Blackberry PROFESSIONAL SOFTWARE FOR IBM LOTUS DOMINO - - RELEASE NOTES Guide de l'utilisateur Page 170

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 210
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 169
IBM Lotus Notes, Domino, Domino Designer 8 Release Notes
Lotus Notes
Problems using Entrust certificates on smartcards
When using pre-loaded certificates and keys stored on smartcards, Notes/Domino follows the "PKCS#11:
Conformance Profile Specification" for RSA Asymmetric Client Signing, which specifies a set of attributes
that must be in the keys and certificates, and a set of functionality that must be supported by the
smartcard and smartcard software. In particular:
"A unique non-null CKA
_
ID value exists and has proper associations for all keys and certificates."
Some certificate authorities, including a number of Entrust CAs, may generate certificates and keys that
contain a null (zero-length) CKA
_
ID attribute. This bug has been reported to Entrust, where it is being
tracked as "SR 1-44960142". Future releases of these Entrust CAs may fix this problem.
Attempting to import these certificates with Notes clients before 7.0.1 will result in an "Illegal null
parameter passed to security function" error.
A workaround has been added to 7.0.1 and this beta release to find, import, and use these noncompliant
certificates and keys, with several caveats:
z
The first import attempt will only find and import compliant certificates and keys. Subsequent imports
will find and import noncompliant certificates of this type, if any private RSA keys with a null CKA
_
ID
attribute were noticed during the first import attempt.
z
The ID file must be smartcard-enabled; the mode of operation added in 7.0 to allow certificates to be
imported and used without first smartcard-enabling the ID file cannot be used with these certificates
and keys.
z
The "Lock ID with Key on Smartcard" functionality is not available when using these noncompliant
certificates and keys.
z
These non-compliant certificates must be imported in order to be used; the new functionality added to
7.02 and this beta release to allow use of certs without first performing an "Import Internet Certificate
from a Smartcard" action is not supported.
Lotus Notes
Unable to send encrypted MIME mail addressed to a group
For a group of users who use MIME (in the user's person document "Format Preference for incoming mail
= Prefers MIME" ia set), some users are set up to read their mail from browsers, and some from a Notes
client.
If you send an unsigned, unencrypted mail to a group containing these MIME users, the mail is received
by all users.
159
Vue de la page 169
1 2 ... 165 166 167 168 169 170 171 172 173 174 175 ... 209 210

Commentaires sur ces manuels

Pas de commentaire