Domino 修复关于sslv3的“贵宾犬”攻击(POODLE)

7 篇文章 0 订阅
1 篇文章 0 订阅

Technote (FAQ)


Question

How is IBM Domino impacted by the POODLE attack and what is the solution?

Answer

SSLv3 contains a vulnerability that has been referred to as the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack, which is a man-in-the-middle attack affecting Web browsers. Browsers connecting via SSLv3 to Domino servers running HTTP are exposed to the POODLE attack. As browsers turn off SSLv3 and disable downgrading from TLS, they will be unable to connect to Domino over HTTP as Domino servers currently support only SSLv3.
 
IBM has released Domino server Interim Fixes that implement TLS 1.0 with TLS_FALLBACK_SCSV for HTTP to protect against the POODLE attack. Implementing TLS 1.0 for Domino will protect against the POODLE attack and will allow browsers to still connect to Domino after they have been changed to address the POODLE attack.

IBM has provided Interim Fixes for the following Domino releases:


Refer to the following wiki article for more information on protocols:   IBM Domino Interim Fixes to support TLS 1.0 which can be used to prevent the POODLE attack: 

In addition, IBM intends to provide hotfixes for other 8.5.x or 9.x releases on demand. Contact IBM to open a PMR via the   IBM Support Portal  if you require a hotfix for these other releases.  
   
Note:  For any Domino release, a proxy server in front of Domino to handle TLS communication will also address this issue. Select a proxy server that disables SSLv3 or prevents downgrading a TLS communication down to SSLv3. Domino 9.0x for Windows has a proxy solution by including the IBM HTTP Server (IHS) that supports TLS. For more information on this topic, refer to technote 1612316 -   "Is it possible to run IBM HTTP Server (IHS) on the same computer as a Domino server?"


sudo bash -c "export NUI_NOTESDIR=/home/lotus; sh install"



评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值