SlideShare a Scribd company logo
1 of 30
#engageug
#engageug
Ad 09
Domino Fitness. Time for a Health Check
Jared Roberts
#engageug
Domino Fitness Check
Are you Domino Fit?
#engageug
Jared Roberts
Head of Digital Solutions – ISW
๏ Melbourne, Australia
๏ Consulting background:
๏ Notes, Domino, Connections, Sametime, WAS, Portal (DX)
๏ Analytics, Integration, Architecture
๏ Strategy, Digital Transformation
๏ Lifelong metal musician
๏ BBQ enthusiast
๏ Amateur beer brewer
๏ Terrible at most sports
#engageug
Modern Workplace
Microsoft
SharePoint
Microsoft 365
Microsoft Power
Platform
Microsoft Teams
HCL Digital
Experience
HCL Domino &
Notes
HCL Volt MX &
Leap
HCL Connections
Cloud 42
Hosting &
Managed Cloud
Services
Cloud Email &
Team
Collaboration
Cloud Expertise &
Services
Enterprise Data
Protection
Software
Development
Custom Software
Development
Low Code / No
Code Platforms
ISW Innovations
Data Intelligence &
Integration
Cloud Data &
Application
Integration
Data Platform
Evaluation
Data Governance
& Quality
Assurance
Master Data
Management
Enterprise Security
SIEM
Attack Surface
Management
IAM & CIAM
Industrial Solutions
Asset
Management
Engineering Lifecycle
Management
Creative Design
Agency
Video & Motion
Graphics
Branding & Print
Design
Website Design &
Build
UI/UX Design
AI & Smarter
Payments
AI Enhanced
Content
Exploration
AI-Powered Virtual
Assistants
Fraud & AML
Monitoring
Secure Payments
Service
Software Licensing Expert Consulting
Cloud Hosting
Managed Services
Service Desk Recruitment Services
ISW
#engageug
Time for a health check!
Think of this exercise as an annual check-up at the doctor.
#engageug
Time for a health check!
Your body will run even if you:
• Feed it bad food
• Never exercise
• Ignore small issues and warnings of bigger problems
• Regularly visit the Amsterdam coffee shops
So you want to change something...
• Run a marathon
• Climb a mountain
• Break the world breath-holding record (Kate Winslet)
#engageug
Time for a health check!
Domino - for all it's wonderful features, will also run if:
• Servers are configured poorly
• Environment is managed terribly
• It’s generally ignored by system admins/owners and IT!!
So you want to change something...
• Upgrade Domino
• Implement new features
• Integrate with other systems or apps
• Deploy major mail routing or security changes
• Execute server consolidation or OS updates
#engageug
Domino Fitness Check: WHY?
๏ Technical
๏ Preparing for ANY changes
๏ Responding to industry/global issues
๏ Operational
๏ Opportunity to solve persistent issues
๏ Improve processes
๏ Long-term stability
๏ Business
๏ License/technical audits
๏ Technology strategy
๏ TCO review/update
#engageug
Domino Fitness Check: HOW?
๏ we collect over 400 configuration items from EACH server
๏ we collect environmental information
(OS, DLL dependencies, external connectivity etc)
๏ We feed information into a comprehensive db with all parameters
(You can do this manually with excel or checklist)
๏ developed a scoring system to give you a "score" out of 100
๏ benchmark against other customers
#engageug
Domino Fitness Check: WHAT?
๏ General Configuration
๏ Server documents config
๏ Connection documents config
๏ Configuration documents config
๏ Domain documents config
#engageug
Domino Fitness Check: WHAT?
๏ Database health
๏ Data footprint
๏ ODS
๏ Compression settings
๏ Maintenance programs
#engageug
Domino Fitness Check: WHAT?
๏ Optimisation
๏ Network compression
๏ Transaction logging
๏ DAOS
#engageug
Domino Fitness Check: WHAT?
๏ Cluster Management
๏ Health
๏ Configuration
#engageug
Domino Fitness Check: WHAT?
๏ Replication
๏ Topology
๏ Settings
#engageug
Domino Fitness Check: WHAT?
๏ Directory Management
๏ Domino Directory
๏ Group Management
๏ Directory Assistance
๏ LDAP
#engageug
Domino Fitness Check: WHAT?
๏ Agent Management
๏ Server Agent Settings
๏ Agent Security Settings
๏ Agent Timeout Settings
#engageug
Domino Fitness Check: WHAT?
๏ Monitoring & Event Management
๏ DDM, Collection & Events Settings
๏ Fault, restart & alerting settings
#engageug
Domino Fitness Check: WHAT?
๏ Security
๏ ID Vault
๏ Notes/Web Authorisation
๏ ECL
๏ Default ACLs
#engageug
Domino Fitness Check: WHAT?
๏ Web Server
๏ Web Server Config
๏ TLS
#engageug
Domino Fitness Check: WHAT?
๏ Policies
๏ Organisational
๏ Explicit
๏ Precedence
๏ Settings documents
#engageug
Domino Fitness Check: WHAT?
๏ Application Management
๏ Template management
๏ Updates management
๏ Application clustering
#engageug
Domino Fitness Check: WHAT?
๏ Backup processes
๏ Database backup processes
๏ Database backup tools
#engageug
Domino Fitness Check: WHAT?
๏ New Features
๏ One-touch setup/automation
๏ Active Directory lookup
๏ DKIM
๏ New backup/restore capabilities
๏ Containerised Domino servers
#engageug
Outcomes
OUTCOMES
#engageug
Outcomes
OUTCOMES
#engageug
Outcomes
#engageug
Wrap Up
#engageug
Health Check Parameters
This is not an exhaustive list… but it’s PLENTY to get you started on a health check!
SERVER INFO
Server
Server Title
FQDN
Domino Version
Operating System
CPU count
Server memory
Disk space
Domino binaries
Domino data
Domino transaction logs
Domino DAOS data
Domino FTI
Domino Views
SERVER DOCUMENTS
Directory Assistance
Load Internet configurations from ServerInternet Sites documents:
Run NSD To Collect Diagnostic Information
Automatically Restart Server After Fault/Crash
Cleanup Script / NSD Maximum Execution Time:
Server Shutdown Timeout:
Maximum Fault Limits:
Mail Fault Notification to:
Administrators
Full Access Administration
Administrators
Database Administrators
Full Remote Console Administrators
View only administrators
System Administrators
Restricted System Administrator
Administer server from a browser
Sign or Run unrestricted methods and operations
Sign agents to run on behalf of someone else
Sign agents or XPages to run on behalf of the invoker
Sign or Run restricted Lotus script/java agents
Run Simple and formula Agents
Sign script libraries to run on behalf of someone else
Run Restricted java/java script/COM agents
Run Unrestricted java/java script/COM agents
Compare Public keys
Allow anonymous Notes connections
Check passwords on Notes IDs
Internet authentication
Access server
Not access server
Create databases & templates
Create new replicas
Create master templates
Allowed to use monitors
Not allowed to use monitors
Trusted servers
Passthru Use
Access this server
Route through
Cause calling
Destinations allowed
Notes network Ports
Port
Protocol
Notes network
Net address
Enabled
Web TCP/IP Port Number
Web TCP/IP Port Status
Enforce server access setting
Web SSL port number
Web SSL port Status
Directory (LDAP) TCP/IP Port Number
Directory (LDAP) TCP/IP Port Status
Enforce server access setting
SSL port number
SSL port Status
Mail (SMTP Inbound) TCP/IP Port Status
Enforce server access setting
Mail (SMTP Outbound) TCP/IP Port Status;
Enforce server access setting
Admin Process
Maximum number of threads:
Day Max concurrent agents:
Day Max LotusScript/Java execution time:
Night Max concurrent agents:
Night Max LotusScript/Java execution time:
Domain Catalog Enabled?
Directory Cataloger Enabled?
Directory Cataloger Schedule
Internet Cluster Manager Configured?
AD Password Sync Configured?
Host Name
Domino Web Engine
Session authentication
Web SSO Configuration
Java Servlet support
Transaction Logging Enabled?
Log path:
Logging style:
DAOS Enabled
Minimum size of object before Domino will store in DAOS:
DAOS base path:
Defer object deletion for:
DAOS object encryption:
DAOS encryption strength:
DAOS Tier 2 Enabled
Notes Traveler Enabled
Maximum Memory Size:
IPC Socket Ports:
External Server URL:
Access server:
