Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-03-2006, 06:42 AM
Intermediate Member
 
Posts: 18
Default Preventing admin from reading certain mailboxes

We'd like to know if there's a way to prevent the Zimbra admin from reading certain mail accounts of senior management, as their mailboxes will contain certain confidential material.

Is there a way to do this? Many thanks in advance.
Reply With Quote
  #2 (permalink)  
Old 12-03-2006, 07:51 AM
Moderator
 
Posts: 2,207
Default

No.

Anyway the messages are written on the server's harddrive in a readable format...
Reply With Quote
  #3 (permalink)  
Old 12-03-2006, 09:54 AM
Former Zimbran
 
Posts: 5,606
Default

You run into the "who polices the police" problem.

I'm sure you could file a bug enhancement request for this feature, but anyone with root access can see the eml files anyway.

You could set up a cron job to mail, rsync, or sftp the audit.log to someone. . .Allthough the log itself is still open to tampering.
Reply With Quote
  #4 (permalink)  
Old 12-03-2006, 10:32 AM
Intermediate Member
 
Posts: 22
Default

You could use an email client (thunderbird, outlook (I assume), apple mail) that supports s/mime encryption. I assume that this is not yet supported by the zimbra web interface.

Each person in the secure group would need certificates and public/private keys, which can be obtained from a certificate authority like Thawte.

You will find lots of instructions if you google s/mime thawte. Add apple to the search if you are using a mac.

Last edited by nxnw; 12-03-2006 at 10:34 AM..
Reply With Quote
  #5 (permalink)  
Old 12-03-2006, 10:46 AM
Zimbra Employee
 
Posts: 228
Default

There is an outstanding bug for fine-grained admin access control, which is slated for an upcoming release.

After it is implemented, you'll be able to say at a fine-grained level what access you want an admin to have. For example, you could grant one admin access to reset passwords on certain accounts, but not change anything else, and another admin access to create domains but not change server info, etc.

You'll also be able to grant "view mail" access to an admin on only certain mailboxes. Of course, if they have physical access to the machine and/or a root/zimbra login they will still be able to access the data.
__________________
Bugzilla - Wiki - Downloads - Before posting... Search!
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.