fighting for truth, justice, and a kick-butt lotus notes experience.

Fixes for IBM Notes and Domino regarding POODLE and SHA-2 available

 November 4 2014 08:20:14 AM
IBM has released interim fixes for IBM Notes and Domino 8.5.x and for 9.0.x tonight that address the POODLE SSL3/TLS1.0 and SHA-2 issues.

The fixes are available for all supported platforms and releases (9.0.1 FP2, 9.0, 8.5.3 FP6, 8.5.2 FP4, 8.5.1 FP5).
But you should be aware that SHA-2 support is only available for Domino 9.0.x.  

You can find the common description here which include reference links for the downloads.

This document describes the usage of the keyring file in that context.

Looking for further information? Go here.

If you are using SSL on your servers the installation is recommended! But I would wait to install it on production systems for a few days, after we all will have received some feedbacks. It it not always good to be the first one ;-)

Thanks to IBM and specially to Dave Kern,  who did a great job in a very short time!
The security team at IBM had been already working on TLS and SHA-2 support before POODLE came up, but had to change their plans (which was 9.0.2 as the target release), because of the short term move to diable SSL 3.0 in browsers and other software.

Dave, thank you very much to make this possible!

PS: Hope TLS v1.2 will be available soon, too.


Added Download Links:



1Jürgen Dohrmann  11/04/2014 1:38:38 PM  Fixes for IBM Notes and Domino regarding POODLE and SHA-2 available

Bei mir führt der Link ins Leere:

The requested URL /sar/CMA/LOA/04v9m/0/853FP6HF1024_W32.exe was not found on this server.

Wir benötigen den FP dringend.


2Ensar Yilmaz  11/05/2014 3:02:06 PM  Fixes for IBM Notes and Domino regarding POODLE and SHA-2 available

Nachfolgend der Link zu dem Fix (falls noch nicht gefunden):

{ Link }

  • Hinweis zum Datenschutz und Datennutzung:
    Bitte lesen Sie unseren Hinweis zum Datenschutz bevor Sie hier einen Kommentar erstellen.
    Zur Erstellung eines Kommentar werden folgende Daten benötigt:
    - Name
    - Mailadresse
    Der Name kann auch ein Nickname/Pseudonym sein und wird hier auf diesem Blog zu Ihrem Kommentar angezeigt. Die Email-Adresse dient im Fall einer inhaltlichen Unklarheit Ihres Kommentars für persönliche Rückfragen durch mich, Detlev Pöttgen.
    Sowohl Ihr Name als auch Ihre Mailadresse werden nicht für andere Zwecke (Stichwort: Werbung) verwendet und auch nicht an Dritte übermittelt.
    Ihr Kommentar inkl. Ihrer übermittelten Kontaktdaten kann jederzeit auf Ihren Wunsch hin wieder gelöscht werden. Senden Sie in diesem Fall bitte eine Mail an blog(a)poettgen(punkt)eu

  • Note on data protection and data usage:
    Please read our Notes on Data Protection before posting a comment here.
    The following data is required to create a comment:
    - Name
    - Mail address
    The name can also be a nickname/pseudonym and will be displayed here on this blog with your comment. The email address will be used for personal questions by me, Detlev Pöttgen, in the event that the content of your comment is unclear.
    Neither your name nor your e-mail address will be used for any other purposes (like advertising) and will not be passed on to third parties.
    Your comment including your transmitted contact data can be deleted at any time on your request. In this case please send an email to blog(a)poettgen(dot)eu