<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Domino, Email, Spam and IT Related &#187; Security Related</title>
	<atom:link href="http://www.indomino.net/blog/category/security-related/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.indomino.net/blog</link>
	<description>My Passion about Lotus Notes, Domino, Email and IT Related</description>
	<lastBuildDate>Fri, 27 Aug 2010 02:48:11 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Three things that need to consider for new server</title>
		<link>http://www.indomino.net/blog/2010/07/08/three-things-that-need-to-consider-for-new-server/</link>
		<comments>http://www.indomino.net/blog/2010/07/08/three-things-that-need-to-consider-for-new-server/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 08:31:16 +0000</pubDate>
		<dc:creator>bfebrian</dc:creator>
				<category><![CDATA[Security Related]]></category>
		<category><![CDATA[ibm]]></category>
		<category><![CDATA[ibm xseries]]></category>
		<category><![CDATA[raid 5]]></category>
		<category><![CDATA[redundancy]]></category>
		<category><![CDATA[server]]></category>

		<guid isPermaLink="false">http://www.indomino.net/blog/?p=204</guid>
		<description><![CDATA[You need to buy a new server for your most critical data, the server should be able to run 24 hours a day, 7 days a week.
What are to consider?
Brand of the servers? Of course. The softwares? Sure.
Anything else?
These are three things that cross my mind.
Raid 5
If your data are important, and mostly are, than [...]]]></description>
			<content:encoded><![CDATA[<p>You need to buy a new server for your most critical data, the server should be able to run 24 hours a day, 7 days a week.</p>
<p>What are to consider?</p>
<p>Brand of the servers? Of course. The softwares? Sure.</p>
<p>Anything else?</p>
<p>These are three things that cross my mind.</p>
<p><strong>Raid 5</strong></p>
<p>If your data are important, and mostly are, than use server that support Raid, at least Raid 5.</p>
<p>With Raid 5, we use at least three hard disks with the same capacity (and better with the same brand and model) and configure it as one drive. If one hard disk failed, the data still can be accessible.</p>
<p>Without Raid 5, if you have three hard disk, and one hard disk is failed, that all the data in  that hard disk will be lost.  You need to rely on your latest backup and pray that restoring the data won&#8217;t be a problem.</p>
<p>Minor side with Raid 5 is that Raid 5 will use one hard disk capacity as it parity, so if you have three 1 TB  hard disks, than the total of your capacity is only 2 TB.</p>
<p>And also with Raid 5 , the performance is slower.</p>
<p>With at least Raid 5, you will have redundancy and more capacity compare to Raid 1. There is also Raid 6 that extend the Raid 5.</p>
<p><a href="http://en.wikipedia.org/wiki/Standard_RAID_levels" target="_blank">More about Standard Raid Levels</a></p>
<p><strong>Hot Swap</strong></p>
<p>Ok, now you use Raid 5 for your critical servers that should run 24 hours a day and 7 days a week.</p>
<p>If one hard disk failed, at least your server still able to run with slower performance.</p>
<p>Now, you still need to replace the failed hard disk with a new one. If your server support Hot Swap capabilities like most IBM xseries, than it should not be a problem. You just need to unplug the failed hard disk, wait for 30 seconds and plug in the new one. Total time should be less than one minute.</p>
<p>But, what if your server do not support Hot Swap?</p>
<p>You need to shutdown your server (when? ), open the server case if necessary, detach the cables, unplug the failed hard disk, then plug in the new disk, attach the cables, close the case then power it on again.</p>
<p>How much time do  you need for that?</p>
<p>And you need a spare time to do it, you can&#8217;t just shutdown the server on office hours, you need to do it after office hours, or maybe before office hours or maybe on weekend?</p>
<p><strong>Warranty</strong></p>
<p>Make sure that your servers have good support and spare parts availability.</p>
<p>One thing that I like the most from IBM server is their warranty and support.</p>
<p>While I&#8217;m working with the IBM servers, I have two mainboards problem and four failed hard disks.</p>
<p>The longest time it need is to replace one mainboard from the old server (very old), because they need to ship it from Singapore.</p>
<p>Recently I have one failed hard disk (one of the reason why I wrote this), call IBM support and describe the problem, and all they need is our machine type, serial number and the FRU of the hard disk. Then hard disk replacement already in the office in the next morning.</p>
<p>That what I called a good support.</p>
<p>If they need a month to replace a failed a broken part, that the support, the warranty is useless.</p>
<p>If your warranty going to expired, or already expired, you should, you must extend it. It&#8217;s not cheap, but for me, very worthed.</p>
<p>With IBM, you can choose 5 days support, or 7 days support. With 7 days support, if you call them on weekend, they still come.</p>
<p>Not sure for other brand, if they support as good as IBM. I only works with IBM brand.</p>
<p>Note, I&#8217;m not an employee of IBM.</p>
<img src="http://www.indomino.net/blog/?ak_action=api_record_view&id=204&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.indomino.net/blog/2010/07/08/three-things-that-need-to-consider-for-new-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TeamViewer, king of remote access</title>
		<link>http://www.indomino.net/blog/2010/02/09/teamviewer-king-of-remote-access/</link>
		<comments>http://www.indomino.net/blog/2010/02/09/teamviewer-king-of-remote-access/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 15:32:06 +0000</pubDate>
		<dc:creator>bfebrian</dc:creator>
				<category><![CDATA[Security Related]]></category>
		<category><![CDATA[remote access software]]></category>
		<category><![CDATA[remote-access]]></category>
		<category><![CDATA[team-viewer]]></category>
		<category><![CDATA[teamviewer]]></category>

		<guid isPermaLink="false">http://www.indomino.net/blog/?p=183</guid>
		<description><![CDATA[My sister just called me, she need to send one email immediately to one of her buyer, but her email is having a problem. The email that she want to send is stuck in the outbox, can&#8217;t be send.
