Connect. Communicate. Collaborate. Securely.

Home » Kerio User Forums » Kerio Connect » security flaw or feature? (security flaw or feature?)
  •  
bandicootltd

Messages: 33
Karma: 3
Send a private message to this user
Hi

I have Kerio in a hosted environment with multiple companies each with their own domain. Inside each domain are multiple users. I always assumed that each domain is completely independent of each other. I have just found out that the calendar of one user in one domain is visibile and writable by all other users in all others domains. It looks like when you share a folder, you are able to share with an everyone group which not only shares with everyone in their domain, but across all domains on the server. Am I missing something? I would have thought that whilst this may be a required feature for some, it is more likely the default would be my hosting scenario. I have looked all round the admin area but cant find any way of keeping all domains absolutely independent.

Anyone know of a fix?
Anyone else concerned by this feature since they also have multiple businesses hosted on one server?
Anyone know of a way of finding out who else has shared folders with everyone?

BTW I have looked through the forum but cant find anyone else asking about this.
  •  
zebby

Messages: 234
Karma: 1
Send a private message to this user
What rights have been assigned to the shared calendar?


  •  
freakinvibe

Messages: 1508
Karma: 58
Send a private message to this user
That's strange. If I share a public contacts folder, I can choose to share it with:


  • A specific user
  • A user group
  • All users from this domain
  • All users on all domains


Are you saying you don't have that choice in the drop-down menu?

Dexion AG - The Blackberry Specialists in Switzerland
https://dexionag.ch
  •  
bandicootltd

Messages: 33
Karma: 3
Send a private message to this user
In sharing I have

User
Group
Authenticated User from domain
Authenticated User
Everyone

A non-techie end user in a hosted environment will assume that everyone means everyone in his company and not everyone including people outside his/her organisation.
  •  
freakinvibe

Messages: 1508
Karma: 58
Send a private message to this user
You have to educate the user to use

Authenticated User from domain

While this might not be very well named by Kerio, you have to live with it for the moment.

Dexion AG - The Blackberry Specialists in Switzerland
https://dexionag.ch
  •  
bandicootltd

Messages: 33
Karma: 3
Send a private message to this user
The above list was from Outlook 2010. I have just had a look at the list when sharing via webmail and...

User
Group
All Users from Domain
All Users
Anonymous Access

On top of it not being particularly clear for non-techies in a hosted environment, there is also no consistency. Makes it very difficult to educate when it is different depending on how they access and share their mail.

Is there any way of finding out who has shared folders with people outside the domain ie

Authenticated User
Everyone
All Users
Anonymous Access?
Previous Topic: V7.5 and Internet Explorer
Next Topic: Spam Thumbs Problem
Goto Forum:
  


Disclaimer:
Kerio discussion forums are intended for open communication between forum members and may contain information and material posted by members which may be useful in learning about Kerio products. The discussion forums are not intended to provide technical support for any specific product. Any information implied or expressed in the discussion forums is that of the posting member. Kerio is in no way responsible for the information posted in the forums, or its accuracy. Kerio employees may participate in the discussions, but their postings do not represent an offical position of the company on any issues raised or discussed. Kerio reserves the right to monitor and maintain the forums to promote free and accurate exchange of information.

Current Time: Fri Aug 18 21:59:34 CEST 2017

Total time taken to generate the page: 0.00421 seconds
.:: Contact :: Home ::.
Powered by: FUDforum 3.0.4.