This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal


Nov 24, 2014, 1:45 PM
51 Posts

Domino 9.0.1.2 with IF (No TLS 1.2?)

  • Category: Security
  • Platform: All Platforms
  • Release: 9.0.1
  • Role: Administrator
  • Tags:
  • Replies: 6

I noticed that this site (www-10.lotus.com) shows TLS 1.2 and 256-bit encryption signature. My server, now using a SHA-2 certificate, still says TLS 1.0. Also, SSL 3.0 is still enabled and some security sites are recommending disabling. I only have a single V3 cipher enabled (AES 256). Should I (if so, how do I?) disabled SSL 3.0 support totally? Since modern browsers support TLS, I don't see why not. Is there a notes.ini setting and/or other configuration change needed? I disabled SSL renegotiation. At this stage, I just want to see better scores. I'm still sitting at a "C" using Qualys SSL Labs site (excellent tool -w- detailed output).

***Also, just curious, why does the KYRTOOL need access to the notes.ini? Does it make an API call or check for a notes.ini setting?

Nov 24, 2014, 2:03 PM
27 Posts
Answer regarding TLS 1.2

The www-10.lotus.com environment uses a network manager that supports TLS 1.2, so that is why you're seeing it. The TLS support in IF1 for native Domino is currently TLS 1.0.
 

Nov 24, 2014, 3:51 PM
51 Posts
Domino 9.0.1.2 with IF (No TLS 1.2?) - Disappointing IBM

Hello,

Thanks for your response. Am I the only person severely frustrated/disappointed with the lack of transport security in Domino? TLS 1.2 was released in 2008 and IBM just scrambled to add TLS 1.0, the initial release from 1999, because of Google's <et al.> pressure tactics!?! Who's defining standards these days? I expect IBM to be at the forefront. This is incredibly disappointing. Have a great day.

***Why does the network manager support TLS 1.2 and not Domino? It sounds like a lack of support for the product line.

Regards,
Michael

Nov 24, 2014, 6:30 PM
328 Posts
No, you're not the only disappointed user

...and I'm equally (or more) disappointed in the instructions to use the darn fix(es)! This is terrible!

http://www-10.lotus.com/ldd/dominowiki.nsf/dx/3rd_Party_SHA-2_with_OpenSSL_and_kyrtool

I know I must be spoiled that the old method was fairly easy, but (and I'm sure like many other admins), I only have to request certificates every couple years - this method is terrible! What about an actual workable solution? I don't have a linux box laying around to work with - Running thru this process I have know Idea what I'll end up with!

Nov 24, 2014, 11:07 PM
94 Posts
You don't need a linux box -- OpenSSL is cross-platform and kyrtool is available on Window...
Nov 25, 2014, 2:50 PM
328 Posts
Thanks, Dave!

First of all, thanks for updating http://www-10.lotus.com/ldd/dominowiki.nsf/dx/3rd_Party_SHA-2_with_OpenSSL_and_kyrtool !

I understand that OpenSSL _IS_ available for Windows; my frustration lies in the fact the the only 'documented' procedure now for obtaining certificates is an example of using a linux tool, there are no examples of using the Windows version, which has its own idiosyncrasies.

I feel a little more confident after reading Michael's notes, and hope to submit my certificate requests today, and will report back..

Thanks!

Nov 24, 2014, 10:16 PM
43 Posts
TLS
I know we are late to TLS. It does take time to code. We had TLS 1.0 code further along and decided it was appropriate to deliver that to get something out quickly. TLS 1.2, suffice to say we are sizing and working on it but SEC Regulations prohibit us from making forward looking statements to the level of detail that you would want. All I can say is watch this space technote and focus on this point:

IBM is committed to delivering a secure and reliable offering. It is our intention to continue to address general enhancements including security updates as is our general practice in our product development cycles or in our ongoing subscription updates.

This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal