Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 05-15-2009, 06:02 AM
Junior Member
 
Posts: 9
Default Passwords

Is it possible for to view end users passwords, now a days with so many connections to one mail box it really sucks to have to reset it to something that could already be just verified.

Zimbra 5.0.14 on Centos 5.3
Reply With Quote
  #2 (permalink)  
Old 05-15-2009, 06:07 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by LowWalker View Post
Is it possible for to view end users passwords,...
No, of course you can't, they're encrypted for security.
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 05-15-2009, 06:18 AM
Junior Member
 
Posts: 9
Default

I mean on server side, I guess I will just have to keep side documentation

But you know what I mean? Blackberry, home PC, work PC, laptop etc...

Almost all users have at least 2 connections set and supporting your end users can get "fun".
Reply With Quote
  #4 (permalink)  
Old 05-15-2009, 06:44 AM
Moderator
 
Posts: 7,928
Default

Why not authenticate against a single source then ?
__________________
Reply With Quote
  #5 (permalink)  
Old 05-19-2009, 07:05 AM
Junior Member
 
Posts: 9
Default

I do want it to auth against a single source. But I also will be doing the end user support for this, so if they "forget" there password, I would rather be able to see it and tell them. If not, I now have to reset it, and have all their connection methods setup with the new password. Just time consuming and a drain. I will just keep a spreadsheet on the side
Reply With Quote
  #6 (permalink)  
Old 05-19-2009, 08:10 AM
Elite Member
 
Posts: 337
Default

If they authenticate against a single source, shouldn't you only have to reset 1 password? What else would you have to be resetting? Sure, the user's other connections will ask for the new password, but that's up to them to enter.
Reply With Quote
  #7 (permalink)  
Old 05-19-2009, 10:07 AM
Partner (VAR/HSP)
 
Posts: 425
Default

What he means is, you have to enter a newly issued password on many devices (iPhone, Outlook, Mac, Connectors, ...).
Reply With Quote
  #8 (permalink)  
Old 05-19-2009, 11:47 AM
Junior Member
 
Posts: 9
Default

Quote:
Originally Posted by interways View Post
What he means is, you have to enter a newly issued password on many devices (iPhone, Outlook, Mac, Connectors, ...).
Yeaaaah! If I give them the option to change their password, thats fine... if I can see it so when they mess up their account, break their blackberry or whatever other 100 things that happen I can be prepared to tell them what it is.

Effectively allowing me to only help them setup access on device, instead of all.
Reply With Quote
  #9 (permalink)  
Old 05-19-2009, 07:57 PM
Partner (VAR/HSP)
 
Posts: 67
Default

I'll just add my 2 cents, take it or leave it. I completely understand where you are coming from with this, as it has caused me issues while supporting users. But, passwords aren't encrypted ONLY for technical security.

I've dealt with this question many time and the major reason that I refuse to know user's passwords is from a liability standpoint. If there is a way that I can figure out a user's password, I can 'masquerade' as that user. If there isn't a way to figure the password out (i.e. hashing), then if a user performs an action, I have a level of recourse (non-repudiation), as they are suppose to be the only one who knows the password to the account.

Not to mention, how do you securely store all of your user's passwords. I know this isn't a big challenge for some, but I've seen more than a few "secret notebooks" or massive spreadsheets.

Once again, I'm not stating this to be a jerk. Just some background...

Cheers,
Dusty
__________________
CoSentry - www.cosentry.com - Co-Location & Business Resiliency Solutions
Reply With Quote
  #10 (permalink)  
Old 05-20-2009, 05:36 AM
Junior Member
 
Posts: 9
Default

I understand the risk, but if you have had to support end users... you get what I mean. I suppose I couldnt encrypt a USB flash drive with the file and keep it on my key chain if audit time rolls around

Also I am new admin to zimbra, are there any extensions that are good for server or user monitoring besides whats in the package?
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.