Solved

How secure is Lotus Notes "digital signature"?

Posted on 2006-06-14
5
1,276 Views
Last Modified: 2013-12-18
How secure is Lotus Notes "digital signature"?
Like how does it compare to other digital signature technologies?
Don't know much about them, but "X.509" is one example.
0
Comment
Question by:wsfindlater
  • 2
  • 2
5 Comments
 
LVL 63

Assisted Solution

by:SysExpert
SysExpert earned 200 total points
ID: 16908121
It is 128 bit I think in R6 and above,  using Public/Private keys, so it should e extremely secure and satisfy all  US Govt. regulations.

Domino also supports X.500 partially.

I would check the IBM site for more detailed info.

I hope this helps !
0
 
LVL 46

Accepted Solution

by:
Sjef Bosman earned 250 total points
ID: 16909286
0
 
LVL 15

Assisted Solution

by:bpmurray
bpmurray earned 50 total points
ID: 16913092
It uses standard digital signatures from Verisign and other companies, so they're as safe and secure as any.
0
 
LVL 46

Expert Comment

by:Sjef Bosman
ID: 16913338
Verisign, that's for SSL, but it's not used for Notes's internal security. Red the Readbook...

1.2.2 Support for larger keys in Notes and Domino 7

As computing power increases, so does the need to extend key lengths to protect against brute force attacks.

In Release 6.0, Notes and Domino can use 1024-bit RSA keys, but cannot not generate them, and can use 128-bit RC4 keys, but cannot use 128-bit RC2 keys. With the advent of 6.0.4 and 6.5.1, Notes and Domino continued to use 1024-bit RSA but can now use 128-bit RC2 keys (however, Notes and Domino cannot generate these RC2 keys).

In Release 7.0, enhancements in Notes and Domino permit 1024-bit RSA keys to be used and generated. In addition, 128-bit RC2 keys can also be used and generated, and there is underlying support for 2048-bit RSA keys.

To help with implementing larger keys, we use key rollover, the process used to update the set of Notes public and private keys that is stored in user and server ID files. Use this to periodically replace this set of keys as a precaution against undetected compromise of the private key, as a remedy to recover from a known compromise of the private key, to increase security by updating to a larger key.
0
 
LVL 15

Expert Comment

by:bpmurray
ID: 16913391
I meant for external security - the traditional use of "digital signature" as sent across the web, rather than the internal stuff. As it says in that quote, the RC2 keys are from external certificates, like Verisign.
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

For users on the Lotus Notes 8 Standard client, this article provides information on checking the Java Heap size and adjusting it to half of your system RAM in attempt to get the Lotus Notes 8.x Standard client to run faster.  I've had to exercise t…
You’ve got a lotus Domino web server, and you have been told that “leverage browser caching” is a must do. This means that we have to tell the browser everywhere in the web to use cache. In other words, we set (and send) an expiration date in the HT…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now