Re: Interesting Exchange 2000/2003 problem

From: Anderson, Kelly (kjanders_at_UMICH.EDU)
Date: 03/30/04

  • Next message: Brian Arkills: "Re: Interesting Exchange 2000/2003 problem"
    Date:         Tue, 30 Mar 2004 14:09:14 -0500
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Rene -

    FWIW, this is "by design" to make it easier for users to work with
    complex ACL's by changing them to "roles" in Exchange permissions.

    Anyhow, you can change this behavior using ADSIEDIT

    MsExchDisableUDGConversion = 1 (block client-initiated conversion) or 2
    (block all conversion). 0 permits all conversion.

    - Kelly
      
    ********************************************
    Kelly J. Anderson, MCSE
    ITCS Windows Infrastructure
    University of Michigan
    http://www.umich.edu/~lannos/win2000
    ********************************************
     

      
    -----Original Message-----
    From: Windows NTBugtraq Mailing List
    [mailto:NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM] On Behalf Of Rene
    Sent: Tuesday, March 16, 2004 11:21 PM
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    Subject: Interesting Exchange 2000/2003 problem

    Environment

    Exchange 2000 or 2003 running in Native mode in a W2K AD.

    Problem

    Regular users with no rights to modify ad security groups have the
    ability to change a distribution list to a security group.

    Steps to recreate problem.

    1: User opens a mailbox with Outlook 2000 / XP / 2003
    2: Navigates to mailbox permissions
    3: Add distribution list from Gal access as contributor.
    4: Save changes

    Once the user adds the distribution list Exchange will convert the
    distribution list to a like security group

    for example if you have a All_Users universal distribution list Exchange
    will convert to a Universal Security group.
    This can cause some serious Kerberos issues if you are running close to
    the Kerberos key size limits.

    Has anyone come across this and if so have they found a solution to
    stopping this behavior?

    -----
    NTBugtraq Editor's Note:

    Want to reply to the person who sent this message? This list is
    configured such that just hitting reply is going to result in the
    message coming to the list, not to the individual who sent the message.
    This was done to help reduce the number of Out of Office messages
    posters received. So if you want to send a reply just to the poster,
    you''ll have to copy their email address out of the message and place it
    in your TO: field.
    -----

    -----
    NTBugtraq Editor's Note:

    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you''ll have to copy their email address out of the message and place it in your TO: field.
    -----


  • Next message: Brian Arkills: "Re: Interesting Exchange 2000/2003 problem"

    Relevant Pages

    • Re: Exchange Permissions Problem
      ... Be sure that the users aren't a member of a group that has an explicit Deny, ... mailboxes on Exchange 2003 SP2. ... permissions for everything, ... I create a global security group called "Exchange ...
      (microsoft.public.exchange.admin)
    • Re: Group permissions possible to open another users mailbox?
      ... only use the former if AD is in native mode. ... needs to be a member of the group Estimating. ... security group in answer to security or distribution. ... Open the properties, and if you see Exchange tabs, and e-mail addresses, ...
      (microsoft.public.windows.server.sbs)
    • Re: Outlook permissions on a security group?
      ... First thing was I was missing the obvious, the security group was email ... wonder I couldn't see it in the Outlook permissions list. ... explaining how to set advanced features on in Exchange Manager. ... Sharing a Mailbox in SBS 2003 ...
      (microsoft.public.windows.server.sbs)
    • RE: How to Assign Access/Perms. to Public Folders??
      ... Unlike Exchange 5.5, there two types of groups in AD+Exchange 2003 ... when the distribution group is used to assign permissions. ... -- Right-click on the security group, ... Microsoft Online Partner Support ...
      (microsoft.public.exchange.setup)
    • Helpdesk Delegate Permissions
      ... We recently upgraded to Exchange 2003, and want to setup the helpdesk ... personell to be able to create mail enabled objects (users, groups, ... What Exchange permissions do you need to grant? ...
      (microsoft.public.exchange.admin)

  • Quantcast