She using windows vista and windows mail as her mail client. I tried to explain to her [...]]]></description>
			<content:encoded><![CDATA[<p>My sister just called me, she need to send one email immediately to one of her buyer, but her email is having a problem. The email that she want to send is stuck in the outbox, can&#8217;t be send.</p>
<p>She using windows vista and windows mail as her mail client. I tried to explain to her on how to solve the problem, but she still didn&#8217;t understand. Can&#8217;t blame her, she is not a computer geek, but a very good sales person.</p>
<p>She is at home, while I&#8217;m in the office, and her buyer waiting for the email, now what to do?</p>
<p>Luckily, the last time I visited her house, I downloaded a very good software called <a href="http://www.teamviewer.com/index.aspx" target="_blank">Team Viewer</a>. I ask her to connect to the internet, and then run the team viewer software by double click the exe file, no need to install, then she get the session id and password.</p>
<p><img class="alignnone size-medium wp-image-184" title="teamviewer" src="http://www.indomino.net/blog/wp-content/uploads/2010/02/teamviewer-300x207.jpg" alt="teamviewer" width="300" height="207" /></p>
<p>And that is it.</p>
<p>She gave me the session id and password, I run my team viewer and than connected to her computer at no time.</p>
<p>Solved the problem in less than 10 minutes, the stuck email went away to her buyer.</p>
<p>She happy, her buyer happy, and I&#8217;m happy able to help.</p>
<p>For quick, and easy setup remote access software, TeamViewer really is the king. You don&#8217;t even need to install the software.</p>
<p>Not only for remote  access, with TeamViewer you can also chat or copy files between computers. Great for remote support.</p>
<p>And all of that without any cost (for home user).</p>
<p>TeamViewer is highly recommended software, that every support computer should have.</p>
<p>I&#8217;m not related in any way with Team Viewer. I am just a happy user.</p>
<img src="http://www.indomino.net/blog/?ak_action=api_record_view&id=183&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.indomino.net/blog/2010/02/09/teamviewer-king-of-remote-access/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Smadav, Indonesian Anti Virus</title>
		<link>http://www.indomino.net/blog/2010/01/13/smadav-indonesian-anti-virus/</link>
		<comments>http://www.indomino.net/blog/2010/01/13/smadav-indonesian-anti-virus/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 07:38:10 +0000</pubDate>
		<dc:creator>bfebrian</dc:creator>
				<category><![CDATA[Security Related]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[indonesia]]></category>
		<category><![CDATA[pcmav]]></category>
		<category><![CDATA[smadav]]></category>

		<guid isPermaLink="false">http://www.indomino.net/blog/?p=164</guid>
		<description><![CDATA[There are many viruses that come from Indonesia, that spread through the internet. Usually, mainstream anti virus like symantec, mcafee, eset have difficulties to detect these local viruses, mostly they able to detect and clean them in  several month after the first break, and that is too late.
