Balancing Security with Domino Web Access

Written by Carl E. Reid on August 21, 2008

Domino Web Access (DWA) allows using a web browser for email through IBM’s Lotus Notes Domino server.  Domino’s claim to fame is made by people using the Lotus Notes client.  This software has to be physically loaded on each desktop computer running Windows or the Mac OS.  This requires being able to use the same computer all the time.  DWA allows a person access email from any computer with an Internet connection. When traveling, basic Internet access from a public hotel computer allows using the DWA.

There are two (2) security considerations to keep in mind, so people aren’t stymied while using the DWA.  This also creates a balance to insure proper security is maintained to protect email accounts.

1. When installing pop up blockers on computers, keep in mind many DWA functions invoke valid pop up windows. Creating, forwarding and replying to email initiates a pop window each time.  If your computer users have the pop up blocker turned “On”, these features will appear not to work.  Let’s say a person clicks on the “new email” link in the DWA. This function window will start to load, but the pop up blocker will immediately close the “new email” window.  To a person using the DWA, this happens so quickly it looks like the “new email” pop window never opened.  This feature basically opens and closes in a fraction of a second.  Now you get helpdesk requests the DWA is not working.  The resolution is the pop blocker needs to be modified to recognize the Domino server Internet web address as a trusted web site.  Or the pop up blocker needs to be turned off temporarily, while accessing email through the DWA.

2. Teach people to get in the habit of clicking on the “log out” link in the top right hand corner of the DWA screen. They should also click the check box to clear the DWA secure cache. Just closing the web browser can still leave an open connection to the email account on the Domino server.  At hotel this would allow someone to step up to the public computer.  Then go right into email account your computer user just left open.  So continue to remind your email users about the importance of clicking the secure cache link through the DWA logout screen.

Liked this post? Share it!
  • Digg
  • Slashdot
  • del.icio.us
  • StumbleUpon
  • Mixx
  • Fleck
  • Furl
  • Ma.gnolia
  • MisterWong
  • NewsVine
  • Reddit
  • Spurl
  • Technorati
  • TwitThis
Subscribe to my RSS feed

Leave a Comment

Comment Policy