Acl

Hi all’

The client software of lotus notes(6,0) , you have a funktion in the upper left corner (mail) where you can change (switch to calender - witch to to do and open another persons mail)

A non administrator can open other persons mail using the domain addresse book , but only the old created mailusers(lotus 5,0) and not the new created (lotus 6,0)users.

(have upgraded from 5 to 6)

I’ve checked the access rights on the old and the new mail databases , and it look the same.

Soo , my question is… is there another ACL that makes it possible to overrule the user mail database ACL ?

Please support me on this big security problem

Subject: ACL

Did you look at the setting “Read public documents” for - Default - in the ACL of each mail database?

Subject: RE: ACL

Hi Rod.

Yes , i’ve just figured it out and changed all default to >no access< on each maildatabase, you were right :-).

I’ve never seen this “default” before , just Anonymous , how did it get there ? , by upgrade ?

Thanks.

Subject: - Default- has always been there (WAS: ACL)

Subject: RE: - Default- has always been there (WAS: ACL)

Hi All,

Just a question and I’ve not tried this yet… What would be the impact on users and/or applications if -Default- ACL entry is removed? Is this advisable?

Thank you…

Subject: RE: - Default- has always been there (WAS: ACL)

It doesn’t matter whether or not it is advisable. You can change the settings for -Default-, but you can’t remove the entry.

Subject: RE: - Default- has always been there (WAS: ACL)

Thank you Rich for the response…

Regards!