But, luckily we also have local anti virus, [...]]]></description>
			<content:encoded><![CDATA[<p>There are many viruses that come from Indonesia, that spread through the internet. Usually, mainstream anti virus like symantec, mcafee, eset have difficulties to detect these local viruses, mostly they able to detect and clean them in  several month after the first break, and that is too late.</p>
<p>But, luckily we also have local anti virus, that mainly able to detect and clean those local viruses, like <a href="http://pcmav.biz/" target="_blank">pcmav</a> and <a href="http://smadav.net" target="_blank">smadav</a>.</p>
<p><a href="http://www.smadav.net"><img class="size-medium wp-image-168 alignleft" title="smadav-about" src="http://www.indomino.net/blog/wp-content/uploads/2010/02/smadav-about-300x223.jpg" alt="smadav-about" width="300" height="223" /></a></p>
<p>But, compare to them, personally I like smadav most because of it small size and able to work together with mainstream anti virus. My smadav 2010 rev 8 able to work together with Symantec End Point 11.</p>
<p>As stated in their <a href="http://www.smadav.net/" target="_blank">website</a></p>
<blockquote><p>Smadav was made to clean and protect your computer from local viruses that many spread in Indonesia.</p></blockquote>
<p>If you using anti virus like symantec, mcafee and esset, you can use smadav as second layer of protection against virus without a problem.</p>
<p>You can download the smadav for personal use for free in <a href="http://www.smadav.net/download" target="_blank">here</a>. The website and user interface are in bahasa, but it&#8217;s will not be difficult to understand the interface because it so easy.</p>
<p>If you want to try pcmav, you can download it in <a href="http://pcmav.biz/download" target="_blank">here</a>.</p>
<p>Be secure.</p>
<img src="http://www.indomino.net/blog/?ak_action=api_record_view&id=164&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.indomino.net/blog/2010/01/13/smadav-indonesian-anti-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Problem when try to install Symantec Endpoint Protection</title>
		<link>http://www.indomino.net/blog/2009/08/19/problem-when-try-to-install-symantec-endpoint-protection/</link>
		<comments>http://www.indomino.net/blog/2009/08/19/problem-when-try-to-install-symantec-endpoint-protection/#comments</comments>
		<pubDate>Wed, 19 Aug 2009 08:40:31 +0000</pubDate>
		<dc:creator>bfebrian</dc:creator>
				<category><![CDATA[Security Related]]></category>
		<category><![CDATA[microsoft windows]]></category>
		<category><![CDATA[pending-system-changes]]></category>
		<category><![CDATA[regedit]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[symantec-endpoint-protection]]></category>
		<category><![CDATA[symantec-endpoint-security]]></category>

		<guid isPermaLink="false">http://www.indomino.net/blog/?p=151</guid>
		<description><![CDATA[Now I&#8217;m in the process to migrate all anti virus clients to Symantec EndPoint Protection.
I&#8217;m very well aware of all Symantec Anti Virus Products, specially that I used to use Symantec Anti Virus Corporate Edition (now called Symantec EndPoint Protection) .  The best thing that I like from Symantec that even though many people complains [...]]]></description>
			<content:encoded><![CDATA[<p>Now I&#8217;m in the process to migrate all anti virus clients to Symantec EndPoint Protection.</p>
<p>I&#8217;m very well aware of all Symantec Anti Virus Products, specially that I used to use Symantec Anti Virus Corporate Edition (now called Symantec EndPoint Protection) .  The best thing that I like from Symantec that even though many people complains that Symantec Anti Viruses are very slow (and I agree ) but it very stable.</p>
<p>And talking about viruses, I prefer slow but accurate rather that fast but there are many viruses still slip away.</p>
<p>But, after many successful installation of Symantec EndPoint Protection, I failed in one computer, with the error message.</p>
<blockquote><p>symantec endpoint protection has <strong><em>detected</em></strong> that there are pending system changes that require a reboot</p></blockquote>
<p>After search the net, it&#8217;s not Symantec problem, actually more than Microsoft problems.</p>
<p>The solution is quite simple.</p>
<p>Open regedit (you should know where and how to run regedit <img src='http://www.indomino.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ), find the value PendingFileRenameOperations, then delete all the data.</p>
<p>The data should be like this:</p>
<blockquote><p>\??\source file<br />
!\??\target file</p></blockquote>
<p>After you delete the data, now you can continue to install Symantec EndPoint Protection without anymore problem.</p>
<img src="http://www.indomino.net/blog/?ak_action=api_record_view&id=151&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.indomino.net/blog/2009/08/19/problem-when-try-to-install-symantec-endpoint-protection/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>About Lotus Foundation</title>
		<link>http://www.indomino.net/blog/2009/02/28/about-lotus-foundation/</link>
		<comments>http://www.indomino.net/blog/2009/02/28/about-lotus-foundation/#comments</comments>
		<pubDate>Sat, 28 Feb 2009 15:11:16 +0000</pubDate>
		<dc:creator>bfebrian</dc:creator>
				<category><![CDATA[Lotus Notes and Domino]]></category>
		<category><![CDATA[Mail and Spam Related]]></category>
		<category><![CDATA[Security Related]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[email clients]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[lotus-domino]]></category>
		<category><![CDATA[lotus-foundation]]></category>
		<category><![CDATA[open-suse-linux]]></category>

		<guid isPermaLink="false">http://www.indomino.net/blog/2009/02/28/about-lotus-foundation/</guid>
		<description><![CDATA[The most interesting part of the event is Lotus Foundation.
