22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The logout function in iNotes Web Access sends a logout command to the server<br />

to expire a session, if session authentication is being used. iNotes Web Access<br />

also closes the browser window to prevent another user from hitting the back<br />

button to view personal information from the previous screen. In addition to<br />

secure logout, iNotes Web Access does some sophisticated things with caching<br />

algorithms. This is to prevent the storage of information in the local browser<br />

cache in a format that someone could easily view.<br />

It should be noted that the secure logout function does not clear the browser’s<br />

local cache. As Internet Explorer stores content in the browser’s cache, it is<br />

possible to access that information programmatically. iNotes Web Access is<br />

unable to delete those files for users; therefore, they must do it by themselves, or<br />

configure the browser to prevent the local storage of information (Temporary<br />

Internet files) after the session has terminated.<br />

Deleting temporary Internet files automatically<br />

There is an option to configure Internet Explorer to empty temporary Internet files<br />

automatically. This can be enabled in Internet Explorer 5.01 or above by making<br />

the following selections: Tools → Internet Options → Advanced tab and selecting<br />

the “Empty temporary Internet file folders when browser is closed” option.<br />

12.3.4 Differences between iNotes Web Access and Notes security<br />

Most of the Notes Client security features are also available for the iNotes Web<br />

Access user. However, there are some differences between Notes and iNotes<br />

security, specifically the following:<br />

► iNotes does not support secret keys. If a Notes user ID already contains<br />

document keys, iNotes will decrypt the document. However, iNotes does not<br />

support the ability to create or import secret keys. If a user periodically<br />

receives messages that contain secret keys, the user needs to import the<br />

secret keys into their Notes user ID in Notes, then re-import the Notes user ID<br />

into iNotes.<br />

► iNotes does not support new public keys.<br />

► iNotes does not support requested name changes, nor is there the ability to<br />

change the default of “Auto Accept” of changes to the ID. If the Administrator<br />

has set Auto Accept of changes to ID file (name), there is no way in iNotes to<br />

override the auto accept as there is in Notes.<br />

► In iNotes, cross-certificates are stored in the Domino Directory only.<br />

► It is not possible to import a SmartCard-enabled Notes ID into iNotes.<br />

Chapter 12. Security features of other Lotus products 553

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!