IBM Verse on Premises Integration with Connections and Docs issue with iNotes\_WA\_Security\_NonceCheck

Created:
Last Update:

Author: Christoph Stoettner
Read in about 2 min · 215 words

Fountain pen and a notebook

Photo by Aaron Burden | Unsplash

During the week we integrated IBM Connections and IBM Docs in our test environment and everything worked fine. Then we moved the configuration to production and most of the stuff was working, like showing Business cards, profile pictures and Connections files to add into mails. Docs Viewer and uploading files from a mail to Connections generated an error: “because of an internal server error”

IMG 02112017 180230 0

IMG 02112017 180238 0

I digged into it with Burpsuite and Fiddler4 , in the meantime a customer called me and described the same symptoms. Within the traces I found that the systems which didn’t upload the files had following header set:

X-IBM-INOTES-NONCE: <none>

and the working one had:

X-IBM-INOTES-NONCE: 2640941AE5454F5853E6732F79E7D2F5

So i searched a little bit on X-IBM-INOTES-NONCE and found that is introduced in Notes/Domino 8.5.2 and shall prevent XSS.

You can disable this with iNotes_WA_Security_NonceCheck =0 and this is mentioned in a technote , that sometimes proxies or F5 needs this setting. First we tried that on our testsystems and we seemed to be right, the upload was broken too.

We removed the notes.ini entry (or set it to 1) and after a http restart the file upload from VOP and the IBM Viewer worked!

IMG 02112017 171042 0

Thanks to Thomas who digged into this with me today.

Update 2017-11-20

IBM released a technote on this.

Author
Add a comment
Error
There was an error sending your comment, please try again.
Thank you!
Your comment has been submitted and will be published once it has been approved.

Your email address will not be published. Required fields are marked with *

Suggested Reading
Aaron Burden: Fountain pen and a notebook
IBM sent me a mail today, their logs show that i downloaded CR3 and they want to tell me, that i need one fix more, when i use Notes 9 Social Edition. I was really surprised and impressed. Here the download link for LO74465 .
Created:
Last Update:
Read in about 1 min
Aaron Burden: Fountain pen and a notebook
You can download the Plugins in greenhouse catalog . Connections Plugins 4.0 are not compatible with IBM Notes 9 Gold. It worked with the beta editions, but not with stable. Direct Link More Infos at Luis Benitez Blog .
Created:
Last Update:
Read in about 1 min
Aaron Burden: Fountain pen and a notebook
Connections 4.5 will be available on 29th of march. more via stephankopp.net
Created:
Last Update:
Read in about 1 min