Lotus foundation is a &#8220;software suite&#8221; that has it own operating system based on striped Open Suse linux, and a striped down version of Lotus Domino server. It has it own anti spam and anti virus software, file sharing, firewall and even VPN server, that why [...]]]></description>
			<content:encoded><![CDATA[<p>The most interesting part of the event is <a href="http://www-01.ibm.com/software/lotus/products/foundations/start/" target="_blank">Lotus Foundation</a>.</p>
<p>Lotus foundation is a &#8220;software suite&#8221; that has it own operating system based on striped Open Suse linux, and a striped down version of Lotus Domino server. It has it own anti spam and anti virus software, file sharing, firewall and even VPN server, that why I called it a software suite.</p>
<p>This is a software suite, so it can be installed in any hardware, but maybe some IBM Business Partner will sell it with the hardware to reduce hardware compatibilities issues.</p>
<p>And for the email clients, it support webmail, lotus notes clients, ms outlook and any other email clients that support pop3 an<br />
In the advertisements, it state that it can up and running in less than 30 minutes, and it designed for small office with no IT personnel.</p>
<p>The suite can self configured, it mean that it will automatically detect the network infrastructure and configure it self based on it founding.</p>
<p>If the suite detected that there are some malfunction in part of it software, it will try to heal it self, by restore the configuration from the last backup, and it will done automatically.</p>
<p>In the demo, the hardware come with two sata harddisks, on for the suite and the other one for the backup. If something really bad happen, it will only take 30 minutes to restore to it default stat, and maybe another 10-30 minutes to restore from the backup.</p>
<p>You can get the brochure <a href="ftp://ftp.software.ibm.com/software/lotus/lotusweb/products/foundations/start/Lotus_Foundations_Brochure.pdf">here</a>, and the datasheet <a href="ftp://ftp.software.ibm.com/software/lotus/lotusweb/products/foundations/start/Lotus_Foundations_Appliance.pdf">here</a>.</p>
<p>I guess it true, that the suite is designed for small office that has no IT personnel, and soon I&#8217;ll be out of the job <img src='http://www.indomino.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<img src="http://www.indomino.net/blog/?ak_action=api_record_view&id=139&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.indomino.net/blog/2009/02/28/about-lotus-foundation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to enable SSL in Lotus Domino</title>
		<link>http://www.indomino.net/blog/2009/01/17/how-to-enable-ssl-in-lotus-domino/</link>
		<comments>http://www.indomino.net/blog/2009/01/17/how-to-enable-ssl-in-lotus-domino/#comments</comments>
		<pubDate>Sat, 17 Jan 2009 03:35:16 +0000</pubDate>
		<dc:creator>bfebrian</dc:creator>
				<category><![CDATA[Lotus Notes and Domino]]></category>
		<category><![CDATA[Security Related]]></category>
		<category><![CDATA[how-to]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[lotus-domino-8]]></category>
		<category><![CDATA[self-certified-certificate]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://www.indomino.net/blog/?p=121</guid>
		<description><![CDATA[One of the good things about Lotus Notes/Domino is that it has a very good help system in NSF format. Lotus Notes/Domino has three basic help databases, for normal Lotus Notes users, for Lotus Notes programmers/designers and for Lotus Domino administrators. All the help databases are easy to read and understand.

But even the easiest documentation [...]]]></description>
			<content:encoded><![CDATA[<p>One of the good things about Lotus Notes/Domino is that it has a very good help system in NSF format. Lotus Notes/Domino has three basic help databases, for normal Lotus Notes users, for Lotus Notes programmers/designers and for Lotus Domino administrators. All the help databases are easy to read and understand.</p>
<p class="MsoNormal">
<p class="MsoNormal">But even the easiest documentation can become confusing sometimes. One of them is how to enable SSL in Lotus Domino servers.</p>
<p class="MsoNormal">
<p class="MsoNormal">I have to read it many times until I understand the concept, so to avoid others to have my difficulties; I created this simple how to.</p>
<p class="MsoNormal">
<p class="MsoNormal">SSL requires certificate, while Lotus Domino support the certificate that created by third party organizations, Lotus Domino also have the capabilities to create it own certificate called <em><strong>Self-Certified Certificate</strong></em>.<span> </span>The problem with Self-Certified Certificate that you need to accept the certificate (trust) before you can use it, while the third party certificate already trusted.</p>
<p class="MsoNormal">
<p class="MsoNormal">This how to will only to discuss about how to create Self-Certified Certificate, this how to will not discuss about the certificate that created by third party organizations. The idea of self-certified certificate is that you can quickly setup your own SSL certificate.</p>
<p class="MsoNormal">
<p class="MsoNormal">This how to required Lotus Notes client, access to Lotus Domino server as Lotus Domino administrator, and have access to copy files to Lotus Domino server.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Server Certificate Administration Database</strong></p>
<p class="MsoNormal">
<p class="MsoNormal">When you install Lotus Domino in the first place, it will automatically created a database called <em><strong>Server Certificate Administration</strong></em>. You will need this database to create your own Self-Certified Certificate. Find and open the Server Certificate Administration or certsrv.nsf in the server, if not available you can create it with the template: csrv50.ntf, give the database name certsrv.nsf</p>
<p class="MsoNormal">
<p class="MsoNormal"><img class="alignnone" src="http://farm4.static.flickr.com/3133/3202166445_246e4e2d94.jpg" alt="" width="500" height="347" /></p>
<p class="MsoNormal">
<p class="MsoNormal">There are several options in the left menu, just ignore it. We only want to create Self-Certified Certificate, click the &#8220;<em><strong>Click Key Ring with Self-Certified Certificate</strong></em>&#8220;.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Create Key Ring</strong></p>
<p class="MsoNormal">
<p class="MsoNormal">Now, there are several fields that need to be filling in. There should be enough help in the Quick Help, but to make it easier, these are the examples:</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Key Ring Information</strong></p>
<p class="MsoNormal">
<p class="MsoNormal"><em><strong>Key Ring File Name</strong></em></p>
