fighting for truth, justice, and a kick-butt lotus notes experience.

    IBM Technote regarding POODLE and SHA-2 - We have a fix for it

     Oktober 21 2014 04:17:36 PM
    Today IBM published two Technotes, in which IBM announced two new Interims Fixes.

    The first one will bring native SHA-2 support to Domino for HTTP, SMTP, IMAP, POP3 and LDAP.
    The other one will take care for the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack issue:


    IBM intends to release Domino server Interim Fixes over the next several weeks that implement TLS 1.0 with TLS_FALLBACK_SCSV for HTTP to mitigate against POODLE. Implementing TLS 1.0 will allow browsers to still connect to Domino after they have been changed to address the POODLE attack, and Domino will protect against browsers that have been compromised by POODLE.


    The POODLE Fix will be available in the next few days for 8.5.3 and 9.0.x. The SHA-2 fix will be available in the next few weeks for Domino 9.0.x only.

    Many thanks to Dave Kern for make this possible!

    Details here:

    Technote for (POODLE )TLS: http://www-01.ibm.com/support/docview.wss?uid=swg21687167
    Technote for SHA-2: http://www.ibm.com/support/docview.wss?uid=swg21418982

    Archive