Not access server:
Remote user commands:
User managed security:
CONFIG DOCUMENTS
Type Ahead
License Tracking
Enforce Internet Password Lockout
Smart Upgrade Database Link
Limit Concurrent Smart Upgrade
Provisioning settings are enabled
Basics
Number of mailboxes
Address lookup
Exhaustive lookup
Relay host for messages leaving the local internet domain
#engageug
Health Check Parameters
Maximum message size
Send all messages as low priority if the message size is between
Allow messages to be sent only to the following external internet
domains
Deny messages to be sent to the following external internet
domains (* means all)
Allow messages only from the following internet hosts to be sent to
external internet domains
Deny messages from the following internet hosts to be sent to
external internet domains (* means all)
Perform Anti-Relay enforcement for these connecting hosts
Exclude these connecting hosts from anti-relay checks
Exceptions for authenticated users
DNS Blacklist filters
DNS Blacklist sites
Desired action when a connecting host is found in a DNS Blacklist
Custom SMTP error response for rejected messages
Verify connecting hostname in DNS
Verify that local domain recipients exist in the Domino Directory
Deny mails to groups
Deny messages intended for the following internet addresses
Allow messages only from the following Internet addresses to be
sent to the Internet
Deny messages from the following Internet addresses to be sent to
the Internet
Allow messages only from the following Notes addresses to be sent
to the Internet
Deny messages from the following Notes addresses to be sent to the
Internet
Maximum delivery threads
Encrypt all delivered mail
Pre-delivery agents
Pre-Delivery agent timeout
User rules mail forwarding
Reverse Path for forwarded mail
Over warning threshold notifications
Over quota notification
Error interval
Over quota enforcement
Server Rules
Message disclaimers
Message tracking
Message tracking collection interval
Log message subjects
Allowed to track messages
Allowed to track subjects
Message Recall
Allow recall of messages with unread status
Do not allow recall of messages older than
Journaling
Out-of-Office
Restrict name lookups to primary directory only
NOTES.INI Settings
HCL iNotes Tab Configured?
Activity Logging is enabled (y/n)
Enabled logging types
Checkpoint interval
Log checkpoint at midnight
Log checkpoints for prime shift
Prime shift interval
Activity Trends
Enable activity trends collector
Activity trends collector database path
Time of day to run activity trends collector
Days of the week to collect observations
Activity Trends Data Profile Options
Mail-in Database for diagnostic reports
Maximum size of diagnostic message including attachments (in MB)
Maximum size of NSD output to attach (in MB)
Maximum amount of console output file to attach (in KB)
Diagnostic file patterns
Remove diagnostic files after a specified number of days
Number of days to keep diagnostic files
Fault Analyzer
Run FaultAnalyzer on Fault DBs on this server
Run Fault Analyzer on
Remove attachments from duplicate faults
Sync Active Directory passwords to Domino
Password change requests expire after
Managers of password sync request databases:
CONNECTION DOCUMENTS
DOMAIN DOCUMENTS
DATA FOOTPRINT
Total # databases
Total Domino Data size (on disk) GB
Total # Mail Files
Total Mail File size (on disk) GB
# Mail Files with Quota
# Mail Files without Quota
ODS
COMPRESSION SETTINGS
# databases with Data Compression
# databases with Design Compression
MAINTENANCE PROGRAMS
NETWORK COMPRESSION
network compression enabled (y/n)
CLUSTER HEALTH
# of cluster replica tasks
work queue depth value
CLUSTER CONFIG
REPLICATION TOPOLOGY
Replication of core DBs (names.nsf, admin4, events4 etc.)
configured to best practice?
Too many or unnessesary Connection documents
REPLICATION SETTINGS
DOMINO DIRECTORY
DD Config Profile
Domino domain defined by this Domino Direcotry
Auto-populated group members update interval
Use more secure internet passwords
List of Admins allowe to create cross domain config docs
DD ACL
GROUPS
# of total groups
# of security groups
# of mail groups
# of multi-purpose groups
# of termination groups
localdomainservers in use (y/n)
localdomainadmins in use (y/n)
otherdomainservers in use (y/n)
DIRECTORY ASSISTANCE
directory assistance enabled (y/n)
directory assistance documents
LDAP
# servers LDAP enabled
LDAP CONFIG
#engageug
Health Check Parameters
Anonynous Users Can query
Allow write access
Timeout
Max entries returned
DN required on bind
MONITORING & EVENT MANAGEMENT
DDM / Monitoring Configuration enabled (y/n)
Server Collection Hierarchy configured (y/n)
Administration / Auto-Close Probes Enabled (y/n)
Fault, restart & alerting settings
ID VAULT
ID Vault DB created (y/n)
ID Vault Trust Certificated created and current (y/n)
ID Vault administrators defined (y/n)
ID password reset roles defined (y/n)
NOTES/WEB AUTHORISATION
ID Public Key Specification
Password Key width
Certificate expiration date
Custom Password Policy Enabled
Notes Shared Login Enabled
Federated Login Enabled
Name variations for web authorisation
SECURITY SETTINGS
Default Security Settings Document Created (y/n)
Security Settings Document assigned to Policy (y/n)
Use Custom Password Policy for Notes Clients
Check password on Notes ID file
Allow Users to Change Internet Password over HTTP
Update Internet Password When Notes Password Changes
Don't prompt for a password from other programs
Enforce Password Expiration
Required Change Interval
Required Password Quality
Mandated encryption standard:
Minimum allowable key strength:
Maximum allowable key strength:
Preferred key strength:
ID Vault configured in settings Document (y/n)
Assigned vault:
Forgotten password help text (y/n)
Enforce password change after password has been reset:
Allow Notes-based programs to use the Notes ID Vault:
Whitelist rules configured for proxies (y/n)
ECL
Admin ECL configured (y/n)
Admin ECL contains correct server groups/wildcards
Admin ECL contains correct user groups/wildcards
Admin ECL does not contain other/external signers
DEFAULT ACLS Mail Files
DEFAULT ACLS Domino Directory
TLS
CertMgr task enabled (y/n)
CertStore DB created (y/n)
TLS configured for all web sites (y/n)
Strong Ciphers used (y/n)
ORGANISATIONAL
Organisational Policy created & deployed (y/n)
Default Security Settings Assinged to Org Policy (y/n)
Settings Assigned to Org Policy (y/n)
EXPLICIT
# Explicit Policies created & deployed
# Explicit Policies assigned using Policy Assignment
PRECEDENCE
Policy Precedence configured correctly for explicit
SETTINGS
# Setup Settings Documents
# Archiving Settings Documents
# Desktop Settings Documents
# Security Settings Documents
# Mail Settings Documents
# Connections Settings Documents
# IBM Traveler Settings Documents
# Roaming Settings Documents
# Symphony Settings Documents
MARVELCLIENT HEALTH
Analyze & Config DB up to date latest version (y/n)
Replication healthy (y/n)
DB Size healthy
Cleanup Task enabled
mc.dll DEPLOYMENT
mc.dll deployed to all Notes users
latest DLLs (including 64-bit) deployed into config DB
Installation document correctly configured
AUDIT ACTIONS
default audit actions enabled
Client data correctly uploaded to Analyze DB
Audit agent configured
MANAGEMENT ACTIONS
Config actions running without error
MCUPGRADE
Latest MCUpgrade deployed
Latest Notes clients & Fix Packs Indexed
At least 1 Upgrade config created
Messaging & Notifications Configured
TEMPLATES MANAGEMENT
Dedicated server/domain to host templates (y/n)
Master template versioning tracked (y/n)
# mail templates used
use customised mail templates? (y/n)