<p class="MsoNormal">The file name of the key ring, the key ring should have kyr extension. If you have several servers that need SSL connection, better give it more understanding name. In this example I give my file name as selfcert-st01.kyr, where st01 is my server name.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong><em>Password and Password Verify</em></strong></p>
<p class="MsoNormal">No need to explain about it. <img src='http://www.indomino.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Distinguished Name</strong></p>
<p class="MsoNormal">
<p class="MsoNormal"><em><strong>Common Name</strong></em></p>
<p class="MsoNormal">The Full Qualified Domain Name (FQDN) of the server. In this example I put st01.indomino.net, because my server will be accessible with st01.indomino.net. Make sure that you can connect to your server with your FQDN.</p>
<p class="MsoNormal">
<p class="MsoNormal"><em><strong>Organization</strong></em></p>
<p class="MsoNormal">Explain about your organization, or your company. I use indomino in the organization.</p>
<p class="MsoNormal">
<p class="MsoNormal"><em><strong>Organizational Unit (optional)</strong></em></p>
<p class="MsoNormal">If you need to break your organization in more details, maybe based on departments or locations. I leave it blank; you can put your department or location.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong><em>City or Locality (optional)</em></strong></p>
<p class="MsoNormal">Your city name, I put Jakarta</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong><em>State or Province</em></strong></p>
<p class="MsoNormal">Your Province, I put Jakarta</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong><em>Country</em></strong></p>
<p class="MsoNormal">Because I live in Indonesia, I put ID</p>
<p class="MsoNormal">
<p class="MsoNormal"><img class="alignnone" src="http://farm4.static.flickr.com/3416/3202166277_d51dc67aee.jpg" alt="" width="500" height="439" /></p>
<p class="MsoNormal">
<p class="MsoNormal">Make sure everything is correct than click the big button in the bottom of the page &#8220;<strong>Create Key Ring with Self-Certified Certificate</strong>&#8220;</p>
<p class="MsoNormal">
<p class="MsoNormal">It will create the key ring and it will notify you that the key ring has been created.</p>
<p class="MsoNormal"><img class="alignnone" src="http://farm4.static.flickr.com/3111/3202166157_d0e9065453.jpg" alt="" width="500" height="383" /></p>
<p class="MsoNormal">
<p class="MsoNormal">The process will create two file names in your notes data folder, <strong>selfcert-st01.kyr</strong> and <strong>selfcert-st01.sth</strong>.<strong> </strong>The<strong> </strong>files<strong> </strong>will<strong> </strong>be<strong> </strong>located<strong> </strong>in your local drive. You need to copy both file to the Lotus Domino server in the Lotus Domino Data directory.</p>
<p class="MsoNormal">
<p class="MsoNormal"><strong>Enable the SSL</strong></p>
<p class="MsoNormal">
<p class="MsoNormal">Now the fun part, how to enable the Self-Certified Certificate with your Lotus Domino.</p>
<ol>
<li>Open your Lotus Domino directory, you have to have full access to it.</li>
<li>Find and edit your current server document configuration (If you using internet sites you have to edit or add the internet sites documents)</li>
<li>Go to Ports tab and find the SSL settings</li>
<li>In the SSL key file name<span> </span>field,  type your kyr file that you just created, I put <em><strong>selfcert-st01.kyr</strong></em> and just let other setting as default.</li>
<li>Now you can enable SSL in any protocols, in this how to I will enable it in HTTP protocol.</li>
<li>Go to Web tab, and find the SSL port status then change it into enable</li>
<li>Click save and close</li>
</ol>
<p class="MsoNormal">
<p class="MsoNormal">Now you can access your website with https, use your server FQDN to access your website.</p>
<p class="MsoNormal">
<p class="MsoNormal">if you access your website via internet explorer or firefox, there will be an error message telling you that the certificate is not trusted, just ignore it and click continue.</p>
<p class="MsoNormal"><img class="alignnone" src="http://farm4.static.flickr.com/3265/3202165347_8b8176360e.jpg" alt="" width="500" height="375" /></p>
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal">To prevent this annoying pop up, you need to accept the certificate in your certificate list.</p>
<p class="MsoNormal">This how to accept the certificate in MS Internet Explorer.</p>
<p class="MsoNormal">In the address bar, there will be a message telling that the site have certificate error.</p>
<p class="MsoNormal"><img class="alignnone" src="http://farm4.static.flickr.com/3476/3202165599_f10c2baf30.jpg" alt="" width="500" height="375" /></p>
<p class="MsoNormal">Follow these steps to add your certificate as trusted certificate.</p>
<ol>
<li>Click it and click view certificate</li>
<li>Click install certificate, don&#8217;t click automatically install, click browse instead.</li>
<li>Select the trusted root certificate authority, and then click finish.</li>
<li>There will be a big warning, just ignore it and click yes.</li>
<li>Restart internet explorer, now you can access your website without certificate warning.</li>
</ol>
<p class="MsoNormal">Now you have SSL enabled Lotus Domino server. You can use SSL not only in the HTTP, but also in Email and LDAP.</p>
<p class="MsoNormal">With HTTPS enabled, your users can change their own password from webmail.</p>
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal">
<img src="http://www.indomino.net/blog/?ak_action=api_record_view&id=121&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.indomino.net/blog/2009/01/17/how-to-enable-ssl-in-lotus-domino/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>About Domino Web Access</title>
		<link>http://www.indomino.net/blog/2008/10/07/about-domino-web-access/</link>
		<comments>http://www.indomino.net/blog/2008/10/07/about-domino-web-access/#comments</comments>
		<pubDate>Tue, 07 Oct 2008 02:47:10 +0000</pubDate>
		<dc:creator>bfebrian</dc:creator>
				<category><![CDATA[Lotus Notes and Domino]]></category>
		<category><![CDATA[Security Related]]></category>
		<category><![CDATA[domino-web-access]]></category>
		<category><![CDATA[dwa]]></category>
		<category><![CDATA[inotes]]></category>
		<category><![CDATA[lotus-domino]]></category>
		<category><![CDATA[lotus-notes]]></category>
		<category><![CDATA[webmail]]></category>

		<guid isPermaLink="false">http://www.indomino.net/blog/2008/10/07/about-domino-web-access/</guid>
		<description><![CDATA[With Lotus Domino, we have the abilities to access our mailbox via web. First, is nothing more than quot;Hey, I can access my email via webquot; or simply webmail, and now it become &#8216;full features&#8217; Lotus Notes client or iNotes (later it called Domino Web Access or DWA).
