22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

530 Lotus Security Handbook<br />

For information on securing the server console with a Smartcard reader, see the<br />

Domino 6 Administration Guide.<br />

Requirements for effective Smartcard use<br />

► Before users can install Smartcard readers, it is critical that you disable<br />

password checking, change/grace intervals, and password expiration in the<br />

Person documents of Smartcard users. Otherwise, those users will eventually<br />

be locked out and unable to log in to their home server.<br />

► Ensure that user IDs are re<strong>cover</strong>able via ID File Re<strong>cover</strong>y before enabling<br />

them for SmartCard use.<br />

11.14.2 Execution Control Lists<br />

An Execution Control List (ECL) protects user workstations against active<br />

content from unknown or suspect sources, and can be configured to limit the<br />

action of any active content that is allowed to run on workstations. The ECL<br />

determines whether the signer of the code is allowed to run the code on a given<br />

workstation, and defines the access that the code has to various workstation<br />

functions. For example, an ECL can prevent another person's code from running<br />

on a computer and damaging or erasing data.<br />

“Active content” includes anything that can be run on a user workstation,<br />

including formulas; scripts; agents; design elements in databases and templates;<br />

documents with stored forms, actions, buttons, and hot spots; as well as<br />

malicious code (such as viruses and so-called “Trojan horses”).<br />

There are two kinds of ECLs: the Administration ECL, which resides in the<br />

Domino Directory (NAMES.NSF); and the workstation ECL, which is stored in the<br />

user's Personal Address Book (NAMES.NSF). The Administration ECL is the<br />

template for all workstation ECLs. The workstation ECL is created when the<br />

Notes client is first installed. The Setup program copies the administration ECL<br />

from the Domino Directory to the Notes client to create the workstation ECL.<br />

A workstation ECL lists the signatures of trusted authors of active content. “Trust”<br />

implies that the signature comes from a known and safe source. For example,<br />

every system and application template shipped with Domino or Notes contains<br />

the signature Lotus Notes Template Development. Likewise, every template and<br />

database that your organization designs should contain the signature of either<br />

the application developer or the administrator. For each signature, the ECL<br />

contains settings that control the actions that active content signed with that<br />

signature can perform and the workstation system resources it can access.<br />

If active content attempts an action that is not enabled for the signer, or if the<br />

signer is not listed in the ECL, Notes generates an Execution Security Alert

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!