More Related Content

What's hot

Best Practice TLS for IBM Domino
Best Practice TLS for IBM DominoBest Practice TLS for IBM Domino
Best Practice TLS for IBM DominoJared Roberts
 
DNUG HCL Domino 11 First Look
DNUG HCL Domino 11 First LookDNUG HCL Domino 11 First Look
DNUG HCL Domino 11 First Lookdaniel_nashed
 
Important tips on Router and SMTP mail routing
Important tips on Router and SMTP mail routingImportant tips on Router and SMTP mail routing
Important tips on Router and SMTP mail routingjayeshpar2006
 
April, 2021 OpenNTF Webinar - Domino Administration Best Practices
April, 2021 OpenNTF Webinar - Domino Administration Best PracticesApril, 2021 OpenNTF Webinar - Domino Administration Best Practices
April, 2021 OpenNTF Webinar - Domino Administration Best PracticesHoward Greenberg
 
Domino Tech School - Upgrading to Notes/Domino V10: Best Practices
Domino Tech School - Upgrading to Notes/Domino V10: Best PracticesDomino Tech School - Upgrading to Notes/Domino V10: Best Practices
Domino Tech School - Upgrading to Notes/Domino V10: Best PracticesChristoph Adler
 
Engage 2015 - 10 Mistakes You and Every XPages Developer Make. Yes, I said YOU!
Engage 2015 - 10 Mistakes You and Every XPages Developer Make. Yes, I said YOU!Engage 2015 - 10 Mistakes You and Every XPages Developer Make. Yes, I said YOU!
Engage 2015 - 10 Mistakes You and Every XPages Developer Make. Yes, I said YOU!Serdar Basegmez
 
Real life challenges and configurations when implementing HCL Sametime v12.0....
Real life challenges and configurations when implementing HCL Sametime v12.0....Real life challenges and configurations when implementing HCL Sametime v12.0....
Real life challenges and configurations when implementing HCL Sametime v12.0....DNUG e.V.
 
The Ultimate Administrator’s Guide to HCL Nomad Web
The Ultimate Administrator’s Guide to HCL Nomad WebThe Ultimate Administrator’s Guide to HCL Nomad Web
The Ultimate Administrator’s Guide to HCL Nomad Webpanagenda
 
RNUG - Dirty Secrets of the Notes Client
RNUG - Dirty Secrets of the Notes ClientRNUG - Dirty Secrets of the Notes Client
RNUG - Dirty Secrets of the Notes ClientChristoph Adler
 
Open Mic "Notes Federated Login"
Open Mic "Notes Federated Login"Open Mic "Notes Federated Login"
Open Mic "Notes Federated Login"Ranjit Rai
 
Understanding domino memory 2017
Understanding domino memory 2017Understanding domino memory 2017
Understanding domino memory 2017mJOBrr
 
OpenNTF Domino API (ODA): Super-Charging Domino Development
OpenNTF Domino API (ODA): Super-Charging Domino DevelopmentOpenNTF Domino API (ODA): Super-Charging Domino Development
OpenNTF Domino API (ODA): Super-Charging Domino DevelopmentPaul Withers
 
dachnug49 - panagenda Workshop - 100 new things in Notes, Nomad Web & MarvelC...
dachnug49 - panagenda Workshop - 100 new things in Notes, Nomad Web & MarvelC...dachnug49 - panagenda Workshop - 100 new things in Notes, Nomad Web & MarvelC...
dachnug49 - panagenda Workshop - 100 new things in Notes, Nomad Web & MarvelC...Christoph Adler
 
