{"id":2468,"date":"2016-06-24T17:06:33","date_gmt":"2016-06-24T15:06:33","guid":{"rendered":"http:\/\/blog.novaknet.de\/?p=2468"},"modified":"2016-06-24T17:06:33","modified_gmt":"2016-06-24T15:06:33","slug":"push-ssl-x-certs-to-ibm-notes-client-prevent-cross-cert-dialog","status":"publish","type":"post","link":"https:\/\/blog.novaknet.de\/?p=2468","title":{"rendered":"Push SSL x-certs to IBM Notes Client (prevent cross-cert dialog)"},"content":{"rendered":"<p>If you connect the IBM Sametime meeting oder advanced server from the IBM Notes client (plug-in) through\u00a0<span style=\"color: #ff0000;\">secure connection<\/span> (SSL) &#8230;<\/p>\n<p><a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/2-2016-06-17_10-44-17.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2471\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/2-2016-06-17_10-44-17-300x95.png\" alt=\"2-2016-06-17_10-44-17\" width=\"300\" height=\"95\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/2-2016-06-17_10-44-17-300x95.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/2-2016-06-17_10-44-17.png 549w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&#8230; you will get a <span style=\"color: #ff0000;\"><em><strong>cross certificate warning<\/strong><\/em><\/span> within the Notes client.<\/p>\n<p><a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/1-2016-06-17_10-44-49.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2470\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/1-2016-06-17_10-44-49-300x210.png\" alt=\"1-2016-06-17_10-44-49\" width=\"300\" height=\"210\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/1-2016-06-17_10-44-49-300x210.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/1-2016-06-17_10-44-49.png 427w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>To <span style=\"color: #0000ff;\">prevent this annoying dialog<\/span> within the IBM Notes client you can <span style=\"color: #ff0000;\">push this x-certs<\/span> to all IBM Notes client through the IBM Domino <span style=\"color: #0000ff;\">policy<\/span>.<\/p>\n<ol>\n<li>Configure\u00a0a secure (SSL) connection from your IBM Notes client (administrator) to the IBM Sametime meeting (or advanced) server<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/2-2016-06-17_10-44-17.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2471\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/2-2016-06-17_10-44-17-300x95.png\" alt=\"2-2016-06-17_10-44-17\" width=\"300\" height=\"95\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/2-2016-06-17_10-44-17-300x95.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/2-2016-06-17_10-44-17.png 549w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/li>\n<li>After you connect the first time to the IBM Sametime meeting server you should get a cross-certificate window<br \/>\n<span style=\"color: #ff0000;\">! DO NOT<\/span> automatically accept it.<br \/>\nYou need to change the fields to save the cross-certificate to your central domino address book (names.nsf).<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/3-2016-06-17_10-44-49.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2472\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/3-2016-06-17_10-44-49-300x208.png\" alt=\"3-2016-06-17_10-44-49\" width=\"300\" height=\"208\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/3-2016-06-17_10-44-49-300x208.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/3-2016-06-17_10-44-49.png 429w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><br \/>\n<\/a><span style=\"color: #808000;\"><em>NOTE: If you do not get the cross-certificate window, please check your local address book for already accepted x-certs and delete the concerning document.<\/em><\/span><\/li>\n<li>In the field &#8222;<span style=\"color: #0000ff;\"><strong>certifier<\/strong><\/span>&#8220; select your IBM Domino <span style=\"color: #0000ff;\">organization id<\/span> (e.g. \/edcom\/de)<br \/>\nIn the field &#8222;<span style=\"color: #0000ff;\"><strong>server<\/strong><\/span>&#8220; select your IBM Domino administration <span style=\"color: #0000ff;\">server<\/span> (could be any other Domino server who helds the names.nsf)<br \/>\nIn the field &#8222;<span style=\"color: #0000ff;\"><strong>subject name<\/strong><\/span>&#8220; select either the Sametime Meeting Server certificate or the <span style=\"color: #0000ff;\">&#8222;trusted root&#8220; authority<\/span><br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/4-2016-06-17_10-45-45.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2474\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/4-2016-06-17_10-45-45-300x195.png\" alt=\"4-2016-06-17_10-45-45\" width=\"300\" height=\"195\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/4-2016-06-17_10-45-45-300x195.