Skip to main content
This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal

Notes/Domino 6 and 7 Forum

Notes/Domino 6 and 7 Forum


  


Extended ACL should do the trick (re: Registering web users with Secondary NAB)
~Umberto Nongeroson 10.Jul.03 09:57 PM a Web browser
Domino Server 6.0.1 All Platforms


Hey Jake,

Forget about a separate address book (although that may work too). There's no need with Extended ACLs in Domino 6.

You can lock down portions of a NAB from one group of users or another. Basically meant for an ASP or something, so that each group they host would appear to have their own NAB. xACL allows an admin to further refine the ACL down to categories of documents within the NAB. The categorization is based on the hierarchical portion of the relevant document (for a person doc, that would be the User Name field).

Note, it doesn't bypass the ACL, it refines it, giving a whole new level of granularity to NAB settings That said, the ACL still sets the ceiling.

So, for this example, we'll go with:
  • /webusers for the 'external' web people. Note that the /webusers version of their name must be the first one listed in the "User Name" field in the server's NAB
  • /Insiders for the employees
Single Domino Directory
UsersCurrent SituationDesired scenario
Road Runner/webuser
Neo/webuser
n/an/a
W.Coyote/Insider
Agent Smith/Insider
All four names are in the address dialogue/webuser names are not listed

Your goal is that W. Coyote and Agent Smith wouldn't be able to send email to Road Runner and Neo. More importantly, that type-ahead addressing wouldn't pick up their names. A simple xACL rule accomplishes that:

First, select your 'target category':

(ok, I used /Web instead of /webusers...sue me ;-)

Next is the Access List. This is analogous to where names/groups are entered in the standard ACL. In this example, */Insider could be a choice.

Then comes the "Attributes":


That's the simple way of setting that up. Another way--and depending on the situation, probably a better way--is to set the "root" rules to 'deny'...and then allow each group to see their own stuff (something like that would be appropriate for an ASP I think).

Only hitch so far is that the /webusers were still viewable in the "Person" view. Perhaps tweaking those rules further would prevent that as well (it was only a quick test for me, so I didn't go the full route of testing for that too...call me lazy ;-)

Anyway, with xACL enabled on the server's NAB, you can assign prevent /Insiders from seeing the /webusers when addressing an email (among other things too). Check out the admin help Database 'Lotus Domino Administrator 6 Help', View 'Index', Document 'Setting up and managing an extended ACL '. It doesn't mention the address dialogue specifically, so I had to try it out. Works like a charm.

Again, check the admin help--there's a couple warnings in there (e.g. the conversion to xACL can apparently be a lengthy process with a 'large' NAB). Also, xACL and anonymous LDAP don't get along too well...unless you don't mind anonymous access to your NAB...

Hope that helps.

Rod




Registering web users with Secondar... (~George Minpone... 3.Jul.03)
. . RE: Registering web users with Seco... (~Ben Kikroberga... 3.Jul.03)
. . . . RE: Registering web users with Seco... (~George Minpone... 3.Jul.03)
. . . . . . xACL might be useful here too... (r... (~Richard Rerebu... 11.Jul.03)
. . Hack the NAB... re: Registering web... (~Naomi Deskrote... 3.Jul.03)
. . . . RE: Hack the NAB... re: Registering... (~Naomi Deskrote... 3.Jul.03)
. . . . RE: Hack the NAB... re: Registering... (~George Minpone... 4.Jul.03)
. . . . . . RE: Hack the NAB... re: Registering... (~Alexis Bubvelu... 4.Jul.03)
. . . . . . RE: Hack the NAB... re: Registering... (~Naomi Deskrote... 7.Jul.03)
. . Hosted organizations? (~August Desboos... 4.Jul.03)
. . Extended ACL should do the trick (r... (~Richard Rerebu... 10.Jul.03)
. . . . RE: Extended ACL should do the tric... (~Rex Zekgeroplo... 18.Jul.03)
. . . . re: Extended ACL should do the tric... (~Richard Rerebu... 18.Jul.03)
. . . . . . RE: re: Extended ACL should do the ... (~Sean Desaplopa... 22.Jul.03)
. . . . . . . . RE: re: Extended ACL should do the ... (~Helga Churesat... 22.Sep.03)
. . . . . . . . . . Reporting a bug is free (~George Prejipy... 24.Jul.03)


Document Options






  Document options
Print this pagePrint this page

Search this forum

Forum views and search


  Forum views and search
Date (threaded)
Date (flat)
With excerpt
Category
Platform
Release
Advanced search

Member Tools


RSS Feeds

 RSS feedsRSS
All forum posts RSS
All main topics RSS