22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

you open another database which resides in another directory, for example<br />

yourserver/help/help5_client.nsf, you will be prompted to authenticate again<br />

since yourserver/help is not a subdirectory of yourserver/mail.<br />

To avoid users being prompted to authenticate multiple times, and to avoid the<br />

security risk of saved passwords when using such basic authentication, you can<br />

enable session authentication on Domino.<br />

Cached authentication credentials<br />

Many browsers store both logon credentials and private data in memory, typically<br />

up to 30 pages, which are not reliably discarded until the browser is closed. The<br />

browser remembers the user’s authentication information while it is still open.<br />

iNotes Web Access provides a “Logout” button that closes the entire browser<br />

session, discards the in-memory files, and tries to close the browser window.<br />

This facility aims to prevent anyone from accessing the user’s mail file by hitting<br />

the “back” button on the browser’s navigation bar to view personal information<br />

from the previous screen while their browser is open and unattended. When all<br />

browser windows are closed, cached files are removed from the browser’s cache,<br />

so that no one can access the user’s personal iNotes Web Access data.<br />

However, there are certain types of personal data that will not be removed unless<br />

the user explicitly empties the temporary Internet files folder through the<br />

appropriate menu command in the browser being used.<br />

Attention: Users should make sure that they close all active browser<br />

windows. iNotes Web Access secure logout will close the active browser<br />

window, but not necessarily all browser windows.<br />

Access level to Forms5.nsf database<br />

Forms5.nsf is one of the databases that is part of iNotes Web Access. It contains<br />

most of the JavaScript, pass-thru HTML and images used to implement the user<br />

interface of iNotes Web Access.<br />

In order for iNotes Web Access to function correctly, make sure that Anonymous<br />

is assigned Reader access to the database {server’s data<br />

directory}\iNotes\Forms5.nsf. You will not see an entry for this database in the<br />

Catalog.nsf database, but you can find the database using the Domino<br />

Administrator → Files tab or by creating a bookmark into your Notes bookmarks<br />

folder.<br />

Enabling anonymous access to this database does not present any security risk<br />

since only the common user interface components that make up the iNotes<br />

interface are contained in this database.<br />

Chapter 12. Security features of other Lotus products 551

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!