Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Everyone can read my e-mail without giving them access.

Status
Not open for further replies.

luusid

MIS
Dec 4, 2002
23
0
0
US
I have a few users who can read other users e-mail even though we took everyone out of the access control to their e-mail. They have access to view the calendar and that works just fine, but when you have someone's calendar open you can moved it to the right and see their inbox and other folders. The inboxes are full and you can view the e-mail. This isn't so for all users on our network. Is there a global setting to deny everyone from viewing other people's e-mail?

Our domino server is 5.0.8 along with our clients. We are planning on migrating to 6.0.1 over the weekend.
 
Access is unequivocally assigned per mail db in the acl of the db.
You should check the mail db of the users whose mail can be viewed and ensure that there is no mistake in the ACL, no group access that would allow world+dog to get in and view the mail.
All delegations show up in the ACL, so there is nothing hidden away anywhere.
A secure ACL for any mail db is as follows :
- owner as Manager
- default as No Access, can read public docs
- LocalDomainServers as Manager
- OtherDomainServers as No Access
- mail server as Admin Server

You might want to add an Admin group with the name of the Notes Admin as Manager of the db, just in case.
Anything else is suspect and should be fully justified before being allowed to stay.
 
How about turning on "Enforce consistent ACL across all replicas of the database"?

Chances are, someone has a local replica of their database and therefore is a manager of the local replica.
 
Thanks for everyone's reply. It was the ACL group we gave access to. We took care of that and this isn't an issue anymore.

David
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top