image
image

|


Go Back   macosx.com > Mac Help Forums > Mac OS X Server

Reply
 
Thread Tools
  #1  
Old July 28th, 2008, 05:45 AM
Registered User
 
Join Date: Jul 2008
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
eddg is on a distinguished road
Homedrive sync serurity issues

Hi,
I run an OSX Tiger server with both Tiger and Leopard clients connecting and using the home drive sync settings within Tiger Server.

We have found that when users and syncing their profiles/home drives they can see all the data in other users home drives (including all of the contents of the folders).

Whilst this is not having an impact on the operation of the server, it does raise security issues when the end users can see the documents held in the home drive of all other users.

The server is fully patched and the access controls prevent someone just navigating to data in a different users home drive. This only happens during the sync process which can take a while since they all have a large amount of data.
Reply With Quote
  #2  
Old July 28th, 2008, 01:25 PM
Registered User
 
Join Date: Mar 2008
Posts: 11
Thanks: 0
Thanked 0 Times in 0 Posts
cticompserv is on a distinguished road
What method are you using to sync profiles?

Kent
Reply With Quote
  #3  
Old July 29th, 2008, 02:20 AM
Registered User
 
Join Date: Jul 2008
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
eddg is on a distinguished road
Hi

Hi,

we are using the sync account for off line use in the mobility section within the user accounts admin section on the server.

cheers

Ed
Reply With Quote
Reply

Tags
security, server, sync

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


All times are GMT -5. The time now is 03:04 AM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.