About this Article:
Anyone with read-only access to the NAB on a default configuration Domino server can get a listing of all users defined in the system -- including the HTTPPassword hash of their passwords. If that concerns you, this article shows you how to use Extended Access Control Lists to boost Web user security.
Technical Editor Terrance A. Crow is the assistant vice president of technology at Corporate One, a corporate credit union in Ohio. He has been a Lotus Notes developer since the 3.x days under OS/2 and now uses Lotus Notes/Domino to build client-server and Web e-commerce solutions. He's also busily building solutions based on open source-based tools.
More importantly, he's married to a genius genealogist and is the father of a son just got his driver's license and a daughter who is mastering music when she isn't writing books. terrance@interstell.com. terrance@interstell.com.