Search DominoPower's 11,323 Lotus-related article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
NOTES AND DOMINO SECURITY
Who's on your ACL?
By Dan Velasco

What I'm about to show you almost got me killed. After I showed it to our intranet manager, she pretended she was holding a double-barreled shotgun and said "BAM!" She told me she would shoot me down like a three-legged deer if I divulged to others at our company (not to mention the outside world!) the information that the agent I created reveals.

"What I'm about to show you almost got me killed."

But after careful negotiation, I discovered what she really meant was that she was forbidding me from sharing the information my agent retrieved from our Notes databases, not the method I used to obtain it (which is one long yet straightforward LotusScript agent and a single form to capture the data). So, to protect my life, I've changed all of the names I use in the screen shots and examples in this article.

I could show you, but then I'd have to kill you
Here is what the agent I developed reveals: it retrieves the ACL of the database of your choice and creates a report that lists everyone who has access to the database, even if they are buried inside a group listed in the ACL. It then formats all of it nicely on a Notes form so you can print it out and examine it over a cup of coffee. Of course, you might spit out that coffee if you find somebody on your access list that you don't think should be there.

The information contained on the ACL Information Form is nothing that somebody couldn't gather themselves if they patiently went through all of the entries in the ACL and noted the access level of each entry, sorting them into one of the seven levels as they went along. Of course, they would then have to go to the Public Name and Address Book separately and manually look up all of the group names and note the members of each. I've gotten incredibly bored just writing about how you would do such a thing, and I can only imagine how boring it would be to actually do it.

Relax. You don't have to put on your Amish work clothes and do any of this by hand. I've already done it for you. You can get a copy of a sample database containing the ACL Information Retrieval agent as well as the ACL Information Form from http://dan.velasco.com. You can also find an online listing of all of the code there as well.


1  ·  2  ·  3  ·  4  ·  Next »
Other articles you might like
Home > Lotus Technologies > Access Control (7 articles)
   Forcing immediate indexes to actually update immediately
   Enabling and disabling the single login setting in Notes 6
   Coding Domino server tasks in C: beyond Windows
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent DominoPower Articles
Lotusphere 2010: mobility and collaboration
2010: A Lotusphere of change
Five trends for 2010
DominoPower TV Episode 1: Inside a strategy session with Teamstudio
More about Domino log files
Say goodbye to the Uh-Ohs. Long live the Tens.
Why your log.nsf might not be purging properly
Latest Lotus Headlines
Recommended Maintenance - Lotus Notes Traveler
Here are the slides and other materials from our Lotusphere session
Microsoft OCS awareness in Lotus Connections and Websphere Portal?
SnTT: XPages Blank Calendar Control (Part 2), adding data
Have your Lotus Notes calendar display multiple time zones
Sample Database for Microsoft Office and Lotus Symphony Integration
Symphony 3.0 beta signals another attack on Office
>> Read all the news
More from the ZATZ journals
Computing Unplugged: The iPad: Apple's latest heartbreaker
David Gewirtz Online: CNN commentary and analysis
OutlookPower: Running auto-respond rules when Outlook is closed
-- Advertisement --

Learn Notes and Domino 8 at your place and pace!
Learn Notes and Domino in your office and/or home! TLCC's highly acclaimed distance learning courses for users, developers, and admins will enhance your career and your resume.

The many included activities and demos will make you a pro! Expert instructor help is a click away.

Click here to try a FREE demo course!!

-- Advertisement --

Teamstudio announces the 2010 spotlight awards winners!
We had some extraordinary submissions for the 3rd annual Teamstudio Spotlight Awards, and choosing the winners was no easy task for our judges! Click here to find out who won, and to learn more about these remarkable applications and the genius developers behind them!

Tap here for more information.
ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Editor's Login