Securing Groupwise System Access; Using A Proxy Server With Client/Server Access; Using Ldap Authentication For Groupwise Users; Managing Mailbox Passwords - Novell GROUPWISE 8 - ADMINISTRATION Administration Manual

Hide thumbs Also See for GROUPWISE 8 - ADMINISTRATION:
Table of Contents

Advertisement

Securing GroupWise System
8 6
Access
Section 86.1, "Using a Proxy Server with Client/Server Access," on page 1211
Section 86.2, "Using LDAP Authentication for GroupWise Users," on page 1211
Section 86.3, "Managing Mailbox Passwords," on page 1211
Section 86.4, "Enabling Intruder Detection," on page 1212
86.1 Using a Proxy Server with Client/Server
Access
POAs in your GroupWise
users want to access their GroupWise mailboxes from outside your firewall using the Windows
client or the Linux/Mac client, you should set up a proxy server outside your firewall to provide
access, as described in
Section 36.3.1, "Securing Client/Server Access through an External Proxy
Server," on page
509. WebAccess client users access their GroupWise mailboxes through their Web
browsers, so your Web server handles the access issues for such users.
86.2 Using LDAP Authentication for GroupWise
Users
LDAP authentication provides a more secure method of mailbox access than standard GroupWise
authentication, which is the default when you set up your GroupWise system. Therefore, you should
implement LDAP authentication, as described in
for GroupWise Users," on page
On the Post Office object, the LDAP username that you provide on the Security property page
should be granted only browser rights in the eDirectory tree. The password for the LDAP user
should be long and randomly generated.
On the LDAP Server object, Require TLS for All Operations should be selected on the SSL/TLS
Configuration property page. On the LDAP Group object, Require TLS for Simple Binds with
Password should be selected.
On your LDAP servers, the trusted root certificate file should be write protected so that it cannot be
tampered with.

86.3 Managing Mailbox Passwords

GroupWise offers varying levels of password security, as described in
Passwords," on page
1151. Make sure that you understand the options available to you and that you
select the level of password security that is appropriate to your GroupWise system.
®
system should be located behind your firewall. If GroupWise client
Section 36.3.4, "Providing LDAP Authentication
514.
Section 74.1, "Mailbox

Securing GroupWise System Access

86
1211

Advertisement

Table of Contents
loading

Table of Contents