My.ADVISOR.com Sign-In
ID
Password

Member Center / Sign-Up
   
SUBSCRIPTION STATUS
If you are a subscriber to this publication, sign-in to access locked articles. To subscribe or renew go to www.AdvisorStore.com.
Go to Article
Advanced Search 

ADMINISTRATION

Cool IBM Lotus Notes 8 Admin Features

Discover three features that can help you control Web logins, get users to a database you've moved, and prevent the wrong e-mail from reaching its destination.

By Terrance A. Crow, Corporate One assistant vice president of technology and Lotus Advisor technical editor


The Notes 8 beta 2 release contains so many glamorous functions -- a beautiful new user interface and a cross-platform development framework, to name a few -- that it's easy to overlook some real gems in the administrative space. Three features in particular offer some real relief to issues that have plagued administrators for years. One feature introduces greater security for users logging into Domino Web applications. Another makes it easier to manage hard drive space while insulating users from the impact of that management. The last feature helps protect users from, well, their own tempers! There are many other administrative upgrades, but these are the ones that caught my attention.

Figure 1: Enable lockouts -- The Configuration document holds the key to enabling Internet Password lockouts.



Figure 2: Lockout reporting -- INetLockout.nsf holds the record of invalid attempts and lockouts.

Three strikes


Domino has a well-deserved reputation as a secure platform. In that context, it's surprising that Domino has been missing the ability to offer features such as Internet ID locking after some number of unsuccessful login attempts. For some of us, the issue was so serious that we had to resort to writing our own solutions (click to see my article "Track Invalid Web-based Login Attempts"). Fortunately, in the beta 2 release, Notes 8 includes the new "Enforce Internet Password Lockout" feature. I can finally retire my convoluted workaround!

Enabling the function is easy. From the Domino Administrator, navigate to the Configuration Tab and expand the Server and Configurations nodes. My server is called ohcmhsrv009, and there was already a configuration present for it. If the server on which you want to enforce lockouts isn't listed, just create a configuration document.

After you're in the configuration document, go to the Security tab. You should see a screen that looks like figure 1. The kinds of features you need to adequately secure your Web logins are there. You can control what you log: failures or attempts and failures. You can control the maximum number of attempts before the system locks the ID. You can set the field to configure how long the lock will hold (i.e., how long before the lock expires) in minutes, hours, or days -- the default is 0, which presumably is never -- an admin would have to unlock it. Finally, you can configure the interval for counting strikes. The default is one day, so the user can try to log in three times in one day before getting locked out.

After you've configured it, the server logs invalid attempts in the Domino console and in a new NSF called INetLockout.nsf. The Domino server creates this database in the data directory's root after you configure the system to log invalid attempts. That database has decent tracking features, and you can perform basic audits based on its functionality. Figure 2 shows an example of what three strikes looks like. Its two views let you quickly and easily see invalid login attempts and lockouts.

This is a beta release, and I expected some unusual behaviors. For example, in its current incarnation, Domino's lockout feature only logs invalid attempts and it only locks out IDs that use the full name to log in. For example, if I use Terry Crow to try to log into Names.nsf three times, the system locks my ID. However, if I use tcrow, I can try to log in forever. Domino logs the attempt on the console, but never in INetLogout.nsf. I've reported the issue to IBM Lotus on its beta Web site.

Another unusual behavior is that to unlock the ID, you have to delete the document in INetLockout.nsf. That means you lose your audit trail! IBM Lotus responded to my beta forum question about this issue in a way that suggests it was interested in finding a solution, and even offered a workaround: Change the INetLockout template so documents don't really get deleted; just move the document to an audit view. The key seems to be that if a document's on the "Locked Out Users" view, Domino considers the ID locked (based on the parameters you set in the Server Configuration document).

Terrance CrowTechnical Editor Terrance A. Crow is the assistant vice president of technology at Corporate One, a corporate credit union in Ohio. He has been a Lotus Notes developer since the 3.x days under OS/2 and now uses Lotus Notes/Domino to build client-server and Web e-commerce solutions. He's also busily building solutions based on open source-based tools.

More importantly, he's married to a genius genealogist and is the father of a son just got his driver's license and a daughter who is mastering music when she isn't writing books. terrance@interstell.com. terrance@interstell.com.

Printer-friendly
page layout

What do YOU think about this topic? Share your advice and thoughts using this form.

Your Name

REQUIRED : PUBLIC

Your E-Mail

REQUIRED : PRIVATE

Job, Company

OPTIONAL : PUBLIC

City, State, Country

OPTIONAL : PUBLIC

Your Web Site

OPTIONAL : PUBLIC

Your Comment

Please help everyone by keeping your comments on-topic, using clean language, and not defaming or making personal attacks.


Your e-mail address is required, but it will not be displayed to the public or given to anyone. See our Privacy Policy. Comments become visible after they pass our spam filter, and spammers and abusers are permanently blocked. Please report spam or abuse.

ARTICLE INFO

Web Edition: 2007 Week 16, Doc #18971

FREE ACCESS FREE ACCESS

Keyword Tags: application development, collaboration, development, E-Mail, ibm, ibm lotus, ibm websphere, it administration, it networking, IBM, IBM Lotus, IBM Lotus Notes, messaging, microsoft windows, security, Tech Administration

Use of this or any other site, content, product or service of Advisor Media constitutes acceptance of Terms of Use.
Portions copyright ©1983-2010 Advisor Media, LLC. All Rights Reserved.
Reuse or reproduction of any portion or quantity of Advisor Media's copyrighted content, in any form, for any purpose, requires written permission.
ADVISOR®, the ADVISOR logo, and other names and logos that incorporate ADVISOR are registered trademarks, trademarks or service marks of Advisor Media, LLC in the United States and/or other countries.
Other trademarks are used for identification, editorial or descriptive purposes and are the property of their owners.
Hosted by Prominic.NET Website powered by
LOTUS SOFTWARE
ztiblt0706 CROWT148 posted 2007-4-16 mod 03/08/2010 03:10:44 AM ztdbms/ztdbms
domino-144.advisor.com my.advisor.com 03/11/2010 10:06:27 AM