IBM Domino Security - SSLv3 vulnerability

Date: 29/01/2015

Back

With POODLE vulnerability, Chrome version 39 (and above) and Firefox 34 (and above) disabling support for SSLv3, we would recommend you upgrade any Domino servers that are accessible via HTTPS to a version that supports TLS and disable support for SSLv3.

Versions of Domino that support TLS 1.0 can be found here

After installing a version that supports TLS 1.0, we recommend that you disable SSLv3
For Domino 9.0.1 Fix Pack 3 & Domino 9.0.1 Fix Pack 2 Interim Fix 3 - Add DISABLE_SSLV3=1 to the servers Notes.ini file
For other versions (that support TLS 1.0 ) Add DEBUG_UNSUPPORTED_DISABLE_SSLV3=17 to the servers Notes.ini file

We would also recommend hardening the Domino server by enabling only the below SSL ciphers:
RC4 encryption with 128-bit key and MD5 MAC
RC4 encryption with 128-bit key and SHA-1 MAC