Greetings!
As luck would have it, I’m once again called into battle with military security folks. The battle is not one of violence (not yet anyway… I suspect they want to kill me already!), but we go around and around over various security issues. The “ammo” that the security folks use, is largely based on heresy and misconceptions (due to a flailing Microsoft bias I think).
One misconception that they had was that NRPC = RPC. RPC is hardly secure and doesn’t even deserve to be in the same category as NRPC! I wish the Lotus folks hadn’t used a moniker so similar… that was a battle unto itself!
Now, the reason that I am appealing to all my friends, peers, associates and cohorts here on the forum… I need ammo!
After a great many rounds of my detailed explanations of how the entire Notes/Domino infrastructure works, they left me with this… “we can’t take your word for it.” So, now I am looking for all of the security-related “documented” features and vulnerabilties known to ND6.5.1.
I am not looking for “opinion” pieces, but truly documented facts. And, I don’t want just one reference, I want all I can get! Nothing is too small or insignificant! Post links to ANYTHING and EVERYTHING!
And, yes, you did hear me right… I want ALL vulnerabilities too! Especially this. My experience/perception of any known vulnerabilities is that for the most part there aren’t any, but those that had surfaced in the more recent past were either quickly fixed (via updates), or that the vulnerabilities have just been minor nuisances that have gotten severely blown out of proportion. I even had a personal experience with the NSA doing their own hack testing, because we wanted to put Domino into a secure environment… needless to say, that their best effort only resulted in crashing the box (NEVER compromising the data).
I figure to take the vulnerability info and either explain how the issues are either bogus in our environment, or to show how the issues have been addressed by subsequent releases (let’s start off with version 6.0… this much they will surely understand).
It is important to note, that this seemingly innocuous request for info has the potential for helping Notes/Domino to gain more ground within more government and military environments. If you’re like me, you just love to see Notes/Domino further proliferating!
On the other hand, there are some pretty significant people looking at our Notes/Domino solutions, and the misguided actions of these security folks WILL cause these big-wigs to look elsewhere for solutions.
I appreciate ALL of your insight and input!
-D
PS- I already supplied these security folks with the Domino Security Redbook, but I scarcely think that anyone has even looked at it. I’ve got the thankless task of breaking each any every little issue/solution into individual bullet points… ugh! This has already taken years off my life in stress alone!! ALL links, facts, references are so very welcome!!