Solved

ALC Defaults

Posted on 2002-07-04
3
166 Views
Last Modified: 2013-12-18
I'm trying to set a standard for our ALC defaults.  We recently started allowing a few people from outside our organization access to our notes server by issuing them an .id file and notes client in order to update a database.  I noticed that some of our databases ACL were opened up more then they should be, this could pose a security risk so I’m doing an audit of all databases.

What is a good standard for setting the default ACL lists?  I think I’ll set this on all databases then open them up according to who needs specific access.

How does this look for a starting point, am I missing anything?
Default - No access
Anonymous  - No access
LocalDomainServers - Manager
AdminTeam -  Manager
OtherDomainServers - No access

Also Uniform Access is set to False on most of the databases, it is good practice to set this to true and what are the implications?
0
Comment
Question by:bnewton
  • 2
3 Comments
 
LVL 10

Expert Comment

by:zvonko
Comment Utility
The defaults look good.

The UniformAccess requires observation of the replication after setting this flag. In most cases you have to synchronize the ACL's between the replicas best by hand with an Manger client. After this synchronization you have to decide from which replica this ACL is allowed to be changed and which server has to do this.

Good luck,
zvonko

0
 
LVL 24

Expert Comment

by:HemanthaKumar
Comment Utility
Here are few technotes that would be a useful reference for you.

The ABC's of using the ACL
==========================
http://www-10.lotus.com/ldd/today.nsf/62f62847467a8f78052568a80055b380/be08e4acfc72cd72852565d9004cb61c?OpenDocument

Follow the related links for more info...

~Hemanth
0
 
LVL 10

Accepted Solution

by:
zvonko earned 200 total points
Comment Utility
Hello bnewton,

please give a note whether you are interested in more details and in which one.

So long,
zvonko


0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

You’ve got a lotus Domino web server, and you have been told that “leverage browser caching” is a must do. This means that we have to tell the browser everywhere in the web to use cache. In other words, we set (and send) an expiration date in the HT…
Article by: Rob
Notes 8.5 Archiving Steps and Tips This article covers setting up a Notes archive, and helps understand some of the menu choices making setting up and maintaining a Notes archive file easier.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now