Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-13-2011, 12:07 AM
j2b j2b is offline
Special Member
 
Posts: 109
Default Rewriting username data in REST url or e-mail address is disclosed

We noticed, that our ZCS users start sharing their resources over internet (e.g. sharing Briefcase folders with images). There are several uses:

- putting links to such resources (View only) on forums over internet;
- sharing such resources in their websites (photos or calendars).

ZCS in this case is working OK. But the problem arrieses in disclosing usernames to public in such cases. Because of multidomain installation, we use single https URL for login for all domains, and provide full e-mail address as a username.

Because we can not guaranty correct operations of such internet resources, where such links are posted, nor there are widely available rewrite functions, as such username does not displays in a single e-mail manner, to be hidden by e.g. SpamSpan, or a like, there is a potential for such e-mail address harvesting for SPAM list generation purposes.

I am aware of a "virtual hosts" possibility, but this does not solve an issue, as it increases expenses per domain due to SSL certs and in final, still does not hide potential combination of user's e-mail address, as username (Account name) is e-mail address data to the left of "@" symbol.

Could somebody recommend any solution or personal practice for this?
Reply With Quote
  #2 (permalink)  
Old 07-18-2011, 02:01 AM
j2b j2b is offline
Special Member
 
Posts: 109
Default

I recently stepped over this new zimlet: Short URL for Briefcase | Zimbra :: Gallery

But still, this issue is active. Any other solutions to build it in-house and integrate with Zimbra?
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.