October OpenNTF Webinar - What we like about Domino/Notes 12, recommended new...
October OpenNTF Webinar - What we like about Domino/Notes 12, recommended new...October OpenNTF Webinar - What we like about Domino/Notes 12, recommended new...
October OpenNTF Webinar - What we like about Domino/Notes 12, recommended new...Howard Greenberg
 
HCL Sametime 12.0 – Converting from native Domino Directory to LDAP and Migra...
HCL Sametime 12.0 – Converting from native Domino Directory to LDAP and Migra...HCL Sametime 12.0 – Converting from native Domino Directory to LDAP and Migra...
HCL Sametime 12.0 – Converting from native Domino Directory to LDAP and Migra...Ales Lichtenberg
 
Configuring Domino To Be An Ldap Directory And To Use An Ldap Directory
Configuring Domino To Be An Ldap Directory And To Use An Ldap DirectoryConfiguring Domino To Be An Ldap Directory And To Use An Ldap Directory
Configuring Domino To Be An Ldap Directory And To Use An Ldap DirectoryEdson Oliveira
 

What's hot (20)

Best Practice TLS for IBM Domino
Best Practice TLS for IBM DominoBest Practice TLS for IBM Domino
Best Practice TLS for IBM Domino
 
DNUG HCL Domino 11 First Look
DNUG HCL Domino 11 First LookDNUG HCL Domino 11 First Look
DNUG HCL Domino 11 First Look
 
Important tips on Router and SMTP mail routing
Important tips on Router and SMTP mail routingImportant tips on Router and SMTP mail routing
Important tips on Router and SMTP mail routing
 
Daos
DaosDaos
Daos
 
April, 2021 OpenNTF Webinar - Domino Administration Best Practices
April, 2021 OpenNTF Webinar - Domino Administration Best PracticesApril, 2021 OpenNTF Webinar - Domino Administration Best Practices
April, 2021 OpenNTF Webinar - Domino Administration Best Practices
 
Domino Tech School - Upgrading to Notes/Domino V10: Best Practices
Domino Tech School - Upgrading to Notes/Domino V10: Best PracticesDomino Tech School - Upgrading to Notes/Domino V10: Best Practices
Domino Tech School - Upgrading to Notes/Domino V10: Best Practices
 
Domino Adminblast
Domino AdminblastDomino Adminblast
Domino Adminblast
 
Engage 2015 - 10 Mistakes You and Every XPages Developer Make. Yes, I said YOU!
Engage 2015 - 10 Mistakes You and Every XPages Developer Make. Yes, I said YOU!Engage 2015 - 10 Mistakes You and Every XPages Developer Make. Yes, I said YOU!
Engage 2015 - 10 Mistakes You and Every XPages Developer Make. Yes, I said YOU!
 
Spnego configuration
Spnego configurationSpnego configuration
Spnego configuration
 
Real life challenges and configurations when implementing HCL Sametime v12.0....
Real life challenges and configurations when implementing HCL Sametime v12.0....Real life challenges and configurations when implementing HCL Sametime v12.0....
Real life challenges and configurations when implementing HCL Sametime v12.0....
 
The Ultimate Administrator’s Guide to HCL Nomad Web
The Ultimate Administrator’s Guide to HCL Nomad WebThe Ultimate Administrator’s Guide to HCL Nomad Web
The Ultimate Administrator’s Guide to HCL Nomad Web
 
RNUG - Dirty Secrets of the Notes Client
RNUG - Dirty Secrets of the Notes ClientRNUG - Dirty Secrets of the Notes Client
RNUG - Dirty Secrets of the Notes Client
 
Open Mic "Notes Federated Login"
Open Mic "Notes Federated Login"Open Mic "Notes Federated Login"
Open Mic "Notes Federated Login"
 
Understanding domino memory 2017
Understanding domino memory 2017Understanding domino memory 2017
Understanding domino memory 2017
 
OpenNTF Domino API (ODA): Super-Charging Domino Development
OpenNTF Domino API (ODA): Super-Charging Domino DevelopmentOpenNTF Domino API (ODA): Super-Charging Domino Development
OpenNTF Domino API (ODA): Super-Charging Domino Development
 
dachnug49 - panagenda Workshop - 100 new things in Notes, Nomad Web & MarvelC...
dachnug49 - panagenda Workshop - 100 new things in Notes, Nomad Web & MarvelC...dachnug49 - panagenda Workshop - 100 new things in Notes, Nomad Web & MarvelC...
dachnug49 - panagenda Workshop - 100 new things in Notes, Nomad Web & MarvelC...
 
Deep Dive AdminP Process - Admin and Infrastructure Track at UKLUG 2012
Deep Dive AdminP Process - Admin and Infrastructure Track at UKLUG 2012Deep Dive AdminP Process - Admin and Infrastructure Track at UKLUG 2012
Deep Dive AdminP Process - Admin and Infrastructure Track at UKLUG 2012
 
October OpenNTF Webinar - What we like about Domino/Notes 12, recommended new...
October OpenNTF Webinar - What we like about Domino/Notes 12, recommended new...October OpenNTF Webinar - What we like about Domino/Notes 12, recommended new...
October OpenNTF Webinar - What we like about Domino/Notes 12, recommended new...
 
HCL Sametime 12.0 – Converting from native Domino Directory to LDAP and Migra...
HCL Sametime 12.0 – Converting from native Domino Directory to LDAP and Migra...HCL Sametime 12.0 – Converting from native Domino Directory to LDAP and Migra...
HCL Sametime 12.0 – Converting from native Domino Directory to LDAP and Migra...
 
