Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-09-2011, 02:00 PM
Active Member
 
Posts: 48
Default Access control to distribution lists in Zimbra 7.

I have been playing with the CLI tools to manage access control to distribution lists. Hopefully this thread will help others and maybe get a list of all the commands to view and grant rights. So far I have been able to disable expansion/viewing and sending to distribution lists per individual email addresses. However, changes to deny sending do not take affect right away. So my questions are..

Is there a way to make the ACL changes take affect right away?

Is there a command to view all ACL's associated with a list? Not just individual email address rights?

Just for reference here are the commands I have used to grant and check rights.

Disable an address from sending to a list.

zmprov grr dl listname@domain usr user@domain -sendToDistList

Disable expansion/viewing an address to a list.

zmprov grr dl listname@domain usr user@domain -viewDistList

To check send access to a list for an address

zmprov ckr dl listname@domain user@domain sendToDistList

To check expand/view access to a list for an address

zmprov ckr dl listname@domain user@domain viewDistList

To grant send rights to only allow addresses in the list.

zmprov grr dl listname@domain grp listname@domain sendToDistList

To grant expansion/view rights to only allow addresses in the list.

zmprov grr dl listname@domain grp listname@domain viewDistList
Reply With Quote
  #2 (permalink)  
Old 02-10-2011, 03:51 PM
Active Member
 
Posts: 48
Default

Just a quick bump. Hopefully someone can give me a quick anwer to making grant rights changes take affect right away when removing sendToDistList access?
Reply With Quote
  #3 (permalink)  
Old 02-13-2011, 01:36 PM
Active Member
 
Posts: 48
Default

Still trying to get an answer to this. I'm now thinking that this is really a bug. Can someone confirm this for me? Here are the steps I used to test this.

1. Create a new distribution list and add a few addresses to the list.

2. Use the grant rights(grr) in zmprov to grant send rights to the list using said list. Check the rights of some other users who are not in the list to confirm they are denied.

3. Try to send to said list with user not on the list. They can send to the list.

4. Create a new user account and attempt to send to the list. They can send to the list.

Like I said before. The viewDistList grant right takes affect right away. The sendToDistList does not. The only way I have found to make the changes take affect is to use zmcontrol to stop and start.
Reply With Quote
  #4 (permalink)  
Old 02-15-2011, 10:46 AM
Active Member
 
Posts: 48
Default

Well, since no one is willing to help me confirm this I have gone ahead and submitted a bug for it.

https://bugzilla.zimbra.com/show_bug.cgi?id=56704
Reply With Quote
  #5 (permalink)  
Old 03-04-2011, 10:24 AM
Active Member
 
Posts: 48
Default

I opened a support case for this Feb 16th. The next day I got a reply that they would look into it. I asked for a status update via email on the 28th but I have not heard anything. I see Zimbra employee's answering questions for users of the FOSS version on these forums. Why can't I get any help as a paying customer? This feature had the most votes for this release. All I want to know is how to make the changes take effect right away or get this problem confirmed so it will be fixed in 7.0.1.
Reply With Quote
  #6 (permalink)  
Old 03-18-2011, 07:01 AM
Active Member
 
Posts: 40
Default

Hi millerdc, I've only just upgraded to 7.0.1 and I think I'm having a similar class of problem, just that its the opposite problem to you.

I've successfully granted the sendToDistList rights for internal users, and blocked public users and that took effect straight away (once the milter server was enabled after a zmcontrol restart), but I cannot seem to get viewDistList expansion working.

Tried checking rights, and restarting zimbra, no luck. Did you do anything special to get expansion working in the ZWC?

Thanks by the way for your command listing here (especially ckr); I found the cli arguments confusing.
Reply With Quote
  #7 (permalink)  
Old 03-18-2011, 07:19 AM
Active Member
 
Posts: 40
Default

hmmmm....ok part of it is perhaps my impatience. Looking at the replies in your bug, they say there is a 15min TTL on milter? I have a few expansions working now, so my rights must be correct.

But yes, a way to force refresh on ACLs faster would be nice.
Reply With Quote
  #8 (permalink)  
Old 03-18-2011, 09:50 AM
Active Member
 
Posts: 48
Default

The viewDistList has always taken affect right away. You may need to check the distribution list and make sure you do not have fide in GAL checked. You also may need to have use GAL for autocomplete checked in the admin console. I remember another settings to use email bubbles that may affect this too. You sendToDistList worked because you started the milter server after the fact. So far the only real way to have sendToDistList take affect right away is to use the "zmmtactl reload" command which restarts the milter server and loads the config.
Reply With Quote
  #9 (permalink)  
Old 03-22-2011, 04:12 PM
Active Member
 
Posts: 40
Default

Thanks, you're right hide in GAL was checked on a few dlists. sorry for thread hijack, you seem to be the only person on the forums playing with dlist permissions though!
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.