05/17/2010

notes and SSL VPN from cyberoam

Category inotes
Hi all,

I am trying to deploy lotus inotes to my users.

So we used a cyberoam ssl vpn that do redirection to lotus inotes (iwaredir).

The cyberoam ssl vpn does work well and show me my server redirection: http://192.168.x.x wich is the lotus domino server with inotes.

in inotes web redirect, (iwaredir.nsf), we set the redirection to resolved and set the servername to http://192.168.x.x

if i try this localy, everything is working: http://192.168.x.x show me the iwaredir.nsf redirection, then my mailbox. (we are using web site rule to map 192.168.x.x to 192.168.x.x/iwaredir.nsf)

if i try this through the ssl vpn, the cyberoam rewrite the url to something like: https://server.cyberoam.name/corporate/CRSSL/http/192.168.x.x/iwaredir.nsf

and the iwaredir.nsf show well then....blank page when it has to load: https://server.cyberoam.name/corporate/CRSSL/http/192.168.x.x/mail/mymail.nsf?OpenDatabase.

but this is not really a blank page. If i look in the source of the page, there are some code in it with many url rewritting.

I do not really know what to set to make it work with ssl vpn.

it seems that inotes does not like url rewritting.

Maybe there is aconfiguration to do for proxy redirection on inotes...

01/25/2010

Archive Folder under notes 8.5.1

Category
So many things to do and so few time....

Last time i blogged was about a crash problem on a domino server, and the problem is still the same.

So now, i will ask some help about a little detail:

i've always used the Archive Folder under lotus notes.

If you use the folder settings and if you create a folder wich name is "Archive", you can just put your mails in this folder and they will automaticaly be copied in your archive database. A magic Folder, or sort of.

but since 8.5.1, i've not used it and today, i try it again.

And now, the magic folder "Archive" does not work anymore, this is just a folder like other.

So what could happened ? Is 8.5.1 disabling this feature, or is this just a bug ?

11/20/2009

More on JVM crashing Domino

Category domino jvm crash
Hi all,

i'm back on my long problem about the JVM crashing the server (http://lotus.bluegeek.fr/web/bluegeek.nsf/d6plinks/BMAI-7PDE76)

I decided to reinstall windows server 2003 R2 +SP2 and then domino 8.5.1 +LP FR.

so i retested to enable JVM and boot domino and...crash !

as always: few informations on the nsd log, but one time i got this:

############################################################
### FATAL THREAD 1/9 [   nhttp:  0734:  0744]
### FP=0x0013a300, PC=0x0826ffff, SP=0x00187390
### stkbase=00190000, total stksize=1048576, used stksize=35952
### EAX=0x10068550, EBX=0x00000025, ECX=0x5a208005, EDX=0x10068550
### ESI=0x0815002d, EDI=0x1016d15c, CS=0x0000001b, SS=0x00000023
### DS=0x00000023, ES=0x00000023, FS=0x0000003b, GS=0x00000000 Flags=0x00210282
Exception code: c0000005 (ACCESS_VIOLATION)
############################################################

############################################################
### PASS 2 : FATAL THREAD with STACK FRAMES 1/9 [   nhttp:  0734:  0744]
### FP=0013a300, PC=0826ffff, SP=00187390
### stkbase=00190000, total stksize=1048576, used stksize=35952
Exception code: c0000005 (ACCESS_VIOLATION)
############################################################



Ok, an access violation, but where, with which software ?

Even IBM support does not found.

so i googled all taht again to find that my server (dedibox V1) run on a Via C7 processor with padlock.

I found something interesting when i've tried to start the server with the controller and the java console.

the server did not start, but three new files appeared in the data diretory.

One of this file (javacore.xxxxxxx....txt) contain that:

2XHCPUS        Processors -
3XHCPUARCH       Architecture   : x86
3XHNUMCPUS       How Many       : 1
3XHNUMASUP       NUMA is either not supported or has been disabled by user

what is NUMA ?

well, google answer me that is the Non Uniform Memory Access and that is a part of AMD multi core processors.
Nothing to do with me as the C7 has one core.

digging more deeply, i ended to find that: http://www-01.ibm.com/support/docview.wss?uid=swg21267793

where the article talk about the fact that on some hardware where numa is enabled, domino could crash and that we need to enable the /usepmtimer on the boot.ini of windows to use the he Windows operating system to use the PM_TIMER, rather than the Time Stamp Counter.

I was just wondering what's the impact on my domino server date if i try this option ?

11/12/2009

Domino and Notes 8.5.1 French available

Category domino notes 8.5.1
After all, the so called Domino 8.5.1 and lotus notes 8.5.1 are available in french from passport advantage. In fact, i were able to download Lotus_Designer_Adm851_Win_FR_CZ90QFR.exe, traveler 8.5.1 multilingual and even lots client 8.5.1 fr alone, but impossbile to download The French Language Pack for domino 8.5.1, download director saying me the file does not exists on the server (even http download does not work).

IBM, please, do some thing on your website:
1. test files you put on it.
2. please, please, please, do something to make it a little faster, please ! 10 minutes just to search for a file...a bit long to me.

i've just finished to install notes, admin and designer 8.5.1 and here is what i can say:

8.5.1 does not really start faster than 8.5. I can not see where people have seen more speed during starting (ho, and the installation just take one hour or so...)
icons are now staying at their place. (just need to re install notesfix and docinfo to get the icons.)
i can change the unread color.

Designer: i'm in love with lotusscript editor for coloring.

so, i'm just searching for a good package of
IBM Lotus Domino 8.5.1 Language Pack for Windows 2003, 2008 and IBM Power Systems French(CZ93UFR) as the file can not be downloaded via passport advantage.

ho, and more to come on Lotus protector i'm testing (i give it a try) for a week now.