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/4-2016-06-17_10-45-45.png 726w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/li>\n<li>Click &#8222;<span style=\"color: #0000ff;\"><strong>cross certify<\/strong><\/span>&#8220; to save the cross-certificate between<em><span style=\"color: #ff0000;\"> IBM Domino organization &lt;&gt; Sametime server &#8222;trusted root&#8220;<\/span><\/em> into your central IBM domino directory (names.nsf)<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/5-2016-06-17_10-46-26.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2475\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/5-2016-06-17_10-46-26-300x173.png\" alt=\"5-2016-06-17_10-46-26\" width=\"300\" height=\"173\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/5-2016-06-17_10-46-26-300x173.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/5-2016-06-17_10-46-26.png 765w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/li>\n<li>Create or edit an IBM Domino policy \u00a0&#8211; <strong><span style=\"color: #0000ff;\">security setting<\/span><\/strong>\u00a0document and switch to<br \/>\n&gt;&gt; tab &#8222;<strong><span style=\"color: #0000ff;\">keys and certificate<\/span><\/strong>&#8220; &gt;&gt; section &#8222;<span style=\"color: #0000ff;\"><strong>administrative trust defaults<\/strong><\/span>&#8220; and press the button &#8222;<span style=\"color: #0000ff;\"><strong>Update Links<\/strong><\/span>&#8220; &#8230;<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/7-2016-06-17_10-46-59.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2477\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/7-2016-06-17_10-46-59-300x200.png\" alt=\"7-2016-06-17_10-46-59\" width=\"300\" height=\"200\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/7-2016-06-17_10-46-59-300x200.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/7-2016-06-17_10-46-59.png 720w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><br \/>\n<\/a>&#8230; and select the cross-certificate you created before<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/6-2016-06-17_10-47-36.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2476\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/6-2016-06-17_10-47-36-300x102.png\" alt=\"6-2016-06-17_10-47-36\" width=\"300\" height=\"102\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/6-2016-06-17_10-47-36-300x102.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/6-2016-06-17_10-47-36.png 724w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/li>\n<li>After the next login from the IBM Notes client, the cross-certificate from the IBM Domino policy security document was saved to the local address book in the view certificates<br \/>\n<a href=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/8-2016-06-17_10-58-05.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-2478\" src=\"http:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/8-2016-06-17_10-58-05-300x95.png\" alt=\"8-2016-06-17_10-58-05\" width=\"300\" height=\"95\" srcset=\"https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/8-2016-06-17_10-58-05-300x95.png 300w, https:\/\/blog.novaknet.de\/wp-content\/uploads\/2016\/06\/8-2016-06-17_10-58-05.png 757w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/li>\n<\/ol>\n<p>Thats it<\/p>\n<p>BTW &#8211; you could also use this documentation to push\u00a0x-certs between\u00a0DomOrg &lt;&gt; DomOrg to IBM Notes clients<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you connect the IBM Sametime meeting oder advanced server from the IBM Notes client (plug-in) through\u00a0secure connection (SSL) &#8230; &#8230; you will get a cross certificate warning within the Notes client. To prevent this annoying dialog within the IBM Notes client you can push this x-certs to all IBM Notes client through the IBM [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,101],"tags":[],"class_list":["post-2468","post","type-post","status-publish","format-standard","hentry","category-nd","category-sametime"],"_links":{"self":[{"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/posts\/2468"}],"collection":[{"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2468"}],"version-history":[{"count":4,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/posts\/2468\/revisions"}],"predecessor-version":[{"id":2481,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=\/wp\/v2\/posts\/2468\/revisions\/2481"}],"wp:attachment":[{"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2468"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2468"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.novaknet.de\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2468"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}