Skip to main content
This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal

HCL Notes/Domino 8.5 Forum (includes Notes Traveler)

HCL Notes/Domino 8.5 Forum (includes Notes Traveler)

Previous Next

From what I think I understand...

...they are basically two separate issues.

1) POODLE has to do with SSLv3 fallback, and is independent of the certificate strength. The IF and future fixpacks for 8.5.x disable SSLv2, and prevent the SSLv3 fallback, and will allow for SSLv3 to be disabled completely.

http://www-01.ibm.com/support/docview.wss?uid=swg21687167

http://www-10.lotus.com/ldd/dominowiki.nsf/dx/IBM_Domino_TLS_1.0

Certificate strength - Notes/Domino 8.5.x and below only support SHA-1 certificates. The only way to run SHA-2 certificates or greater will be to upgrade to 9.0.1.

http://www-01.ibm.com/support/docview.wss?uid=swg21418982

Certificate authorities as well as browsers are removing support for SHA-1 - I think most certificate authorities might still be willing to issue SHA-1 'short term' certificates - mine will thru EOY 2015 - but it seems that most browser vendors won't support SHA-1 'soon'.

https://www.cscglobal.com/cscglobal/pdfs/Digital%20Certificates%20Industry%20Changes.pdf

(edit) So, yes, It appears that by 2017 user won't be able to connect to an 8.5.x server using https.

In addition to all that, it seems that various ciphers are suspect and some browsers may drop support for those as well. See this discussion:
http://www-10.lotus.com/ldd/ndseforum.nsf/xpTopicThread.xsp?documentId=D804457CF4E7894B85257DA100787ABA

So... Short term, you should be OK with 8.5.x as far as POODLE, etc goes, but long term to get SHA-2 support you'll need to upgrade to 9.0.1FP2IF1 or greater. Additionally, I'd suspect the new ciphers , 'if there will be any', would also be available only for the 9 code stream.


Feedback response number WEBB9SLMNJ created by ~Sigmund Dworelitnivu on 01/09/2015

Problems with SSL cert install - 'c... (~Martha Lopjipy... 9.Jan.15)
. . Have Thawte re-issue the certificat... (~Sigmund Dworel... 9.Jan.15)
. . . . Follow on (~Martha Lopjipy... 9.Jan.15)
. . . . . . From what I think I understand... (~Sigmund Dworel... 9.Jan.15)
. . . . . . . . I hate admin work... (~Martha Lopjipy... 9.Jan.15)
. . . . . . . . . . No problem! (~Sigmund Dworel... 9.Jan.15)
. . . . . . . . . . . . Dev by choice, admin, just because (~Martha Lopjipy... 13.Jan.15)
. . . . . . . . . . . . . . Reverse Proxy (~Carol Asafreek... 14.Jan.15)
. . . . . . . . . . . . . . . . Not likely (~Martha Lopjipy... 19.Jan.15)
. . . . . . . . . . . . . . . . . . Have you ruled out upgrading? (~Tanita Desweve... 21.Jan.15)
. . . . . . . . . . . . . . . . Agreed, although... (~Fred Asatumibu... 14.Jan.15)
. . . . . . . . . . . . . . . . . . You are right (~Carol Asafreek... 14.Jan.15)
. . . . . . . . . . . . . . . . . . . . Reverse proxy (~Fred Asatumibu... 15.Jan.15)
. . . . . . . . . . . . . . . . . . . . . . Nice (~Carol Asafreek... 15.Jan.15)
. . . . . . . . . . . . . . Sounds familiar (~Fred Asatumibu... 13.Jan.15)




Printer-friendly

Search this forum

Member Tools


RSS Feeds

 RSS feedsRSS
All forum posts RSS
All main topics RSS