[Kolab-devel] Correct Free/Busy URL for Outlook

Henning Holtschneider henning at loca.net
Mon Apr 11 15:21:59 CEST 2005


On Monday 11 April 2005 15:02, Joon Radley wrote:

> Is there a way to disable or avoid the need for a user name and password as
> in the Free Busy URL shown below? This URL transmits the password over an
> unencrypted channel.

It *should* work over HTTPS, too. But at least my Outlook 2003 SP1 only shows 
an error bubble on the taskbar when trying to fetch free/busy information 
over HTTPS. This happens even though I installed the CA certificate from the 
Kolab server on the workstation.

Anyway, I think transmitting the password unencrypted is not a problem here 
because there are much more severe issues:

- A normal user will never be able to change her/his password because the URL 
syntax is too complicated.

- If the password uses characters that have to be specially encoded to 
represent a valid URL, the user will have to know how to encode them 
correctly.

For most installations, it will most likely be best to remove the 
authentication from the free/busy URI on the server. The free/busy lists are 
no secret anyway.

Regards,
Henning Holtschneider
--
LocaNet oHG - http://www.loca.net
Lindemannstrasse 81, D-44137 Dortmund
tel +49 231 91596-25, fax +49 231 91596-55
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 197 bytes
Desc: not available
URL: <http://lists.kolab.org/pipermail/devel/attachments/20050411/5bbf8fdf/attachment.sig>


More information about the devel mailing list