Solved

Need help with Domino DB security issue

Posted on 2002-05-09
1
170 Views
Last Modified: 2013-12-18
Domino Database security seems to be bypassed by Lotus Sametime's (Sametime is an app. that runs on Domino) "Add invitee" Java applet.  I can't keep the applet from being able to browse the secondary directory no matter what ACL settings I use.  This is a problem since I want to use a secondary directory for each company accessing the server but I don't want them seeing each others directories.


Example case:
Suppose I create a secondary domino directory, "secondDir.nsf" . I next create/install a directory assistance DB and add secondDir.nsf to it. Finally, I create a group, SecondDirGroup, and add to it a few person names.

Now, if I set secondDir.nsf's ACL to allow only access by SecondDirGroup (removing all other entries and setting "enforce a consistent ACL..."), I can still access secondDir.nsf from Sametime's invite attendee Java applet using a login that is not anyone in SecondDirGroup. That is I can see everyone and every group listed in secondDir.nsf.

Any ideas?
0
Comment
Question by:Taurus
1 Comment
 
LVL 63

Accepted Solution

by:
SysExpert earned 200 total points
ID: 7021843
I would check the Lotus Sametime/IBM support site and if there is not an answer there, open up a ticket with Lotus regarding this issue.

Because of the integration, this may be a problem.

Other options.

Use a *.dir link and put the , SecondDirGroup in a seperate directory.

the *.dir file can include access control lists.

I hope this helps !
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I thought it will be a good idea to make a post as it will help in case someone else faces these issues. I trust this gives an idea how each entry in Notes.ini can mean a lot for the Domino Server to be functioning properly. This article discusses t…
IBM Notes offer Encryption feature using which the user can secure its NSF emails or entire database easily. In this section we will discuss about the process to Encrypt Incoming and Outgoing Mails in depth.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question