View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0004050 | SOGo | ActiveSync | public | 2017-02-22 13:36 | 2017-03-02 08:36 |
Reporter | rci | Assigned To | |||
Priority | immediate | Severity | minor | Reproducibility | always |
Status | new | Resolution | open | ||
Platform | [Server] Linux | OS | Debian | OS Version | 8 (Jessie) |
Product Version | 3.2.7 | ||||
Summary | 0004050: Confidential and private entries exposed in Outlook (ActiveSync) | ||||
Description | Confidential entries are handled well in web interface and Thunderbird but are fully visable in Outlook (connected with ActiveSync). In our case it's Outlook 2013. | ||||
Steps To Reproduce | Enter an event and make it either confidential (only time and date visable) or private (same permissions). | ||||
Additional Information | Also see issue 0003888 | ||||
Tags | No tags attached. | ||||
I've just tried it and it does work. That code has NOT changed in a long time. So either your SOGoCalendarDefaultRoles is wrong, you're using a SOGoSuperUsernames or the calendar permissions are wrong. Provide more evidence if you want. |
|
User is not included in SuperUsers and the permisssions weren't changed for a long time. I checked it right now. |
|
/ General / [] marks removed information; the admin accounts are not involved in the events in question. |
|
|
|
|
|
|
|
|
|
|
|
i subscribe the calender of user1. i use the same user to subscribe in outlook and thunderbird. The rights in SOGoWeb are the same for every user but i post the rights direct from the user wich i subscribed. |
|
Tested again. sogo1 shares his personal calendar with sogo3: public: view all Created 3 events from SOGo's web interface, each with a different access level. sogo3 subscribes to sogo1's calendar and active the synchronize flag to have it in Outlook. Outlook sees 2 events: the public one with all details, and the confidential one with only the title with a swapped value set at "(Confidential event)". |
|
|
|
|
|
|
|
we reproduce your way. if we do it the same way like you. it works al fine. see screenshot 2017-02-23 15:41 BUT!!! forget screenshot 2017-02-23 15:42 the event names are to confusing and a i didnt make a sync |
|
That has nothing to do with ActiveSync. When you added that ICS subscription in Outlook, it requires authentication to access it. Then, you have provided "sogo1's" credentials and NOT the credentials of "sogo3". |
|
Sorry that i lead you on the wrong track with Outlook EAS. That was our fault. i dont have to enter credentials if i add the calendar this way. Now we configure the outlook clients again with the Active Sync way on subscribed calendars. But the option is a newer one. In our roll-out version we didn't had this option. But it don't fix this security hole and it keep the door open to get information to events thats are private or confidental. If the calendar has been |
|
|
|
Done a new test again this morning, all is fine. This ticket would require investigation on the server itself. |
|
What kind of investigation on the server would you suggest? |
|
Investigation on the server itself means testing with a test account, debugging the log files, attaching to processes using gdb, reviewing configuration files, etc. That requires a valid support contract. |
|
Thank you for the information. Prior we have to wait if the decision to work with SOGo remains valid. In my opinion it should. But it's CIO's decision. It depends on the reliability of SOGo with Outlook 2013 as client. |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2017-02-22 13:36 | rci | New Issue | |
2017-02-22 13:42 | ludovic | Severity | major => minor |
2017-02-22 13:45 | ludovic | Note Added: 0011352 | |
2017-02-22 14:05 | robert.k | Note Added: 0011355 | |
2017-02-22 14:20 | rci | Note Added: 0011356 | |
2017-02-23 06:55 | rci | Note Edited: 0011356 | |
2017-02-23 07:12 | robert.k | File Added: rights_auth.png | |
2017-02-23 07:12 | robert.k | File Added: rights_public.png | |
2017-02-23 07:13 | robert.k | File Added: event_details_in_outlook.png | |
2017-02-23 07:13 | robert.k | File Added: ou_cal_user1.png | |
2017-02-23 07:13 | robert.k | File Added: tb_cal_user1.png | |
2017-02-23 07:17 | robert.k | Note Added: 0011363 | |
2017-02-23 07:22 | rci | Note Edited: 0011356 | |
2017-02-23 13:41 | ludovic | Note Added: 0011367 | |
2017-02-23 14:41 | robert.k | File Added: sogoweb_view_from_sogo3.png | |
2017-02-23 14:42 | robert.k | File Added: outlook_view_sogo3.png | |
2017-02-23 14:45 | robert.k | File Added: outlook_sogo3.png | |
2017-02-23 14:49 | robert.k | Note Added: 0011370 | |
2017-02-23 14:50 | robert.k | Note Edited: 0011370 | |
2017-02-23 14:51 | robert.k | Note Edited: 0011370 | |
2017-02-23 14:57 | ludovic | Note Added: 0011371 | |
2017-02-24 06:47 | robert.k | Note Added: 0011375 | |
2017-02-24 07:19 | robert.k | Note Edited: 0011375 | |
2017-02-24 07:20 | robert.k | Note Edited: 0011375 | |
2017-02-24 08:21 | robert.k | File Added: tb_ics.png | |
2017-02-24 08:44 | robert.k | Note Edited: 0011375 | |
2017-02-24 08:55 | robert.k | Note Edited: 0011375 | |
2017-02-28 13:47 | ludovic | Note Added: 0011388 | |
2017-03-01 06:51 | rci | Note Added: 0011391 | |
2017-03-02 01:09 | ludovic | Note Added: 0011404 | |
2017-03-02 08:36 | rci | Note Added: 0011406 |