Now in Domino Web Access there are three [...]]]></description>
			<content:encoded><![CDATA[<p>With Lotus Domino, we have the abilities to access our mailbox via web. First, is nothing more than quot;Hey, I can access my email via webquot; or simply webmail, and now it become &#8216;full features&#8217; Lotus Notes client or iNotes (later it called Domino Web Access or DWA).<br />
Now in Domino Web Access there are three options on how to access your mailbox via web.</p>
<ul>
<li> Domino Web Access</li>
<li> Domino Web Access Lite</li>
<li> Domino Web Access Ultra Lite</li>
</ul>
<p>Big thanks to <a href="http://gunawantw.wordpress.com" target="_blank">Gunawan&#8217;s blog</a> who give me the news about <a href="http://gunawantw.wordpress.com/2008/09/10/lotus-inotes-ultralite-mode-nggak-cuma-buat-iphone-doang" target="_blank">the new web access ultra lite and how to enable it</a>.</p>
<p><strong>Domino Web Access</strong><br />
This is the standard web access. If your main internet browser is Internet Explorer and you have fast internet connection, than this kind of web access is the most suitable for you.<br />
As normal Lotus Notes client, It give you more features, like preview and full access to your calendar.<br />
I still having problem to access Domino Web Access via my Firefox 3.0.1, it still buggy. One big problem that I can&#8217;t attached any files to new email. I&#8217;m not sure if the problem is in Domino or Firefox, but I do hope that both parties can work together to solved this problem.</p>
<p><strong>Domino Web Access Lite</strong><br />
As in the name, this web access is a liter web access version than the standard. If you have slow or medium internet connection maybe you can try this web access. It does not give you preview and full calendar functionality, but it will give you tabs for email and sidebar for calendaring.<br />
You can easily change from full dwa to lite dwa from the right top menu.</p>
<p><strong>Domino Web Access Ultra Lite</strong><br />
This is new since Lotus Domino 8.02, designed for mobile users with smartphone or pda. It designed to run on iphone but it run perfectly in my Opera Mini under my Nokia E61. But because of the landscape screen in Nokia E61 , the icons does not fit very well. It should fit well in any screen that in portrait mode.<br />
As in <a href="http://gunawantw.wordpress.com" target="_blank">Gunawan&#8217;s Blog</a> you can try to access your Domino Web Access Ultra Lite via Google Chrome, but because Google Chrome is using some part of Opera engine, I think it should run in Opera browser too (it run in my Opera Mini).</p>
<p><img src="http://www.indomino.net/blog/wp-content/uploads/2008/10/dwa-ultralite-home.png" alt="" width="279" height="477" /><img src="http://www.indomino.net/blog/wp-content/uploads/2008/10/dwa-ultralite-inbox.png" alt="" width="279" height="477" /></p>
<p>Domino still support standard webmail for older internet browser or non standard internet browser (I can access webmail via Opera Mini).<br />
For more security, it is wise to enable SSL encryption in your web server to prevent someone else hacking into your data, specially your username and password.</p>
<img src="http://www.indomino.net/blog/?ak_action=api_record_view&id=81&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.indomino.net/blog/2008/10/07/about-domino-web-access/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Symantec Endpoint Security, New Anti Virus from Symantec</title>
		<link>http://www.indomino.net/blog/2007/11/13/symantec-endpoint-security-new-anti-virus-from-symantec/</link>
		<comments>http://www.indomino.net/blog/2007/11/13/symantec-endpoint-security-new-anti-virus-from-symantec/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 02:26:01 +0000</pubDate>
		<dc:creator>bfebrian</dc:creator>
				<category><![CDATA[Security Related]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[symantec-endpoint-security]]></category>

		<guid isPermaLink="false">http://www.indomino.net/blog/2007/11/13/symantec-endpoint-security-new-anti-virus-from-symantec/</guid>
		<description><![CDATA[I&#8217;m a loyal customer of Symantec Anti Virus product, it serve me well for the last 7 years.
