I am not the Notes admin but I supervise one. Our admins keep a list of everyone's password so that they can get into the users mail box and print out the encrypted emails to satisfy public records requests.
I am trying to find out if I can end this practice or if this truly is a flaw in Notes administration. I found this other thread that helps somewhat but I need the answer to how to print the encrypted emails.
From thread
Can these notes.id files with default password be used to read the encrypted mail or only used to regain access when user forgets password? Do you have to login as the user to read the encrypted mail?
A slightly related question (will repost separately if needed):
If a user leaves, and the person's manager needs to access the mailbox to see what they were working on, does the manager need to login as the user or is there a way to import the encryption key into the manager's id file?
I am trying to find out if I can end this practice or if this truly is a flaw in Notes administration. I found this other thread that helps somewhat but I need the answer to how to print the encrypted emails.
From thread
1. Ensure your users change their password after being setup. Teach them how to change it or better still sych with a directory such as AD and NDS.
2. Keep a copy of your Notes.id for every user with a defualt password, but ensure you have these files in a very secure location.
3. Keep your Cert.id and server.id secure as well
4. Do not use a default password like "lotusnotes" for these id's.
Can these notes.id files with default password be used to read the encrypted mail or only used to regain access when user forgets password? Do you have to login as the user to read the encrypted mail?
A slightly related question (will repost separately if needed):
If a user leaves, and the person's manager needs to access the mailbox to see what they were working on, does the manager need to login as the user or is there a way to import the encryption key into the manager's id file?