Configuring Domino To Be An Ldap Directory And To Use An Ldap Directory
Configuring Domino To Be An Ldap Directory And To Use An Ldap DirectoryConfiguring Domino To Be An Ldap Directory And To Use An Ldap Directory
Configuring Domino To Be An Ldap Directory And To Use An Ldap Directory
 

Similar to Domino Fitness. Time for a Health Check

Secure360 - Attack All the Layers! Again!
Secure360 - Attack All the Layers! Again!Secure360 - Attack All the Layers! Again!
Secure360 - Attack All the Layers! Again!Scott Sutherland
 
24 Hours Of Exchange Server 2007 ( Part 12 Of 24)
24  Hours Of  Exchange  Server 2007 ( Part 12 Of 24)24  Hours Of  Exchange  Server 2007 ( Part 12 Of 24)
24 Hours Of Exchange Server 2007 ( Part 12 Of 24)Harold Wong
 
eMagic-Data Center Management System
eMagic-Data Center Management SystemeMagic-Data Center Management System
eMagic-Data Center Management SystemSandesh Sonar
 
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...European Collaboration Summit
 
Azure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD DeploymentAzure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD DeploymentAnthony Clendenen
 
Applciation footprinting, discovery and enumeration
Applciation footprinting, discovery and enumerationApplciation footprinting, discovery and enumeration
Applciation footprinting, discovery and enumerationBlueinfy Solutions
 
Back to the Future: Understand and Optimize your IBM Notes and Domino Infrast...
Back to the Future: Understand and Optimize your IBM Notes and Domino Infrast...Back to the Future: Understand and Optimize your IBM Notes and Domino Infrast...
Back to the Future: Understand and Optimize your IBM Notes and Domino Infrast...Dominopoint - Italian Lotus User Group
 
AWS re:Invent 2016: Amazon CloudFront Flash Talks: Best Practices on Configur...
AWS re:Invent 2016: Amazon CloudFront Flash Talks: Best Practices on Configur...AWS re:Invent 2016: Amazon CloudFront Flash Talks: Best Practices on Configur...
AWS re:Invent 2016: Amazon CloudFront Flash Talks: Best Practices on Configur...Amazon Web Services
 
“Lights Out”Configuration using Tivoli Netcool AutoDiscovery Tools
“Lights Out”Configuration using Tivoli Netcool AutoDiscovery Tools“Lights Out”Configuration using Tivoli Netcool AutoDiscovery Tools
“Lights Out”Configuration using Tivoli Netcool AutoDiscovery ToolsAntonio Rolle
 
Scoping for BMC Discovery (ADDM) Deployment by Traversys Limited
Scoping for BMC Discovery (ADDM) Deployment by Traversys LimitedScoping for BMC Discovery (ADDM) Deployment by Traversys Limited
Scoping for BMC Discovery (ADDM) Deployment by Traversys LimitedWes Moskal-Fitzpatrick
 
Enterprise Cloud Security
Enterprise Cloud SecurityEnterprise Cloud Security
Enterprise Cloud SecurityMongoDB
 
O365 quick with fast user experience
O365 quick with fast user experienceO365 quick with fast user experience
O365 quick with fast user experienceZscaler
 
SharePoint 2010 Global Deployment
SharePoint 2010 Global DeploymentSharePoint 2010 Global Deployment
SharePoint 2010 Global DeploymentJoel Oleson
 
Why And When Should We Consider Stream Processing In Our Solutions Teqnation ...
Why And When Should We Consider Stream Processing In Our Solutions Teqnation ...Why And When Should We Consider Stream Processing In Our Solutions Teqnation ...
Why And When Should We Consider Stream Processing In Our Solutions Teqnation ...Soroosh Khodami
 
Practical management of development & QA environments for SharePoint 2013
Practical management of development & QA environments for SharePoint 2013Practical management of development & QA environments for SharePoint 2013
Practical management of development & QA environments for SharePoint 2013SharePointRadi
 
Back to the Future - Understand and Optimize your IBM Notes/Domino Infrastruc...
Back to the Future - Understand and Optimize your IBM Notes/Domino Infrastruc...Back to the Future - Understand and Optimize your IBM Notes/Domino Infrastruc...
Back to the Future - Understand and Optimize your IBM Notes/Domino Infrastruc...panagenda
 
Cybersecurity controlling ports and network devices
Cybersecurity controlling ports and network devices Cybersecurity controlling ports and network devices
Cybersecurity controlling ports and network devices Jim Kaplan CIA CFE
 
Teched Middle East New World of SharePoint 2010 Administration with Joel Oles...
Teched Middle East New World of SharePoint 2010 Administration with Joel Oles...Teched Middle East New World of SharePoint 2010 Administration with Joel Oles...
Teched Middle East New World of SharePoint 2010 Administration with Joel Oles...Joel Oleson
 
Securing Your Enterprise Web Apps with MongoDB Enterprise
Securing Your Enterprise Web Apps with MongoDB Enterprise Securing Your Enterprise Web Apps with MongoDB Enterprise
Securing Your Enterprise Web Apps with MongoDB Enterprise MongoDB
 

Similar to Domino Fitness. Time for a Health Check (20)

Securing Windows web servers
Securing Windows web serversSecuring Windows web servers
Securing Windows web servers
 
Secure360 - Attack All the Layers! Again!
Secure360 - Attack All the Layers! Again!Secure360 - Attack All the Layers! Again!
Secure360 - Attack All the Layers! Again!
 
24 Hours Of Exchange Server 2007 ( Part 12 Of 24)
24  Hours Of  Exchange  Server 2007 ( Part 12 Of 24)24  Hours Of  Exchange  Server 2007 ( Part 12 Of 24)
24 Hours Of Exchange Server 2007 ( Part 12 Of 24)
 
eMagic-Data Center Management System
eMagic-Data Center Management SystemeMagic-Data Center Management System
eMagic-Data Center Management System
 
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...
[Collinge] Office 365 Enterprise Network Connectivity Using Published Office ...
 
Azure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD DeploymentAzure Global Bootcamp 2017 Azure AD Deployment
Azure Global Bootcamp 2017 Azure AD Deployment
 
Applciation footprinting, discovery and enumeration
Applciation footprinting, discovery and enumerationApplciation footprinting, discovery and enumeration
Applciation footprinting, discovery and enumeration
 
Back to the Future: Understand and Optimize your IBM Notes and Domino Infrast...
Back to the Future: Understand and Optimize your IBM Notes and Domino Infrast...Back to the Future: Understand and Optimize your IBM Notes and Domino Infrast...
Back to the Future: Understand and Optimize your IBM Notes and Domino Infrast...
 
AWS re:Invent 2016: Amazon CloudFront Flash Talks: Best Practices on Configur...
AWS re:Invent 2016: Amazon CloudFront Flash Talks: Best Practices on Configur...AWS re:Invent 2016: Amazon CloudFront Flash Talks: Best Practices on Configur...
AWS re:Invent 2016: Amazon CloudFront Flash Talks: Best Practices on Configur...
 
