TLS 1.2 support in Domino 9.0.1 Fix Pack 3 Interim Fix 2

by Volker Weber

Domino 9.0.1FP3IF2 — that's short for "Domino 9.0.1 Fix Pack 3 Interim Fix 2 (released March 27, 2015)" — introduces TLS 1.2 support. That is both important and overdue. Installing the Interim Fix is not enough. Daniel explains what settings need to be changed. It's complicated.

Comments

Extremely overdue.
Looks like IBM finally woke up.

Manfred Wiktorin, 2015-03-31

And the IHS support in Domino 9 is called deprecated now. Fun for all those customers who recently migrated their SSL certificates from Domino kyr to IHS kdb and now can do the same in the opposite direction.

Oliver Regelmann, 2015-03-31

IHS is a bag of hurt. So i doubt that many customers would miss it.

Manfred Wiktorin, 2015-03-31

for people not in the know: nginx is a free and excellent alternative to IHS available for quite some time. It also does a lot more, and frees up Domino resources.

Google nginx and Domino to find the articles about how to set it up.

Lars Berntrop-Bos, 2015-04-01

Well it's not like Microsoft Exchange did a lot better: just a few days ago Cumulative Update 8 finally removed a hard-coded restriction that forced unsecure (SSLv3 or TLS1.0) email transportation...

http://support.microsoft.com/en-us/kb/3045301 (SMTP is not transported over TLS 1.1 or TLS 1.2 protocol in an Exchange Server 2013 environment)

Ralf ter Veer, 2015-04-01

Broken link. The link to Daniel's blog post has a typo in the URL. "fp2" instead of "fp3". Once I changed that, it worked.

Scott Vrusho, 2015-04-01

Thanks, Scott. Fixed. As you can imagine, I don't type URLs but copy them. Looks like Daniel changed a typo in the header which then changed the URL. All good now.

Volker Weber, 2015-04-01

Sorry I tried to just change the typo in the text but it also changed the link ...
There are more postings about the fixes and there are also new Wiki entries posted on the IBM Domino Wiki. I have updated my posts with that info as well.

And there is a presentation I did at Engage conference with some more details.

@Lars, not all options of the nginx solution are free. But it is a good product.
If you are running SMTP TLS Extension you might not have a proxy in front of your server and need the new TLS fixes.


-- Daniel

Daniel Nashed, 2015-04-02

Recent comments

Volker Weber on Heading to the cardiologist :: Reddit at 19:26
Mariano Kamp on Heading to the cardiologist :: Reddit at 19:25
Volker Weber on Heading to the cardiologist :: Reddit at 19:15
Joel Demay on Heading to the cardiologist :: Reddit at 19:07
Henning Heinz on IBM verkauft Notes, Domino, Sametime, Connections, Portal und weitere Produkte at 12:03
Hubert Stettner on Heading to the cardiologist :: Reddit at 11:08
Felix Binsack on IBM verkauft Notes, Domino, Sametime, Connections, Portal und weitere Produkte at 09:51
Bernd Vellguth on IBM verkauft Notes, Domino, Sametime, Connections, Portal und weitere Produkte at 21:46
Jan Tietze on Echo Spot ist wieder online at 19:36
Gerhard Henzler on I could be in this video at 18:44
Volker Weber on IBM verkauft Notes, Domino, Sametime, Connections, Portal und weitere Produkte at 18:35
Bernd Vellguth on IBM verkauft Notes, Domino, Sametime, Connections, Portal und weitere Produkte at 18:34
Jens Wagner on I could be in this video at 13:46
Volker Weber on I could be in this video at 13:30
Volker Weber on IBM verkauft Notes, Domino, Sametime, Connections, Portal und weitere Produkte at 13:16
Henning Heinz on IBM verkauft Notes, Domino, Sametime, Connections, Portal und weitere Produkte at 12:56
Volker Weber on IBM verkauft Notes, Domino, Sametime, Connections, Portal und weitere Produkte at 11:54
Henning Heinz on IBM verkauft Notes, Domino, Sametime, Connections, Portal und weitere Produkte at 11:51
Volker Weber on Echo Spot ist wieder online at 11:48
Volker Weber on IBM verkauft Notes, Domino, Sametime, Connections, Portal und weitere Produkte at 10:27
Joerg Rafflenbeul on IBM verkauft Notes, Domino, Sametime, Connections, Portal und weitere Produkte at 10:24
Markus Dierker on I could be in this video at 10:17
Frank van der Linden on IBM sells Notes, Domino, Sametime, Connections, Portal. And a whole lot more. at 09:31
Jan Tietze on Echo Spot ist wieder online at 08:05
Tobias Falk on Apple Watch EKG außerhalb der USA gesperrt at 00:26

Ceci n'est pas un blog

I explain difficult concepts in simple ways. For free, and for money. Clue procurement and bullshit detection.

vowe

Contact
Publications
Stuff that works
Amazon Wish List
Frequently Asked Questions

rss feed  twitter  amazon

Local time is 11:38

visitors.gif

buy me coffee