HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 4.122 Configuration for browser access to Lotus Notes

S 4.122 Configuration for browser access to Lotus Notes

Initiation responsibility: Head of IT Section, IT Security Management

Implementation responsibility: Administrator

If browser access to a Lotus Domino server is to be allowed, then a reasonable level of security must be guaranteed for this type of access also.

To protect browser-based access, the following recommendations, which affect server, client and their communication mechanisms, should be implemented:

  1. All accesses which require authentication should be protected with SSL (see S 4.124 Configuration of authentication mechanisms with browser access to Lotus Notes).
  1. Browsers which support the SSL protocol must be used (see S 4.127 Secure configuration of browser access to Lotus Notes). The browser should support strong encryption, i.e. algorithms with a minimum 80 bit key length.
  1. The Domino server must be configured for SSL-protected Web access (see S 4.123 Configuration of SSL-protected browser access to Lotus Notes). To ensure that encryption is strong, at least version 5.0.4 of Domino Server should be used.
  1. Access restrictions should be configured at database level also (see S 4.125 Instituting restrictions on access to Lotus Notes databases with browser access).

If Web access to a Notes system is planned, then the following additional security-relevant aspects must be considered:

Additional controls:


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
last update:
July 2001
home