Now, from my consultant, I&#8217;m being told that Symantec, again, releasing a new product for security called Symantec Endpoint Security. Symantec Endpoint Security will be replacing Symantec Anti Virus Corporate Edition 10.
Why security, why not Anti Virus? Because [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m a loyal customer of Symantec Anti Virus product, it serve me well for the last 7 years.</p>
<p>Now, from my consultant, I&#8217;m being told that Symantec, again, releasing a new product for security called <a href="http://edm.symantec.com/endpointsecurity/" target="_blank">Symantec Endpoint Security</a>. Symantec Endpoint Security will be replacing Symantec Anti Virus Corporate Edition 10.</p>
<p>Why security, why not Anti Virus? Because it&#8217;s more than Anti Virus, it have:</p>
<ul>
<li>Anti Virus</li>
<li>Anti Spyware</li>
<li>Firewall</li>
<li>and Intrusion Prevention</li>
</ul>
<p>You can download a trial version of Symantec Endpoint Security in <a href="http://www4.symantec.com/Vrt/offer?a_id=48182" target="_blank">here</a>.</p>
<p>This is a good news, that meant that Symantec is trying to do their best to improve their security product to protect their customer.</p>
<p>But, this is also a bad news for me. Why? Because I need to migrate to existing Symantec Anti Virus CE 10 to the new  Symantec Endpoint Security. And that, will be NOT an easy job.</p>
<p>There are three version of Symantec Endpoint Security:</p>
<ol>
<li>Symantec Endpoint Security <a href="http://edm.symantec.com/endpointsecurity/pdfs/12836807_SEP_US_ds.pdf" target="_blank">pdf</a></li>
<li>Symantec Endpoint Security Small Business Edition <a href="http://edm.symantec.com/endpointsecurity/pdfs/12836806_SEP_SBE_US_ds_hires.pdf" target="_blank">pdf</a></li>
<li>Symantec Multi-tier Protection <a href="http://edm.symantec.com/endpointsecurity/pdfs/12836805_ESMP_US_ds_hires.pdf" target="_blank">pdf</a></li>
</ol>
<p>What suprise me that, in Symantec Endpoint Security Small Business Edition they have Symantec Mail Security for Microsoft Exchange, but Lotus Domino.</p>
<p>Why, I&#8217;m not sure. Symantec Mail Security for Domino only exist in Symantec Multi-tier Protection.</p>
<p>If you using Lotus Domino, and want to use Symantec product, than you need yo buy the most expensive product which is Symantec Multi-tier Protection, and if you use MS Exhange you can buy more cheaper product.</p>
<p>Now, again, I need to learn how to migrate our Anti Virus or Security software and I hope that the new software will perform better than the previous one.</p>
<p>Cross my fingers, and moving forward.</p>
<img src="http://www.indomino.net/blog/?ak_action=api_record_view&id=68&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.indomino.net/blog/2007/11/13/symantec-endpoint-security-new-anti-virus-from-symantec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Connection without Connection</title>
		<link>http://www.indomino.net/blog/2007/09/03/connection-without-connection/</link>
		<comments>http://www.indomino.net/blog/2007/09/03/connection-without-connection/#comments</comments>
		<pubDate>Mon, 03 Sep 2007 09:39:07 +0000</pubDate>
		<dc:creator>bfebrian</dc:creator>
				<category><![CDATA[Security Related]]></category>
		<category><![CDATA[jokes]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[smtp]]></category>

		<guid isPermaLink="false">http://www.indomino.net/blog/2007/09/03/connection-without-connection/</guid>
		<description><![CDATA[This is really happen.  
I just have an electrical problem, the power from electric company was down, so we have to run our servers from ups.
After a while, the ups start to drop the battery, so we start to shutdown unnecessary servers, so it give the ups more power to run.
But, it not for [...]]]></description>
			<content:encoded><![CDATA[<p>This is really happen. <img src='http://www.indomino.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I just have an electrical problem, the power from electric company was down, so we have to run our servers from ups.</p>
<p>After a while, the ups start to drop the battery, so we start to shutdown unnecessary servers, so it give the ups more power to run.</p>
<p>But, it not for long, the electriciy still down and the ups battery start to drop quickly, so we decided to run ONLY the smtp server, so at least we still can receive emails.</p>
<p>But someone in the IT department take it very literally, he or she also pull the plug of the switches, including the main switch that connect to the servers (including smtp server)<br />
And the smtp server is up and running.</p>
<p>But without the connection to the main switch, how it can receive any emails? <img src='http://www.indomino.net/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>No one say that he or she that pull the plug of the switches, it still remain a mystery. <img src='http://www.indomino.net/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<img src="http://www.indomino.net/blog/?ak_action=api_record_view&id=62&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.indomino.net/blog/2007/09/03/connection-without-connection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPCop Firewall Review Part II</title>
		<link>http://www.indomino.net/blog/2007/07/10/ipcop-firewall-review-part-ii/</link>
		<comments>http://www.indomino.net/blog/2007/07/10/ipcop-firewall-review-part-ii/#comments</comments>
		<pubDate>Tue, 10 Jul 2007 09:20:01 +0000</pubDate>
		<dc:creator>bfebrian</dc:creator>
				<category><![CDATA[Linux and Open Source]]></category>
		<category><![CDATA[Security Related]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[ipcop]]></category>
		<category><![CDATA[review]]></category>

		<guid isPermaLink="false">http://www.indomino.net/blog/2007/07/10/ipcop-firewall-review-part-ii/</guid>
		<description><![CDATA[I has been testing IPCop Firewall for more than a week now. I only have two minor problems with IPCop, there are:

IPCop as default allow all connections to the Internet. This maybe ideal for home users but not corporate users.
