[Kolab-devel] Re: Free busy information

Bernhard Reiter bernhard at intevation.de
Thu Sep 2 13:54:43 CEST 2004


On Thursday 02 September 2004 08:58, Bo Thorsen wrote:
> On Thursday 02 September 2004 08:32, Martin Konold wrote:
> > Am Donnerstag, 2. September 2004 08:19 schrieb Bo Thorsen:


> > > On Thursday 02 September 2004 08:07, Martin Konold wrote:
> > > > Am Mittwoch, 1. September 2004 13:29 schrieb Bo Thorsen:
> > > > > security risk in that or not. If we can come up with a secure way
> > > > > of doing it, I would agree with them that this is the best
> > > > > solution.
> > > >
> > > > The currently discussed schema is secure by default because the
> > > > freebusy generating server code runs with the credentials of the
> > > > client asking for it.

> > > I know. I'm thinking about the server generating all of it.

Bo's original comment considered creating all freebusy list
information on the server with a user that can read 
all the folders (it needs for creation).
This "freebusy" user would have a lot of credentials.

> I'm still not dismissing the possibility of generating all fb information
> on the server. It's a potential security problem, but coding wise it's by
> far the most simple solution.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2145 bytes
Desc: signature
URL: <http://lists.kolab.org/pipermail/devel/attachments/20040902/916a8611/attachment.p7s>


More information about the devel mailing list