Skip to main content
This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal

HCL Notes/Domino 8.5 Forum (includes Notes Traveler)

HCL Notes/Domino 8.5 Forum (includes Notes Traveler)

Previous Next
Subject: Traveler Security Flaw?
Feedback Type: Problem
Product Area: Notes Traveler
Technical Area: Accessibility
Platform: Windows
Release: 8.5.3
Reproducible: Not attempted

I recently was notified that a couple of my Traveler users were receiving new devices. Rather than keep the Traveler database cluttered with multiple devices, I used the "Tell Traveler Delete {device} {username}" to remove the device that was no longer supposed to be used.

Today I noticed one of the deleted users, who activated his new device, apparently activated the previous devices he had been using.

Now, this might not be a problem if we were allowing everyone to activate devices, or authorized people to activate as many devices as they wanted to. However, I have the security set that each user can activate a SINGLE device, then any further devices require approval.

Have I discovered a security flaw? Is a previously activated device still considered 'approved' if that device is deleted from the server and the user re-activates it, after having activated another device (which is considered approved)?

We are wanting to allow users to activate only ONE device. We already had an allowed user attempt to activate a personal device, and the approval process caught it, asking us to allow. However, this user activated their new device, and then apparently tried to activate their previous device, and it was allowed, instead of requiring Admin Approval.

Brian


Feedback number WEBB8VHLZN created by ~Julia Quetjipytexings on 06/22/2012

Status: Open
Comments:

Traveler Security Flaw? (~Julia Quetjipy... 22.Jun.12)
. . re:Traveler Security Flaw? (~Alexis Asanist... 22.Jun.12)
. . . . Tell traveler security delete <devi... (~Julia Quetjipy... 22.Jun.12)
. . . . . . RE: Tell traveler security delete <... (~Manny Ekrevero... 25.Jun.12)




Printer-friendly

Search this forum

Member Tools


RSS Feeds

 RSS feedsRSS
All forum posts RSS
All main topics RSS