10/27/2009

passportadvantage down ?

Category
hi all,

is it me or passportadvantage does not respond to my request since this morning ?

10/22/2009

domino 8.5 (or 8.5.1),traveler, quickr and sametime on the same server ?

Category domino 8.5 quickr sametime traveler
Hi all.

Recently, i've upgraded our production server to 8.5 fp1. As soon as the french LP is here, i will upgrade to 8.5.1.

I've already installed traveler which work very well with our phones (nokia essentially).

But as many of you have notices, IBM is 'offering' us many product at no charge with new version of domino: Quicr Entry, Sametime Entry and traveler.

Well, at no charge ? really ?
i.e: everywhere i found that it is recommended to install sametime on its own server, same thing for traveler or quickr.

do i really need three servers (and of course three licences..) just to use traveler, sametime and quickr on my simple, 40 users organisation ?

I've done the test to install quickr entry on a french domino 8.5 fp1, just after installing traveler, and quickr refuse to install saying me that a quickr installation already exist in lotus program folder.
(maybe because i'm trying to use a partitionned server...)

Does someone already installed all this products together, on the same server ?
Where can we found documentation on combining all these products ?

One more thing: Is a 64 bits version of all this products will be launched ?

09/23/2009

Working with V8.5 now

Category 8.5
I'm working with 8.5 since a few days now and here is what i can say:

Pros:
Great UI, a real refresh if you're used to work with 6.5 or 7. This UI only available on the full eclipse client but for many computer it will be good.
I love the plugins or widgets. Currently using : twitnotes and openntf recent (but does not work since i upgrade the 8.0.2 client to 8.5 fp1). I use Activities too (with a connection to bleedyellow).
other things will follow.

Cons: (in fact bugs i hope)
The Quota bar does not always appears:
A picture named M2
(here you can see my old 6.5.4 on the old server, design 6.5)
Same thing on a 8.5 mail file (ods 51) on a 8.5fp1 server.

Icons were boring me (they appear and disappear when i open a mail, a view,...), changing the height of the toolbar constantly, until i unchecked the first line:
A picture named M3

and now, all my toolbars always appear.
Html emails: So slow to open...more than 4 minutes sometimes. (a quick tips: check "do not use embedded browser for mime emails"). Internet explorer fault or lotus fault ?
A picture named M4

many things will follow.

Designer:
Well, so many things to learn again before being able to use what seems to be a great tool.
Actually trying to deal with Xpage, but i'm lost....



09/22/2009

Dojo on Domino: Where do we find documentation ?

Category domino 8 dojo 1.1.1

Hi all,

I'm currently looking at using the integrated dojo toolkit shipped with domino 8.5.

By the past, i've played with an old dojo toolkit to get datas from a view on domino.

Now, i'm trying to reuse this old code to diplay some Calendar view (from mail files) on a unique web page, with possibility to create entries, change date, ....

But of course, old code is not reusable (the dojo.io.bind does not seems to work with dojo 1.1.1)

So here is a question:
What can i do with dojo 1.1.1, shipped with domino 8.5 ?
Is there a documentation on this dojo toolkit, some exemples to give it a try.
How can i get a Calendar view an display it with a beautiful css, xsl and so on...no exemple ?

For now, i've tried the XML/XSLT approach, without sucess, the json approach (with dojo but i'm lost with 1.1.1) and even the simple iframe approach (display the view, but very awful and unusuable)

Cheers

07/21/2009

Connection attempted on Organisation, but not configured in POP3 Internet Site Document

Category domino pop3
Hi all.

Last week, i decided to take a look at an old problem on my 6.5.4 fp3 domino.

Some time ago, i needed to enable internet site document to play with web site.

Of course, we use smtp and pop3 on this server, so i needed to create internet site documents for smtp and pop3.

If smtp is running well with internet site document enabled, the pop3 server refuse to answer my requests, saying: "Connection attempted on <Organisation>, but not configured in POP3 Internet Site Document"

This problem was old and i found some new things last week:

http://www-01.ibm.com/support/docview.wss?uid=swg21199698 and http://chris-linfoot.net/d6plinks/CWLT-6EVC8Z  show me the way.

In fact, i were not using ip address in the internet site document for pop3, so i checked that and put the local ip address of my server in it.

Then i restarted the pop3 task and the http task to see the result.

And ...Magic...pop3 started to answer my requests.

But today, after the sever restarted during the week end, pop3 still say:"Connection attempted on <Organisation>, but not configured in POP3 Internet Site Document"

All i can do now is to disable the loading of internet site documents on the default document server.

i opened a pmr to lotus as i do not know what to do next.

Edit and solution with read more...
Read More

07/03/2009

SlowLoris can down your domino server

Category apache domino web attack

If you have not heard about SlowLoris and other HTTP DOS tools, it's time to listen

All version of Apache server are vulnerable by this http dos attack.

very simple to experiment, just a few commands to get the tool and test against any webserver.

For my first test, i have attacked my webserver, a simple apache2 server, listening on the default 80 port.

3 seconds later, the site became unavailable.

The only informations i found against this is:
Mod_antiloris which is a mod for apache. --> this was not working for me, maybe a bad config.
A reverse proxy (not apache based of course) in front of apache. --> the only real solution for the moment, plus it can help to create High availaible service.

After installing the reverse proxy, i decided to test slowloris against my domino server.
3 seconds later, the domino web server became very long to answer but continue to serve page (very slowly)


So i can advice you to check you apache and domino server and put a reverse proxy in front of them.
more info here: http://ha.ckers.org/blog/20090617/slowloris-http-dos/