Page 1 of 2 12 LastLast
Results 1 to 10 of 11

Thread: Access control to distribution lists in Zimbra 7.

Hybrid View

  1. #1
    Join Date
    Oct 2008
    Location
    San Diego
    Posts
    48
    Rep Power
    7

    Default Access control to distribution lists in Zimbra 7.

    I have been playing with the CLI tools to manage access control to distribution lists. Hopefully this thread will help others and maybe get a list of all the commands to view and grant rights. So far I have been able to disable expansion/viewing and sending to distribution lists per individual email addresses. However, changes to deny sending do not take affect right away. So my questions are..

    Is there a way to make the ACL changes take affect right away?

    Is there a command to view all ACL's associated with a list? Not just individual email address rights?

    Just for reference here are the commands I have used to grant and check rights.

    Disable an address from sending to a list.

    zmprov grr dl listname@domain usr user@domain -sendToDistList

    Disable expansion/viewing an address to a list.

    zmprov grr dl listname@domain usr user@domain -viewDistList

    To check send access to a list for an address

    zmprov ckr dl listname@domain user@domain sendToDistList

    To check expand/view access to a list for an address

    zmprov ckr dl listname@domain user@domain viewDistList

    To grant send rights to only allow addresses in the list.

    zmprov grr dl listname@domain grp listname@domain sendToDistList

    To grant expansion/view rights to only allow addresses in the list.

    zmprov grr dl listname@domain grp listname@domain viewDistList

  2. #2
    Join Date
    Oct 2008
    Location
    San Diego
    Posts
    48
    Rep Power
    7

    Default

    Just a quick bump. Hopefully someone can give me a quick anwer to making grant rights changes take affect right away when removing sendToDistList access?

  3. #3
    Join Date
    Oct 2008
    Location
    San Diego
    Posts
    48
    Rep Power
    7

    Default

    Still trying to get an answer to this. I'm now thinking that this is really a bug. Can someone confirm this for me? Here are the steps I used to test this.

    1. Create a new distribution list and add a few addresses to the list.

    2. Use the grant rights(grr) in zmprov to grant send rights to the list using said list. Check the rights of some other users who are not in the list to confirm they are denied.

    3. Try to send to said list with user not on the list. They can send to the list.

    4. Create a new user account and attempt to send to the list. They can send to the list.

    Like I said before. The viewDistList grant right takes affect right away. The sendToDistList does not. The only way I have found to make the changes take affect is to use zmcontrol to stop and start.

  4. #4
    Join Date
    Oct 2008
    Location
    San Diego
    Posts
    48
    Rep Power
    7

    Default

    Well, since no one is willing to help me confirm this I have gone ahead and submitted a bug for it.

    https://bugzilla.zimbra.com/show_bug.cgi?id=56704

  5. #5
    Join Date
    Oct 2008
    Location
    San Diego
    Posts
    48
    Rep Power
    7

    Default

    I opened a support case for this Feb 16th. The next day I got a reply that they would look into it. I asked for a status update via email on the 28th but I have not heard anything. I see Zimbra employee's answering questions for users of the FOSS version on these forums. Why can't I get any help as a paying customer? This feature had the most votes for this release. All I want to know is how to make the changes take effect right away or get this problem confirmed so it will be fixed in 7.0.1.

  6. #6
    Join Date
    Mar 2007
    Posts
    45
    Rep Power
    8

    Default

    Hi millerdc, I've only just upgraded to 7.0.1 and I think I'm having a similar class of problem, just that its the opposite problem to you.

    I've successfully granted the sendToDistList rights for internal users, and blocked public users and that took effect straight away (once the milter server was enabled after a zmcontrol restart), but I cannot seem to get viewDistList expansion working.

    Tried checking rights, and restarting zimbra, no luck. Did you do anything special to get expansion working in the ZWC?

    Thanks by the way for your command listing here (especially ckr); I found the cli arguments confusing.

  7. #7
    Join Date
    Mar 2007
    Posts
    45
    Rep Power
    8

    Default

    hmmmm....ok part of it is perhaps my impatience. Looking at the replies in your bug, they say there is a 15min TTL on milter? I have a few expansions working now, so my rights must be correct.

    But yes, a way to force refresh on ACLs faster would be nice.

  8. #8
    Join Date
    Oct 2008
    Location
    San Diego
    Posts
    48
    Rep Power
    7

    Default

    The viewDistList has always taken affect right away. You may need to check the distribution list and make sure you do not have fide in GAL checked. You also may need to have use GAL for autocomplete checked in the admin console. I remember another settings to use email bubbles that may affect this too. You sendToDistList worked because you started the milter server after the fact. So far the only real way to have sendToDistList take affect right away is to use the "zmmtactl reload" command which restarts the milter server and loads the config.

  9. #9
    Join Date
    Mar 2007
    Posts
    45
    Rep Power
    8

    Default

    Thanks, you're right hide in GAL was checked on a few dlists. sorry for thread hijack, you seem to be the only person on the forums playing with dlist permissions though!

  10. #10
    Join Date
    Jul 2012
    Posts
    1
    Rep Power
    3

    Default

    Hi millerdc
    though its more than a year old thread, but even today with Zimbra7.2 I still am stuck with the same issue, distribution list access control. I did everything that you mentioned here and followed all the comments in bugzila too, but when i create a new DL no matter what i do, everybody inthe world has the right to send email to it
    I refresh the milter, shutdown and startup zmcontrol, wiat for 20 minutes but nothing, even gmail and yahoo can still send emails.
    Though on ckr command it shows selected people as ALLOWED and rest DENIED, but still allows to send email.
    My questions:
    when creating a new DL, do you check mark on "Can receive mail" and "hide GAL"
    i guess as soon as we create a new DL it is open to all, but as we give a single access right (ALLOWED) it turns everybody as DENIED and keeps only the selected person allowed (only for displaying status level).

    Please suggest somethiing for me

Similar Threads

  1. Replies: 21
    Last Post: 02-04-2010, 10:06 AM
  2. I have problems with en language in zimbra 5.01
    By yuranchik in forum Installation
    Replies: 0
    Last Post: 01-24-2008, 03:23 AM
  3. Replies: 22
    Last Post: 12-02-2007, 05:05 PM
  4. Post instsallation problems
    By Assaf in forum Installation
    Replies: 14
    Last Post: 01-29-2007, 11:38 AM
  5. Unable to start tomcat
    By chanck in forum Administrators
    Replies: 11
    Last Post: 06-11-2006, 01:58 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •