22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

450 Lotus Security Handbook<br />

organization uses. In addition, the service provider administrator must create and<br />

maintain a mechanism that the hosted organization's administrators use to<br />

communicate problems and issues that require the intervention of the service<br />

provider administrator.<br />

Securing the Domino service provider environment<br />

The Domino service provider environment uses all of the standard Domino<br />

security features to ensure complete security for the service provider and the<br />

hosted organizations that subscribe to the service provider’s services. An xSP<br />

environment that has multiple hosted organizations has potentially thousands of<br />

users whose access must be restricted to their own data only.<br />

In addition, the service provider configuration uses extended ACLs in the Domino<br />

Directory to protect the data of each hosted organization from access by users in<br />

other hosted organizations. The extended ACLs required to support the xSP<br />

security model are automatically established when new hosted organizations are<br />

created. Plan and test carefully if you want to modify ACLs and extended ACLs in<br />

an xSP environment – security is extremely important.<br />

The authentication controls in Site documents control only who can authenticate<br />

and use the Internet protocols. After authentication, ACLs and extended ACLs<br />

control the data that can be read from and written to the Domino Directory.<br />

A user in a hosted organization cannot directly access databases in any<br />

subdirectories other than the hosted organization's directory. Exceptions are the<br />

“help” and “common” subdirectories of the Domino data directory, which contain<br />

databases accessible to users in all hosted organizations.<br />

To provide users with access to databases outside those of the hosted<br />

organization's subdirectory, create a directory link within the hosted<br />

organization's directory.<br />

11.4 Roaming users<br />

New for<br />

Domino 6<br />

Users who access Notes from more than one Notes client can access their<br />

customized settings and personal information automatically from any Notes<br />

client in the domain. Data for these users, known as roaming users, replicates<br />

between the user's machine and a roaming user server, where these files are<br />

stored. When a roaming user logs on from a different Notes client, it<br />

automatically retrieves the user's ID file, Personal Address Book, bookmarks,<br />

and journal from the roaming user server. Any changes the user makes in these<br />

files replicate to the roaming user server. This enables the roaming user to have<br />

a consistent experience from any Notes client.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!