IPCop as default not support NAT 1:1. Although we can modify the iptables script (/etc/rc.d/rc.firewall.local), but [...]]]></description>
			<content:encoded><![CDATA[<p>I has been testing IPCop Firewall for more than a week now. I only have two minor problems with IPCop, there are:</p>
<ol>
<li>IPCop as default allow all connections to the Internet. This maybe ideal for home users but not corporate users.</li>
<li>IPCop as default not support NAT 1:1. Although we can modify the iptables script (/etc/rc.d/rc.firewall.local), but it will nice to have a gui for it similar with <span style="font-style: italic">port forwarding</span> and <span style="font-style: italic">external access</span> in Firewall menu.</li>
</ol>
<p>Other than that, overall IPCop is good firewall, stable and easy enough to manage.</p>
<p><strong>IPCop Addons</strong><br />
IPCop addons is a bit tricky to install. I have install many addons, while most of them install flawlessly, but a few of them cause a big problem.</p>
<p><strong>A Tip</strong><br />
Before you add patch or add an addon, please do it your test machine and see how it&#8217;s going. I have spent an entire night to fix it after I installed an addon.</p>
<p>I will only talk about addons that I have a problem when installing.</p>
<p><strong>BlockOut Traffic (BOT).</strong><br />
I have no problem when installed this addon, the installation was easy, and the configuration is very straight forward. BUT after I download and install a modified kernel that support layer7 filtering from <a href="http://www.mhaddons.tk/" target="_blank">http://www.mhaddons.tk/</a>, BOT doesn&#8217;t works anymore.<br />
Before the modified kernel, BOT block out any traffic successfully.</p>
<p>But, after the modified kernel installed, nothing is blocked.<br />
Reinstalling BOT doesn&#8217;t solved the problem.</p>
<p>It seem that BOT and the modified kernel can&#8217;t work together.</p>
<p>Finally I had to remove BOT, and manually modify the iptables to block most of the ports.</p>
<p><strong>Guardian</strong></p>
<p align="left">This one cause a very big problem. I download the latest guardian (v 2.4.9.7) from <a href="http://www.mhaddons.tk/" target="_blank">http://www.mhaddons.tk/</a>, and when installing I receive an error. I&#8217;m not sure what kind of error, it says line error or something, but the installations process continue with no further error.<br />
Curiosity, I reinstall the Guardian, and that cause a big problem.<br />
Connection to the IPCop servers is blocked.<br />
When I list the iptables rules with iptables -L command, it give me surprisingly result.</p>
<p><em>Chain INPUT (policy DROP)<br />
target     prot opt source               destination</em></p>
<p><em>Chain FORWARD (policy DROP)<br />
target     prot opt source               destination</em></p>
<p><em>Chain OUTPUT (policy DROP)<br />
target     prot opt source               destination</em></p>
<p>When I try to manually run the iptables script, it give me errors about segmentation fault.</p>
<p>Panic, I restart the server, still give me errors about iptables segmentation fault.</p>
<p>I realize that IPTables got corrupted.</p>
<p>Then I found out that I still able to change the default policy from DROP to ACCEPT, at least I still can access the server remotely and copy files.</p>
<p>No connections to the net allowed unless though proxy.<br />
Incoming and Outgoing email pending in the mail server.</p>
<p>I&#8217;m not sure how can I restore the corrupted IPTables.</p>
<p>After some trying and errors, than I manually copy files from the original iso of IPCop from /lib/iptables and /sbin and then restart.</p>
<p>It solved the problem.</p>
<p>All the iptables rules applied and run, what a relief.</p>
<p>I know that I need the install the new kernel that support layer 7 filtering, but I think that enough for now. I hate another surprises.<br />
Regarding my previous tip, now I&#8217;m looking for unused, spare PC to become my test server. I will install all new addon in there first, after successfully installed, then I will installed in the live firewall.<br />
I hope there are no more surprises.</p>
<p>I do now run many addons in my IPCop, and they works wonderfully, but still a test server will be great.</p>
<img src="http://www.indomino.net/blog/?ak_action=api_record_view&id=53&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.indomino.net/blog/2007/07/10/ipcop-firewall-review-part-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
