I have created a number of folders outside the Domino data directory on a server (6.02 CF2), and am using folder links (directory links) to refer to them. Each folder link also contains the name of a group who are allowed to use it.
The reason for doing so is to prevent other users who have legitimate access to the server from browsing the contents of these restricted folders. The reason I am not using directory ACLs is that they only seem to hide the folder, but don’t appear to restrict access. If a user guesses the folder name, they can still type it in the Open Database dialog box and browse.
Anyway, this all works fine, until I implement Directory Assistance. I have found that if I want to use a group that is NOT from the primary Domino Directory (ie. names.nsf on the server) to secure the folder, the link is denied to everyone. This is despite the fact that the directory assistance document has the ‘Group Authorisation’ flag set to Yes. I know that directory assitance is working properly, as database ACLs are being honoured. I have tested this for both Notes and http users.
Does anyone have a workaround for this? I really want to use the groups in my secondary directory to secure the links, otherwise it becomes an administrative headache to copy the groups into the primary directory and keep them synchronised.
Thanks in advance…
Pete