“Lights Out”Configuration using Tivoli Netcool AutoDiscovery Tools
“Lights Out”Configuration using Tivoli Netcool AutoDiscovery Tools“Lights Out”Configuration using Tivoli Netcool AutoDiscovery Tools
“Lights Out”Configuration using Tivoli Netcool AutoDiscovery Tools
 
Scoping for BMC Discovery (ADDM) Deployment by Traversys Limited
Scoping for BMC Discovery (ADDM) Deployment by Traversys LimitedScoping for BMC Discovery (ADDM) Deployment by Traversys Limited
Scoping for BMC Discovery (ADDM) Deployment by Traversys Limited
 
Enterprise Cloud Security
Enterprise Cloud SecurityEnterprise Cloud Security
Enterprise Cloud Security
 
O365 quick with fast user experience
O365 quick with fast user experienceO365 quick with fast user experience
O365 quick with fast user experience
 
SharePoint 2010 Global Deployment
SharePoint 2010 Global DeploymentSharePoint 2010 Global Deployment
SharePoint 2010 Global Deployment
 
Why And When Should We Consider Stream Processing In Our Solutions Teqnation ...
Why And When Should We Consider Stream Processing In Our Solutions Teqnation ...Why And When Should We Consider Stream Processing In Our Solutions Teqnation ...
Why And When Should We Consider Stream Processing In Our Solutions Teqnation ...
 
Practical management of development & QA environments for SharePoint 2013
Practical management of development & QA environments for SharePoint 2013Practical management of development & QA environments for SharePoint 2013
Practical management of development & QA environments for SharePoint 2013
 
Back to the Future - Understand and Optimize your IBM Notes/Domino Infrastruc...
Back to the Future - Understand and Optimize your IBM Notes/Domino Infrastruc...Back to the Future - Understand and Optimize your IBM Notes/Domino Infrastruc...
Back to the Future - Understand and Optimize your IBM Notes/Domino Infrastruc...
 
Cybersecurity controlling ports and network devices
Cybersecurity controlling ports and network devices Cybersecurity controlling ports and network devices
Cybersecurity controlling ports and network devices
 
Teched Middle East New World of SharePoint 2010 Administration with Joel Oles...
Teched Middle East New World of SharePoint 2010 Administration with Joel Oles...Teched Middle East New World of SharePoint 2010 Administration with Joel Oles...
Teched Middle East New World of SharePoint 2010 Administration with Joel Oles...
 
Securing Your Enterprise Web Apps with MongoDB Enterprise
Securing Your Enterprise Web Apps with MongoDB Enterprise Securing Your Enterprise Web Apps with MongoDB Enterprise
Securing Your Enterprise Web Apps with MongoDB Enterprise
 

Recently uploaded

Design and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data ScienceDesign and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data SciencePaolo Missier
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
ChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps ProductivityChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps ProductivityVictorSzoltysek
 
JavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate GuideJavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate GuidePixlogix Infotech
 
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data PlatformLess Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data PlatformWSO2
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Bhuvaneswari Subramani
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Decarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational PerformanceDecarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational PerformanceIES VE
 
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Modernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaModernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaWSO2
 
Choreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringChoreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringWSO2
 
Navigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern EnterpriseNavigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern EnterpriseWSO2
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxRemote DBA Services
 
Simplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptxSimplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptxMarkSteadman7
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 

Recently uploaded (20)

Design and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data ScienceDesign and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data Science
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
ChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps ProductivityChatGPT and Beyond - Elevating DevOps Productivity
ChatGPT and Beyond - Elevating DevOps Productivity
 
JavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate GuideJavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate Guide
 
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data PlatformLess Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Decarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational PerformanceDecarbonising Commercial Real Estate: The Role of Operational Performance
Decarbonising Commercial Real Estate: The Role of Operational Performance
 
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Modernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaModernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using Ballerina
 
Choreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software EngineeringChoreo: Empowering the Future of Enterprise Software Engineering
Choreo: Empowering the Future of Enterprise Software Engineering
 
Navigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern EnterpriseNavigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern Enterprise
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
Simplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptxSimplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptx
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 

