Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-19-2010, 02:54 PM
Active Member
 
Posts: 26
Default Rights delegation for users

With the ZImbra 6.0 administrative rights delegation, I was hoping a problem we were working on had been solved, namely the ability to give users the ability to log into *specific* other user accounts without sharing a password. (We have some shared accounts that previously had shared passwords that had to be changed when a user left the company.)

Thus far, I've been able to successfully give a user:
* account list view (and the ability to log in to the administration console)
* adminLoginAs

But they are currently unable to *see* the account, so they can't get the View Mail button.

What privilege am I missing? I went digging through the Delegated Administration chapter of the Admin Guide 6.0, and it implied that those were the only privs I needed to give, but the example I was following was for a Domain Admin, which isn't what I'm after at all.
Reply With Quote
  #2 (permalink)  
Old 03-23-2010, 02:58 PM
Active Member
 
Posts: 26
Default Answer: Rights delegation for individual users to read mailboxes

I couldn't find any documentation on this, so I had to do some digging and some tinkering, and this is what I ended up needing to set up to get this working. We have some users who are specifically assigned to correspond with specific customers (CRMs, basically) but sometimes they go on vacation. When they do, we have requests for other CRMs to get full access to their accounts, temporarily. It also works for executive assistants who are managing things for their bosses.

Here're the rights it appears I need to delegate to make viewMail work *only* for one targeted user:

Code:
Grantee Name              | Target Name              | Target Type | Right Name
listWithPrivs@example.com | userToBeRead@example.com | account     | adminLoginAs
listWithPrivs@example.com | userToBeRead@example.com | account     | listAccount
listWithPrivs@example.com | userToBeRead@example.com | account     | getAccount
listWithPrivs@example.com | userToBeRead@example.com | account     | getAccountInfo
listWithPrivs@example.com | userToBeRead@example.com | account     | getAccountMembership
listWithPrivs@example.com | userToBeRead@example.com | account     | getMailboxInfo
listWithPrivs@example.com | userToBeRead@example.com | account     | viewAccountAdminUI
listWithPrivs@example.com | globalacltarget          | global      | listDomain
listWithPrivs@example.com | globalacltarget          | global      | listAccount
And the user has to be an administrator. We also needed to set up the zimbraWebClientAdminReference because we have proxy servers, and the zimbraPublicServiceHostname to make sure the proxy servers were what we got directed back to when clicking the ViewMail button.

It is possible I've given one or two rights extra, but we're under sufficient time constraints that I couldn't just add them one at a time. We have pretty much proven to our satisfaction that they can *only* log in to the targeted user account, and not any others, which is the main concern here. And this way, we have no sharing of passwords.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.