<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>lekkimworld.comsecurity</title>
    <link>http://lekkimworld.com/tags/security/</link>
    <description>IBM Lotus Notes/Domino, Websphere, IBM Connections, mobile, web, JavaScript, Java...</description>
    <language>en</language>
    <copyright>Mikkel Flindt Heisterberg (mh [at] intravision [dot] dk</copyright>
    <pubDate>Sat, 19 May 2012 06:50:25 GMT</pubDate>
    <dc:creator>Mikkel Flindt Heisterberg (mh [at] intravision [dot] dk</dc:creator>
    <dc:date>2012-05-19T06:50:25Z</dc:date>
    <dc:language>en</dc:language>
    <dc:rights>Mikkel Flindt Heisterberg (mh [at] intravision [dot] dk</dc:rights>
    <image>
      <title>lekkimworld.comsecurity</title>
      <url>http://lekkimworld.com/tags/security/</url>
    </image>
    <item>
      <title>Websphere Application Server Security - make sure file based auth continues if federated repository is unavailable</title>
      <link>http://lekkimworld.com/2010/06/30/websphere_application_server_security_make_sure_file_based_auth_continues_if_federated_repository_is_unavailable.html</link>
      <content:encoded>&lt;p&gt;
While looking for another tidbit of information on Google I found this very interesting setting in a WAS FAQ (&lt;a href="http://www.ibm.com/developerworks/websphere/techjournal/1003_botzum/1003_botzum.html"&gt;Q &amp; A: Frequently asked questions about WebSphere Application Server security&lt;/a&gt;). That fact that access to the Integrated Solutions Console (ISC) would stop if a LDAP directory was unavailable even though the ISC admin account was local has been bothering me for a while. It was nice to see that this fact which has been irritating me for a while (when it isn't set) is solvable.
&lt;/p&gt;
&lt;i&gt;
&lt;p&gt;
7. When using a federated repository, is there a way to ensure that my file-based registry will continue to function when a LDAP server is down?
&lt;/p&gt;
Yes, there is a configuration option that enables the authentication to continue if one or more other registries are down, as long as the ID is found in one of the registries that are still up and functional. The federated repository configuration command to permit this is:
&lt;br /&gt;
&lt;pre&gt;$AdminTask createIdMgrRealm 
     -name ibmRealm -allowOperationIfReposDown true&lt;/pre&gt;
&lt;/p&gt;
&lt;p&gt;
More information can be found in the Information Center article: IdMgrRealmConfig command group for the AdminTask object. 
&lt;/p&gt;
&lt;/i&gt;</content:encoded>
      <category domain="http://lekkimworld.com/tags/faq/">faq</category>
      <category domain="http://lekkimworld.com/tags/security/">security</category>
      <category domain="http://lekkimworld.com/tags/was/">was</category>
      <category domain="http://lekkimworld.com/tags/websphere/">websphere</category>
      <pubDate>Wed, 30 Jun 2010 06:26:46 GMT</pubDate>
      <guid isPermaLink="false">tag:lekkimworld.com,2010-06-30:default/1277879206230</guid>
      <dc:date>2010-06-30T06:26:46Z</dc:date>
    </item>
    <item>
      <title>Is the security of the Notes/Domino Java implementation questionable? (security vulnerability in the Notes/Domino Java API)</title>
      <link>http://lekkimworld.com/2006/12/07/is_the_security_of_the_notes_domino_java_implementation_questionable_security_vulnerability_in_the_notes_domino_java_api.html</link>
      <content:encoded>During some security research into the Notes/Domino Java API I stumbled upon what I cannot judge to be anything but a &lt;b&gt;major&lt;/b&gt; flaw in the Java implementation of Notes/Domino. The flaw allows me to circumvent the restricted/unrestricted operations security model for agents as well as all security measures put in place by the SecurityManager installed by IBM. The research was done on Notes/Domino 7.0.1 but I cannot see why it shouldn't be applicable to prior releases. I have been working with the IBM Security Response Team to assess the implications and &lt;a href="http://www-1.ibm.com/support/docview.wss?rs=463&amp;uid=swg21248025"&gt;technote #1248025&lt;/a&gt; (SPR# KLYH6NSJD2) has the official IBM response.&lt;p&gt;&lt;a href="http://lekkimworld.com/2006/12/07/is_the_security_of_the_notes_domino_java_implementation_questionable_security_vulnerability_in_the_notes_domino_java_api.html"&gt;Read more...&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <category domain="http://lekkimworld.com/categories/java/">Java</category>
      <category domain="http://lekkimworld.com/categories/ibm_products/">IBM</category>
      <category domain="http://lekkimworld.com/tags/domino/">domino</category>
      <category domain="http://lekkimworld.com/tags/java/">java</category>
      <category domain="http://lekkimworld.com/tags/security/">security</category>
      <category domain="http://lekkimworld.com/tags/vulnerability/">vulnerability</category>
      <pubDate>Thu, 07 Dec 2006 11:14:47 GMT</pubDate>
      <guid isPermaLink="false">tag:lekkimworld.com,2006-12-07:default/1165490087755</guid>
      <dc:date>2006-12-07T11:14:47Z</dc:date>
    </item>
    <item>
      <title>Potential IBM Lotus Notes information leakage on port 1352</title>
      <link>http://lekkimworld.com/2006/11/08/potential_ibm_lotus_notes_information_leakage_on_port_1352.html</link>
      <content:encoded>Saw a technote on the Lotus Domino Support RSS feed on some &lt;u&gt;potential&lt;/u&gt; information leakage on the Notes/Domino port (1352). Interesting as I cannot remember the last time I saw a security issue being reported in regard to the NRPC protocol. A fact that warms my security-conscientious heart.&lt;p&gt;&lt;a href="http://lekkimworld.com/2006/11/08/potential_ibm_lotus_notes_information_leakage_on_port_1352.html"&gt;Read more...&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <category domain="http://lekkimworld.com/categories/ibm_products/">IBM</category>
      <category domain="http://lekkimworld.com/tags/notes.ini/">notes.ini</category>
      <category domain="http://lekkimworld.com/tags/security/">security</category>
      <category domain="http://lekkimworld.com/tags/technote/">technote</category>
      <pubDate>Wed, 08 Nov 2006 21:53:39 GMT</pubDate>
      <guid isPermaLink="false">tag:lekkimworld.com,2006-11-08:default/1163022819393</guid>
      <dc:date>2006-11-08T21:53:39Z</dc:date>
    </item>
    <item>
      <title>Security threats of syndicated content</title>
      <link>http://lekkimworld.com/2006/08/07/security_threats_of_syndicated_content.html</link>
      <content:encoded>I guess it had to happen or will happen at some point that RSS is used as the vector to exploit some kind of security vulnerability.&lt;p&gt;&lt;a href="http://lekkimworld.com/2006/08/07/security_threats_of_syndicated_content.html"&gt;Read more...&lt;/a&gt;&lt;/p&gt;</content:encoded>
      <category domain="http://lekkimworld.com/tags/rss/">rss</category>
      <category domain="http://lekkimworld.com/tags/security/">security</category>
      <category domain="http://lekkimworld.com/tags/vulnerability/">vulnerability</category>
      <pubDate>Mon, 07 Aug 2006 09:01:02 GMT</pubDate>
      <guid isPermaLink="false">tag:lekkimworld.com,2006-08-07:default/1154941262001</guid>
      <dc:date>2006-08-07T09:01:02Z</dc:date>
    </item>
  </channel>
</rss>