Domino Fitness. Time for a Health Check

  • 1. #engageug #engageug Ad 09 Domino Fitness. Time for a Health Check Jared Roberts
  • 3. #engageug Jared Roberts Head of Digital Solutions – ISW ๏ Melbourne, Australia ๏ Consulting background: ๏ Notes, Domino, Connections, Sametime, WAS, Portal (DX) ๏ Analytics, Integration, Architecture ๏ Strategy, Digital Transformation ๏ Lifelong metal musician ๏ BBQ enthusiast ๏ Amateur beer brewer ๏ Terrible at most sports
  • 4. #engageug Modern Workplace Microsoft SharePoint Microsoft 365 Microsoft Power Platform Microsoft Teams HCL Digital Experience HCL Domino & Notes HCL Volt MX & Leap HCL Connections Cloud 42 Hosting & Managed Cloud Services Cloud Email & Team Collaboration Cloud Expertise & Services Enterprise Data Protection Software Development Custom Software Development Low Code / No Code Platforms ISW Innovations Data Intelligence & Integration Cloud Data & Application Integration Data Platform Evaluation Data Governance & Quality Assurance Master Data Management Enterprise Security SIEM Attack Surface Management IAM & CIAM Industrial Solutions Asset Management Engineering Lifecycle Management Creative Design Agency Video & Motion Graphics Branding & Print Design Website Design & Build UI/UX Design AI & Smarter Payments AI Enhanced Content Exploration AI-Powered Virtual Assistants Fraud & AML Monitoring Secure Payments Service Software Licensing Expert Consulting Cloud Hosting Managed Services Service Desk Recruitment Services ISW
  • 5. #engageug Time for a health check! Think of this exercise as an annual check-up at the doctor.
  • 6. #engageug Time for a health check! Your body will run even if you: • Feed it bad food • Never exercise • Ignore small issues and warnings of bigger problems • Regularly visit the Amsterdam coffee shops So you want to change something... • Run a marathon • Climb a mountain • Break the world breath-holding record (Kate Winslet)
  • 7. #engageug Time for a health check! Domino - for all it's wonderful features, will also run if: • Servers are configured poorly • Environment is managed terribly • It’s generally ignored by system admins/owners and IT!! So you want to change something... • Upgrade Domino • Implement new features • Integrate with other systems or apps • Deploy major mail routing or security changes • Execute server consolidation or OS updates
  • 8. #engageug Domino Fitness Check: WHY? ๏ Technical ๏ Preparing for ANY changes ๏ Responding to industry/global issues ๏ Operational ๏ Opportunity to solve persistent issues ๏ Improve processes ๏ Long-term stability ๏ Business ๏ License/technical audits ๏ Technology strategy ๏ TCO review/update
  • 9. #engageug Domino Fitness Check: HOW? ๏ we collect over 400 configuration items from EACH server ๏ we collect environmental information (OS, DLL dependencies, external connectivity etc) ๏ We feed information into a comprehensive db with all parameters (You can do this manually with excel or checklist) ๏ developed a scoring system to give you a "score" out of 100 ๏ benchmark against other customers
  • 10. #engageug Domino Fitness Check: WHAT? ๏ General Configuration ๏ Server documents config ๏ Connection documents config ๏ Configuration documents config ๏ Domain documents config
  • 11. #engageug Domino Fitness Check: WHAT? ๏ Database health ๏ Data footprint ๏ ODS ๏ Compression settings ๏ Maintenance programs
  • 12. #engageug Domino Fitness Check: WHAT? ๏ Optimisation ๏ Network compression ๏ Transaction logging ๏ DAOS
  • 13. #engageug Domino Fitness Check: WHAT? ๏ Cluster Management ๏ Health ๏ Configuration
  • 14. #engageug Domino Fitness Check: WHAT? ๏ Replication ๏ Topology ๏ Settings
  • 15. #engageug Domino Fitness Check: WHAT? ๏ Directory Management ๏ Domino Directory ๏ Group Management ๏ Directory Assistance ๏ LDAP
  • 16. #engageug Domino Fitness Check: WHAT? ๏ Agent Management ๏ Server Agent Settings ๏ Agent Security Settings ๏ Agent Timeout Settings
  • 17. #engageug Domino Fitness Check: WHAT? ๏ Monitoring & Event Management ๏ DDM, Collection & Events Settings ๏ Fault, restart & alerting settings
  • 18. #engageug Domino Fitness Check: WHAT? ๏ Security ๏ ID Vault ๏ Notes/Web Authorisation ๏ ECL ๏ Default ACLs
  • 19. #engageug Domino Fitness Check: WHAT? ๏ Web Server ๏ Web Server Config ๏ TLS
  • 20. #engageug Domino Fitness Check: WHAT? ๏ Policies ๏ Organisational ๏ Explicit ๏ Precedence ๏ Settings documents
  • 21. #engageug Domino Fitness Check: WHAT? ๏ Application Management ๏ Template management ๏ Updates management ๏ Application clustering
  • 22. #engageug Domino Fitness Check: WHAT? ๏ Backup processes ๏ Database backup processes ๏ Database backup tools
  • 23. #engageug Domino Fitness Check: WHAT? ๏ New Features ๏ One-touch setup/automation ๏ Active Directory lookup ๏ DKIM ๏ New backup/restore capabilities ๏ Containerised Domino servers
  • 28. #engageug Health Check Parameters This is not an exhaustive list… but it’s PLENTY to get you started on a health check! SERVER INFO Server Server Title FQDN Domino Version Operating System CPU count Server memory Disk space Domino binaries Domino data Domino transaction logs Domino DAOS data Domino FTI Domino Views SERVER DOCUMENTS Directory Assistance Load Internet configurations from ServerInternet Sites documents: Run NSD To Collect Diagnostic Information Automatically Restart Server After Fault/Crash Cleanup Script / NSD Maximum Execution Time: Server Shutdown Timeout: Maximum Fault Limits: Mail Fault Notification to: Administrators Full Access Administration Administrators Database Administrators Full Remote Console Administrators View only administrators System Administrators Restricted System Administrator Administer server from a browser Sign or Run unrestricted methods and operations Sign agents to run on behalf of someone else Sign agents or XPages to run on behalf of the invoker Sign or Run restricted Lotus script/java agents Run Simple and formula Agents Sign script libraries to run on behalf of someone else Run Restricted java/java script/COM agents Run Unrestricted java/java script/COM agents Compare Public keys Allow anonymous Notes connections Check passwords on Notes IDs Internet authentication Access server Not access server Create databases & templates Create new replicas Create master templates Allowed to use monitors Not allowed to use monitors Trusted servers Passthru Use Access this server Route through Cause calling Destinations allowed Notes network Ports Port Protocol Notes network Net address Enabled Web TCP/IP Port Number Web TCP/IP Port Status Enforce server access setting Web SSL port number Web SSL port Status Directory (LDAP) TCP/IP Port Number Directory (LDAP) TCP/IP Port Status Enforce server access setting SSL port number SSL port Status Mail (SMTP Inbound) TCP/IP Port Status Enforce server access setting Mail (SMTP Outbound) TCP/IP Port Status; Enforce server access setting Admin Process Maximum number of threads: Day Max concurrent agents: Day Max LotusScript/Java execution time: Night Max concurrent agents: Night Max LotusScript/Java execution time: Domain Catalog Enabled? Directory Cataloger Enabled? Directory Cataloger Schedule Internet Cluster Manager Configured? AD Password Sync Configured? Host Name Domino Web Engine Session authentication Web SSO Configuration Java Servlet support Transaction Logging Enabled? Log path: Logging style: DAOS Enabled Minimum size of object before Domino will store in DAOS: DAOS base path: Defer object deletion for: DAOS object encryption: DAOS encryption strength: DAOS Tier 2 Enabled Notes Traveler Enabled Maximum Memory Size: IPC Socket Ports: External Server URL: Access server: Not access server: Remote user commands: User managed security: CONFIG DOCUMENTS Type Ahead License Tracking Enforce Internet Password Lockout Smart Upgrade Database Link Limit Concurrent Smart Upgrade Provisioning settings are enabled Basics Number of mailboxes Address lookup Exhaustive lookup Relay host for messages leaving the local internet domain
