Lotus Notes、ID 文件以及新版本(8 及更高版本)中的变化

发布于 2024-07-08 21:19:32 字数 799 浏览 7 评论 0原文

对于那些不知道的人来说,Lotus Notes是一个很酷的系统,它具有非常强大的数据库复制能力,以及非常强大的证书管理和签名。

然而,强大的证书使用本身就是 Notes 的缺点之一。

当您通过 Notes 客户端登录到 Lotus Notes 时,您使用的密码不会存储在任何地方,除非作为存储在本地工作站上的 Notes ID 文件中的私钥的加密/解密密钥。

这意味着您可以拥有该文件的 15 个副本,其中包含 15 个不同的密码,并且只要您拥有匹配的密码,每个副本都是有效的。

对于身份管理系统来说,这是相当严重的,因为没有服务器端组件来访问密码更改事件,而是完全基于客户端,并且服务器几乎无法告诉它发生了!

我听到的传言是,在 Lotus Notes/Domino 的后续版本中,这种基于 ID 文件的身份验证开始发生变化。

我很难找到关于更改内容、更改方式以及版本的明确解释。 (8.5?9?稍后?)

这个问题的第二部分是,Active Directory 集成方面发生了什么? 我听说有传言可能会允许 AD 身份验证而不是 ID 文件身份验证。 我对此的猜测是,存储在服务器上的 ID 文件仍将用于授权,但成功的 Active Directory 身份验证将用于解锁对其的访问? 或者是其他型号?

寻找已经弄清楚这一点的人的观点!

附带说明一下,访问 Notes 的 Webmail 时会使用第二个密码 (httpPassword),因为当用户进行身份验证时,服务器当然无法访问本地 ID 文件。 人们假设这是他们将转向其他形式的身份验证的模型,但众所周知,假设是一个糟糕的计划!

For those who are not aware, Lotus Notes is a cool system, which has very powerful database replication abilities, and very strong certificate management and signing.

However that strong certificate usage is itself one of Notes's downfalls.

When you log in to Lotus Notes via a Notes client, the password you use is not stored anywhere, except as the encrypt/decrypt key to the Private Key stored in the Notes ID file on your local workstation.

What this means is that you can have 15 copies of this file, with 15 different passwords, and each one is valid, as long as you have the matching password.

For Identity Management systems, this is pretty crippling, as there is no server side component to access the password change event, rather it is entirely client based, and the server can barely even tell it happened!

The rumours I hear is that in later releases of Lotus Notes/Domino, this ID file based authentication is starting to change.

I am having trouble finding clear cut explanations for what is changing, how, and in what version. (8.5? 9? Later?)

Second part to this question is, what is happening in terms of Active Directory integration? I heard it rumoured that AD authentication might be allowed instead of ID file authentication. My guess on that aspect is that the ID file stored on the server will still be used for authorization, but the successful Active Directory authentication will be used to unlock access to it? Or is it some other model?

Looking for someones perspective who has figured this out already!

On a side note, there is a second password (httpPassword) that is used when Notes's Webmail is accessed, since of course the server has no access to the local ID file when the user authenticates. One assumes this is the model they would move to for other forms of authentication, but as we all know, assuming is a bad plan!

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(1

野生奥特曼 2024-07-15 21:19:32

Notes Domino 8.5 具有新的 ID Vault 功能。 它于一月初发布。

ID Vault 的工作原理是在服务器上安全地保存 ID 的副本。 然后,它根据需要向用户提供 ID。 这允许这样的配置:用户要求服务器重置密码,服务器在将 id 文件下载给用户之前对 id 文件进行更改。

有关 ID Vault 的更多信息,请访问:

管理 Notes 用户 ID 和密码的新方法 (dominoblog.com)

先睹为快 - Domino 8.5 id Vault (pmooney.net)

更新:8.5 已发布。

Notes Domino 8.5 has the new ID Vault feature. It was released in early January.

ID Vault works by keeping a copy of the id securely on the server. It then provisions the id on demand to the user. This allows for a configuration where the user asks the server to reset the password and the server makes the change to the id file before downloading it the the user.

More info on ID Vault here:

A New Way to Manage Notes User IDs and Passwords (dominoblog.com)

Sneak peak - the Domino 8.5 id vault (pmooney.net)

Updated: 8.5 has been released.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文