Solved

About protected directory. Protected Directory Vs Server Access List

Posted on 2004-03-26
10
242 Views
Last Modified: 2013-12-18
Some one, mentioned something about protected directory. Can you provide me steps how to configure it ?
By doing so, i.e. putting the other copy in a protected directory, Will admins and server's have access to replicate with other servers or not ? Also need to know pros and cons of using protected directory Vs Server access List ?


Thanks!
0
Comment
Question by:navgup
  • 5
  • 3
  • 2
10 Comments
 
LVL 31

Expert Comment

by:qwaletee
ID: 10690424
Sorry, but "protected directory" is not known nomenclature.

Perhaps what you mean is the new R6 capability to break apart the "configuration" poerion of your directory and the "user" part of your directory.  Server docs, config docs, connections, etc. go in the primary directory, but user's are registered in a secondary dorectory.
0
 
LVL 31

Expert Comment

by:qwaletee
ID: 10690451
Note: that's called a "configuration directory," and has to reside on each server, while the "primary" directory contains just users names, groups, and mail-in docs/resources.  The "primary" directory typically sits on another server that is network reachable by the config-only servers.
0
 
LVL 31

Expert Comment

by:qwaletee
ID: 10690482
Also note (sorry about themultiple posts): This is officially supported in R6.  However, it is also possible to do this in R5, with some monkeying around.  Not for the fainthearted.
0
ScreenConnect 6.0 Free Trial

At ScreenConnect, partner feedback doesn't fall on deaf ears. We collected partner suggestions off of their virtual wish list and transformed them into one game-changing release: ScreenConnect 6.0. Explore all of the extras and enhancements for yourself!

 
LVL 15

Expert Comment

by:Bozzie4
ID: 10694148
I think you mean the file system directory, right ?

You can protect a directory/folder on the filesystem on the server.  In R6, you can protect it in such a way, that people who are not allowed to access it, don't see it either.  In R5, you can restrict access, but not hide it.
You can do this in the Files tab of Domino Adminstrator : right-click the directory and choose "Manage Directory ACL" (this is for R6, I'm not sure how to do it in R5)

This allows more flexibility then simply using Server access lists, because you can block access to specific directories only, but there are directories you can't protect like this (of course)

cheers,

Tom
0
 

Author Comment

by:navgup
ID: 10703790
Yes Bozzie4, i meant file system directory.
In R6 i understand there is a built in functionality to protect a directory. But does anyone know how to protect a directory in R5. I thought you create a .DIR file or something.. not sure exactly..
0
 

Author Comment

by:navgup
ID: 10703976
Bozzie4, Can you explain me atleast how to retrict access for a directory in R5 ( i don;t care if it is not hidden)?
0
 
LVL 15

Accepted Solution

by:
Bozzie4 earned 75 total points
ID: 10704617
You can do this in the server document, click on the Web button, choose File protection.

Enter the directory to protect there, and apply the security settings.  ALthough in R5 this is under 'web' settings, I seem to remember this applies to Notes too.  You can't hide the directory, though, but you can restrict access to it.

cheers,

Tom
0
 
LVL 31

Expert Comment

by:qwaletee
ID: 10707285
Web file protections apply to HTTP access only.  The Notes client can't open these files anyway.

I THINK the web file protections do not apply to NSF files, only to files read off the disk.  So, in:

C:\Notes\Data\mail - contains your mail files, http://youserver/mail/qwaletee.nsf would be my mail file
C:\Notes\Data\Domino\HTML\mail - if a web browser requests http://yourserver/mail/hello.gif, server looks for hello.gif in this directory

To the browser, qwaletee.nsf and hello.gif appear to be in the same folder.  To Domino, hello.gif uses disk directory mechanisms, while qwaletee.nsf uses Domino Web Application Server mechanisms.  The Notes client can't see hello.gif, because it does not read "normal HTTP transfers."  If you set a file protection on c:\Notes\Data\mail, it doesn't apply, because the web app server doesn't use these (I think), only the standard HTTP stack.

For .nsf protection, you would normally use regular ACLs.  You could tehoretically create a folder called c:\mail, and a file called c:\notes\data\mail.dir that contains:
c:\mail
group_with_permission_to_access

That certainly works with Notes, and I believe it will work with Domino web app server as well.  But ACLs are a better bet, since it relies on a standard mechnism that is self documenting, while .DIR files rely on physical disk structure, which would not be reliable if, say, you did a server migration or had to rebuild the server.
0
 

Author Comment

by:navgup
ID: 11172244
qualetee, could you please elaborate more on what you mentioned about .nsf protection in the last two paragraph. How am i suppose to create a protected folder, please provide some basic steps that i can do on the server. (i just want to implement this in a notes client/server environment and no web)

for eg..
under the notes\data folder i have 3 other folders called:
notes\data\app1, notes\data\app2 & notes\data\app3

Case 1. If I want to protect all the folders under notes\data from common user groups, but allow certain Database admins to access these folders.

Case 2. If i want to protect all the folders under notes\data from common user groups except notes\data\app1. In another words i want to provide access to notes\data\app1

Case 3. If i want to protect only one folder under notes\data from common user groups and give open access to the rest.
0
 
LVL 31

Expert Comment

by:qwaletee
ID: 11183530
Answered in the other question you recently asked.
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I thought it will be a good idea to make a post as it will help in case someone else faces these issues. I trust this gives an idea how each entry in Notes.ini can mean a lot for the Domino Server to be functioning properly. This article discusses t…
Problem "Can you help me recover my changes?  I double-clicked the attachment, made changes, and then hit Save before closing it.  But when I try to re-open it, my changes are missing!"    Solution This solution opens the Outlook Secure Temp Fold…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question