22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The manner in which the membership is built is simple and effective: the data for<br />

the people using the QuickPlace is entered in the form shown in Figure 12-1 and<br />

they are segregated into three groups (in increasing levels of access): Readers,<br />

Authors, Managers. In essence, it means that the Directory entries and the ACL<br />

entries are all handled in one place.<br />

QuickPlace incorporates Domino components in its architecture. Specifically, the<br />

Domino Web Server (nhttp.exe) provides the HTTP stack and the Domino URL<br />

processor (ninotes.dll) provides the semantics for processing Domino URLs.<br />

12.1.1 QuickPlace and SSL<br />

You can configure QuickPlace to use an SSL connection to encrypt the data<br />

transferred between Web browsers and a QuickPlace server. The SSL<br />

handshake is provided by the Domino Web server, so SSL must be configured<br />

first on Domino. Then you can set up QuickPlace to use SSL to secure LDAP<br />

communications between QuickPlace and the LDAP server, as well as HTTP<br />

between browser clients and place servers.<br />

Without SSL configured to the directory server, the information passed during the<br />

authentication process between the QuickPlace server and the Domino server<br />

will not be encrypted.<br />

You may also want to consider port encryption for TCP/IP and Notes protocols.<br />

Encrypting ports protects replication traffic between two QuickPlace servers. For<br />

more information on enabling port encryption on the Domino server, see the<br />

Domino 6 Administration help.<br />

12.1.2 User directories<br />

Important: If you configure QuickPlace to use SSL but have not configured<br />

Domino, SSL LDAP authentication will fail.<br />

A QuickPlace “place” can have both local users and external users. The specific<br />

difference between local and external users is where their contact and<br />

authentication information is stored.<br />

Local users have contact and authentication information stored in the<br />

QuickPlace-specific membership database (Contacts1.nsf) of the “place”<br />

Managers of the place can create users, change the users' access levels, and<br />

delete users. Local users can access only the place where their membership<br />

information is contained.<br />

Chapter 12. Security features of other Lotus products 537

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!