SSL ciphers
Many clients will not support older or more vulnerable SSL ciphers. These are generally not enabled on the HCL Domino server, but if a particular cipher needs to be disabled to avoid the clients from trying to use the cipher and encountering problems, the following procedures show how to disable them.
Procedure
- Use the Domino® Administrator client to open the server's public address book.
- In the navigator, select the Configuration tab,
then select .
- Click the Edit Server action.
- Select the Ports tab, then select Internet Ports.
- Set TCP/IP port status to: Enabled, Redirect to SSL should not be used.
- Under SSL authentication options, the Client Certificate field should be set to No.
- In the SSL settings section of the form, select the Modify button under the SSL ciphers item.
- In the SSL Cipher Settings dialog, deselect the ciphers to be disabled.
- Save your changes.
Alternate procedure
- Ciphers may also be disabled via the Internet Sites document.
If there is an Internet Site document for your server, open it.
- Click the Edit Web Site action.
- Select the Security tab.
- Under TCP Authentication options, the Redirect TCP to SSL field should be set to No.
- Under SSL authentication, the Client Certificate field should be set to No.
- Select
- In the SSL Cipher Settings dialog, deselect the ciphers to be disabled.
- Save your changes.