcfg.nsf). This
database would allow an attacker to view and potentially modify URL mappings, URL redirection, and other administrative functions of
your Domino site.

I checked.  -Default- and Anonymous both have No Access turned on.  They both do have "Read Public Documents" checked.  If I uncheck this will this do anything drastic?  Like, if Anonymous cannot even get to a log in page to log in how will they be able to log in and become something other than Anonymous?  Or is that not really a concern because it just doesn't work that way.  Like, the configuration is read by LocalDomainServers and the log in screen is then presented by that, (or some such thing)?

Mar 18, 2015, 1:03 PM
151 Posts
Changes sign on screen

We tried it.  It changed our sign in screen. (There's an image posted that only appears if I "edit" this.  Strange.)

 

 

Mar 18, 2015, 1:19 PM
326 Posts
Try it

In domcfg there is a login form.  If your users are already authenticated then there should not be any issues.

Mar 19, 2015, 7:02 PM
151 Posts
???If your users are already authenticated???

How do they get authenticated before they sign on?

Mar 19, 2015, 9:29 PM
326 Posts
Other authentication

Such as webseal.

Mar 19, 2015, 9:30 PM
326 Posts
Other authentication

Such as webseal.


This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal