[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference iosg::all-in-1_v30

Title:*OLD* ALL-IN-1 (tm) Support Conference
Notice:Closed - See Note 4331.l to move to IOSG::ALL-IN-1
Moderator:IOSG::PYE
Created:Thu Jan 30 1992
Last Modified:Tue Jan 23 1996
Last Successful Update:Fri Jun 06 1997
Number of topics:4343
Total number of notes:18308

452.0. "GMA security" by EVTAI1::PROT () Thu Apr 09 1992 18:28

    DIAMOND BL122:
    
    Strange behaviour with GMA:
    
    Suppose a user having an private MAIN drawer.
    If this user GMA's another user,the GMA code set ACL's for this other
    user on the following targets:
    
    -MAIL_ACCESS.DAT  (it's normal)
    -ACCESS.DAT       (it's also normal in order to be able to create
    		records in the drawer INBOX,READ,CREATED, and OUTBOX folders) 
    
    
    -MSG.DIR	       (normal also to be able to create mail messages)
    
    But also:
    
    -DOCn.DIR    (DEFAULT and NO-DEFAULT)
    -[.DOCn]*.*
    
    For these two last targets I really not understand because that allow
    this new user to access to all the existing DOCUMENTs, not only the MAILs.
    
    
    Why doing that, it could be enough and I think better to just put ACL's
    on MAIL_ACCESS,ACCESS and MSG.DIR ?
    
    
    
    Am I wrong ?
    
    Louis
T.RTitleUserPersonal
Name
DateLines
452.1Expected behaviourIOSG::TALLETTJust one more fix, then we can ship...Thu Apr 09 1992 22:096
    
    	Yes, that's how it works. GMA grants access to the whole
    	drawer, not just mail. See the documentation (I hope :-)
    
    Regards,
    Paul
452.2sharing is done at drawer levelCHRLIE::HUSTONFri Apr 10 1992 14:3111
    
    Louis,
    
    Sharing is basically done at a drawer level, so if you share the drawer
    you share everything in the drawer. By just putting the acl on the
    *.dat files that says the user has access to the drawer, 
    putting it on everything in the doc*.dir's give the user access to
    the content of the documents as well as the documents themselves.
    
    --Bob
    
452.3...EVTAI1::PROTMon Apr 13 1992 18:0517
    Bob,
    
     I agree  with you, my question was to understand why it was necessary
    to put also the acls on the .DOCn directories and documents. In this
    case the SMU user could only do an index of the folder, create and read
    MAILs, but neither read DOCUMENT nor edit them.This behaviour could be
    very interesting. Then he never writes in .DOCn , only in .MSG
    
    But now I think to a case where the SMU user need to write in a
    a .DOC dir, it's when he will create a document for auto-reply. Then
    maybe it's good like that... It's now an organisational problem, to
    make the owner of the mail drawer aware that he should have another personal
    unshared drawer where to put his privates documents that he doesn't
    want the SMU user to be able to access to.
    
    Louis 
                                             
452.4You got it!IOSG::TALLETTJust one more fix, then we can ship...Mon Apr 13 1992 21:269
>    It's now an organisational problem, to
>    make the owner of the mail drawer aware that he should have another personal
>    unshared drawer where to put his privates documents that he doesn't
>    want the SMU user to be able to access to.
    
    	Exactly! You got it!
    
    Regards,
    Paul