SECURITY
"Active content" includes anything that can be run on a user workstation, including formulas; scripts; agents; design elements in databases and templates; documents with stored forms, actions, buttons, hot spots; as well as malicious code (such as viruses and so-called "Trojan horses").
There are two kinds of ECLs: the Administration ECL, which resides in the IBM® Lotus® Domino™ Directory (NAMES.NSF), and the workstation ECL, which is stored in the user's Contacts (NAMES.NSF). The Administration ECL is the template for all workstation ECLs. The workstation ECL is created when the IBM® Lotus® Notes® client is first installed. The Setup program copies the administration ECL from the Domino Directory to the Lotus Notes client to create the workstation ECL.
The workstation ECL
A workstation ECL lists the signatures of trusted authors of active content. "Trust" implies that the signature comes from a known and safe source. For example, every system and application template shipped with Domino or Lotus Notes contains the signature Lotus Notes Template Development. Likewise, every template and database that your organization designs should contain the signature of either the application developer or the administrator.
For each signature, the ECL contains settings that control the actions that active content signed with that signature can perform and the workstation system resources it can access.
For a description of ECL access options, see ECL security access options.
1. Choose File - Security - User Security. Macintosh OS X users: Notes - Security - User Security.
2. Click What Others Do, and select either Using Workstation, Using Applets, or Using JavaScript.
When active content runs on a user workstation and attempts a potentially harmful action -- for example, programmatically sending mail -- the following occurs:
1. Lotus Notes verifies that the active content is signed and looks up the signer of the code in the workstation ECL.
2. Lotus Notes checks the signer's ECL settings to determine whether the action is allowed.
3. One of the following occurs:
Determining effective access
Users can also determine the "effective access" that a person or a group has to the workstation ECL by clicking the 'Effective Access' button on an ECL. Effective access is not always apparent, especially if users enable ECL access for a Lotus Notes session. For example, a user may grant temporary access to a group that designed a database application in which the user is working. This access is valid for the duration of a session, but a session might last all day.
Note If you restrict users' abilities to change their ECL, the "Effective Session ECL" button will be grayed out.
See also