Welcome @stoeps.de, the blog of Christoph Stoettner
I work at Vegard IT GmbH as a senior consultant with a focus on collaboration software, Kubernetes, security and automation. I mainly deal with HCL Connections, WebSphere Application Server, Kubernetes, Ansible, Terraform and Linux.
Sometimes my daily work results in technical talks and blog articles, which you can follow here more or less regularly. You can find the presentations in the main menu under public speaking .
I created a list of tools I use regularly, most of which have been released under an open source license.
In my spare time I read a lot, test all kinds of technical software and gadgets and try to follow about 200 RSS feeds.
Here you can find a collection of them.
This is my private blog, all opinions are my own.
Last created or modified articles
I started reviewing old blog post and replace links, or check if the information is still valid. So here are the last updated articles.
- Apple push notification certificates expire on 4th of July 2024 · Created: 2024-06-24
- Be careful with search-admin role in HCL Connections · Created: 2024-05-03
- CVE-2024-23557 - HCL Connections Security Update for User Enumeration Vulnerability · Created: 2024-04-21
- Talks 2024 · Updated: 2024-04-05 · Created: 2024-01-01
- Chemnitzer Linuxtage 2024 · Created: 2024-04-05
![Christoph Stoettner](https://stoeps.de/images/comic_head_1024_no_bg.png)
![Card image cap](https://stoeps.de/posts/2022/mustgather/jeff-sheldon-Tymrm3l36Dk-unsplash_hud30cda00d52379ee42c3f89144b97300_1662585_350x175_fill_q75_box_smart1.jpg)
![Card image cap](https://stoeps.de/posts/2022/patch_orientme_container/wilhelm-gunkel-an35-e-RS58-unsplash_hubd143dd938ee489892fafe64770a75c0_2851184_350x175_fill_q75_box_smart1.jpg)
I wrote about font loading from external CDN in the post Hiding The Create Community Button 2nd last year and hoped this is finally fixed for all Connections applications. A good summary on the reasons to not allow external font loading is Blocking Web Fonts for Speed and Privacy .
So I checked with a Connections 7 deployment with the latest CFix (CFix.70.2112) deployed, if this is still an issue with Connections.
In former Connections’ versions we found external fonts loaded in Orient Me (/social
), Communities Catalog (/communities
) and the Admin panel (/cnxadmin/
).
Last Update: Read in about 5 min
![Card image cap](https://stoeps.de/posts/2021/connections_docs_tls_and_xml/20211212-162739_hu83f7c08725410926c47e26ccc9014249_171304_350x175_fill_box_smart1_3.png)
I installed HCL Connections Docs 2.0.1 on top of an already installed HCL Connections 6.5CR1 with Docs Viewer. Usually a simple task, the installation was smooth, after the mandatory restart the Edit
button in the files’ application appeared and all looked good, but when the users clicked on edit
a white page was loaded.
![Card image cap](https://stoeps.de/posts/2021/log4j_how_to_find_out/lucian-alexe-p3Ip8U0eNNM-unsplash_hu9161546d56113d53497e938d8f2cbcef_3556528_350x175_fill_q75_box_smart1.jpg)
Update 2021-12-13 2021-12-15
- Elasticsearch: Apache Log4j2 Remote Code Execution (RCE) Vulnerability - CVE-2021-44228 - ESA-2021-31
- HCL: CVE-2021-44228 : Security Advisory
- IBM: Security Bulletin: Vulnerability in Apache Log4j affects WebSphere Application Server (CVE-2021-44228)
- Security Bulletin: HCL Connections Security Update for Apache Log4j 2 Vulnerability (CVE-2021-44228)
- CVE-2021-45046: It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations.
So there is a fix for kc.war
which updates the log4j
2.8 to 2.15, Elasticsearch in Component Pack has log4j 2.8 and 2.11 included but is not vulnerable because of additional security settings.
Last Update: Read in about 5 min
![Card image cap](https://stoeps.de/posts/2021/websphere_traces_on_steroids/lindsay-henwood-7_kRuX1hSXM-unsplash_hu5fa4487cdb1abc5282c8de9313991c61_359829_350x175_fill_q75_box_smart1.jpg)
During troubleshooting of WebSphere Application Server it is necessary to enable traces and see more detailed log messages.
Enabling these traces is very annoying, because you need to follow long click paths within the Integrated Solution Console (ISC).
![Card image cap](https://stoeps.de/posts/2021/connections_desktop_plugins_password_save_policy/tadas-sar-T01GZhBSyMQ-unsplash_hu6da21bfecdbdd2359d06f43986f000c2_2557568_350x175_fill_q75_box_smart1.jpg)
During the latest automated deployment of the HCL Connections Desktop Plug-ins for Microsoft™ Windows™ , I had issues activating the Password Save Policy
. We wanted to disable the option that users can save passwords.
The documentation tells us, that the registry key HKLM\SOFTWARE\Wow6432Node\IBM\Social Connectors\Settings\Password Save Policy
needs to be set to 1
to achieve this.