  • 29. #engageug Health Check Parameters Maximum message size Send all messages as low priority if the message size is between Allow messages to be sent only to the following external internet domains Deny messages to be sent to the following external internet domains (* means all) Allow messages only from the following internet hosts to be sent to external internet domains Deny messages from the following internet hosts to be sent to external internet domains (* means all) Perform Anti-Relay enforcement for these connecting hosts Exclude these connecting hosts from anti-relay checks Exceptions for authenticated users DNS Blacklist filters DNS Blacklist sites Desired action when a connecting host is found in a DNS Blacklist Custom SMTP error response for rejected messages Verify connecting hostname in DNS Verify that local domain recipients exist in the Domino Directory Deny mails to groups Deny messages intended for the following internet addresses Allow messages only from the following Internet addresses to be sent to the Internet Deny messages from the following Internet addresses to be sent to the Internet Allow messages only from the following Notes addresses to be sent to the Internet Deny messages from the following Notes addresses to be sent to the Internet Maximum delivery threads Encrypt all delivered mail Pre-delivery agents Pre-Delivery agent timeout User rules mail forwarding Reverse Path for forwarded mail Over warning threshold notifications Over quota notification Error interval Over quota enforcement Server Rules Message disclaimers Message tracking Message tracking collection interval Log message subjects Allowed to track messages Allowed to track subjects Message Recall Allow recall of messages with unread status Do not allow recall of messages older than Journaling Out-of-Office Restrict name lookups to primary directory only NOTES.INI Settings HCL iNotes Tab Configured? Activity Logging is enabled (y/n) Enabled logging types Checkpoint interval Log checkpoint at midnight Log checkpoints for prime shift Prime shift interval Activity Trends Enable activity trends collector Activity trends collector database path Time of day to run activity trends collector Days of the week to collect observations Activity Trends Data Profile Options Mail-in Database for diagnostic reports Maximum size of diagnostic message including attachments (in MB) Maximum size of NSD output to attach (in MB) Maximum amount of console output file to attach (in KB) Diagnostic file patterns Remove diagnostic files after a specified number of days Number of days to keep diagnostic files Fault Analyzer Run FaultAnalyzer on Fault DBs on this server Run Fault Analyzer on Remove attachments from duplicate faults Sync Active Directory passwords to Domino Password change requests expire after Managers of password sync request databases: CONNECTION DOCUMENTS DOMAIN DOCUMENTS DATA FOOTPRINT Total # databases Total Domino Data size (on disk) GB Total # Mail Files Total Mail File size (on disk) GB # Mail Files with Quota # Mail Files without Quota ODS COMPRESSION SETTINGS # databases with Data Compression # databases with Design Compression MAINTENANCE PROGRAMS NETWORK COMPRESSION network compression enabled (y/n) CLUSTER HEALTH # of cluster replica tasks work queue depth value CLUSTER CONFIG REPLICATION TOPOLOGY Replication of core DBs (names.nsf, admin4, events4 etc.) configured to best practice? Too many or unnessesary Connection documents REPLICATION SETTINGS DOMINO DIRECTORY DD Config Profile Domino domain defined by this Domino Direcotry Auto-populated group members update interval Use more secure internet passwords List of Admins allowe to create cross domain config docs DD ACL GROUPS # of total groups # of security groups # of mail groups # of multi-purpose groups # of termination groups localdomainservers in use (y/n) localdomainadmins in use (y/n) otherdomainservers in use (y/n) DIRECTORY ASSISTANCE directory assistance enabled (y/n) directory assistance documents LDAP # servers LDAP enabled LDAP CONFIG
  • 30. #engageug Health Check Parameters Anonynous Users Can query Allow write access Timeout Max entries returned DN required on bind MONITORING & EVENT MANAGEMENT DDM / Monitoring Configuration enabled (y/n) Server Collection Hierarchy configured (y/n) Administration / Auto-Close Probes Enabled (y/n) Fault, restart & alerting settings ID VAULT ID Vault DB created (y/n) ID Vault Trust Certificated created and current (y/n) ID Vault administrators defined (y/n) ID password reset roles defined (y/n) NOTES/WEB AUTHORISATION ID Public Key Specification Password Key width Certificate expiration date Custom Password Policy Enabled Notes Shared Login Enabled Federated Login Enabled Name variations for web authorisation SECURITY SETTINGS Default Security Settings Document Created (y/n) Security Settings Document assigned to Policy (y/n) Use Custom Password Policy for Notes Clients Check password on Notes ID file Allow Users to Change Internet Password over HTTP Update Internet Password When Notes Password Changes Don't prompt for a password from other programs Enforce Password Expiration Required Change Interval Required Password Quality Mandated encryption standard: Minimum allowable key strength: Maximum allowable key strength: Preferred key strength: ID Vault configured in settings Document (y/n) Assigned vault: Forgotten password help text (y/n) Enforce password change after password has been reset: Allow Notes-based programs to use the Notes ID Vault: Whitelist rules configured for proxies (y/n) ECL Admin ECL configured (y/n) Admin ECL contains correct server groups/wildcards Admin ECL contains correct user groups/wildcards Admin ECL does not contain other/external signers DEFAULT ACLS Mail Files DEFAULT ACLS Domino Directory TLS CertMgr task enabled (y/n) CertStore DB created (y/n) TLS configured for all web sites (y/n) Strong Ciphers used (y/n) ORGANISATIONAL Organisational Policy created & deployed (y/n) Default Security Settings Assinged to Org Policy (y/n) Settings Assigned to Org Policy (y/n) EXPLICIT # Explicit Policies created & deployed # Explicit Policies assigned using Policy Assignment PRECEDENCE Policy Precedence configured correctly for explicit SETTINGS # Setup Settings Documents # Archiving Settings Documents # Desktop Settings Documents # Security Settings Documents # Mail Settings Documents # Connections Settings Documents # IBM Traveler Settings Documents # Roaming Settings Documents # Symphony Settings Documents MARVELCLIENT HEALTH Analyze & Config DB up to date latest version (y/n) Replication healthy (y/n) DB Size healthy Cleanup Task enabled mc.dll DEPLOYMENT mc.dll deployed to all Notes users latest DLLs (including 64-bit) deployed into config DB Installation document correctly configured AUDIT ACTIONS default audit actions enabled Client data correctly uploaded to Analyze DB Audit agent configured MANAGEMENT ACTIONS Config actions running without error MCUPGRADE Latest MCUpgrade deployed Latest Notes clients & Fix Packs Indexed At least 1 Upgrade config created Messaging & Notifications Configured TEMPLATES MANAGEMENT Dedicated server/domain to host templates (y/n) Master template versioning tracked (y/n) # mail templates used use customised mail templates? (y/n)