Message-ID: <29641921.1075841470729.JavaMail.evans@thyme>
Date: Sat, 3 Nov 2001 10:11:13 -0800 (PST)
From: mark.hall@enron.com
To: cooper.richey@enron.com
Subject: RE: albertapower.enron.com added to trusted sites list
Cc: faheem.qavi@enron.com, dan.dietrich@enron.com, simon.burgess@enron.com
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Bcc: faheem.qavi@enron.com, dan.dietrich@enron.com, simon.burgess@enron.com
X-From: Hall, Mark </O=ENRON/OU=NA/CN=RECIPIENTS/CN=JOEA>
X-To: Richey, Cooper </O=ENRON/OU=NA/CN=RECIPIENTS/CN=Crichey>
X-cc: Qavi, Faheem </O=ENRON/OU=NA/CN=RECIPIENTS/CN=FQAVI>, Dietrich, Dan </O=ENRON/OU=NA/CN=RECIPIENTS/CN=Ddietri>, Burgess, Simon </O=ENRON/OU=EU/cn=Recipients/cn=SBurgess>
X-bcc: 
X-Folder: \ExMerge - Richey, Cooper\infrastructure
X-Origin: RICHEY-C
X-FileName: cooper richey 6-26-02.PST

Who controls, developes and designs the activeX control?  If the control is developed in housen the component should follow and proper review/release process and then signed for production.  If this control is developed by an outside source, what is the functionality of the object?  what processes where taken to ensure the assurance of "fair-play" from a security risk evaluation point on this version and all potention upgrade versions?  And what relationship do we have with them to inquire about a signed version of their component?

Sorry for the incovienence of these queries, and I am sorry that these questions have to come from a desktop architect.  But to maintain tight security to ensure the stability for Enrons network, I think that these are important issues.

 
From Mark Hall's Blackberry

-----Original Message-----
From: Richey, Cooper <Cooper.Richey@ENRON.com>
To: Hall, Mark <Mark.Hall@ENRON.com>
CC: Qavi, Faheem <Faheem.Qavi@ENRON.com>; Dietrich, Dan <Dan.Dietrich@ENRON.com>
Sent: Fri Nov 02 16:58:08 2001
Subject: RE: albertapower.enron.com added to trusted sites list


		What is the particulars of the reasoning behind needing the site to be listed as Trusted?
		TO FACILITATE POWER AND GAS TRADERS' ACCESS TO WEB-BASED DECISION
		SUPPORT TOOLS.

		What functionality is missing or broken because it is only listed as a intranet site?
		ACCESS DATA SOURCES FROM OTHER DOMAINS

		What option in the configuration of Trusted sites facilitates the functionality that is broken or missing?
		(1) DOWNLOAD UNSIGNED ACTIVE-X CONTROLS

		are these answers satisfactory? if not, please let me know what else I can possibly do
		to get this done.   

		Cooper



	 -----Original Message-----
	From: 	Hall, Mark  
	Sent:	Friday, November 02, 2001 3:34 PM
	To:	Richey, Cooper
	Cc:	Qavi, Faheem; Dietrich, Dan
	Subject:	RE: albertapower.enron.com added to trusted sites list

	Here are few question that I think should be asked before the approval of this change be granted:
		What is the particulars of the reasoning behind needing the site to be listed as Trusted?
		What functionality is missing or broken because it is only listed as a intranet site?
		What option in the configuration of Trusted sites facilitates the functionality that is broken or missing?

	Please remit answer at your earliest convience.

	Mark Hall
	Desktop Architecture

		 -----Original Message-----
		From: 	Qavi, Faheem  
		Sent:	Friday, November 02, 2001 11:11 AM
		To:	Hall, Mark
		Subject:	FW: albertapower.enron.com added to trusted sites list

		Mark,

			Will this suffice or do you need more?  Thanks.

		Faheem A. Qavi
		Enron Net Works
		IT Security & Controls
		* Faheem.Qavi@Enron.Com  
		*  (713) 345-8338


		 -----Original Message-----
		From: 	Richey, Cooper  
		Sent:	Friday, November 02, 2001 11:09 AM
		To:	Qavi, Faheem
		Subject:	albertapower.enron.com added to trusted sites list

		please add "http://albertapower.enron.com" to the trusted sites list to facilitate power and gas traders' access to web-based decision 	support tools.  

		let me know if there are other questions/issues

		Cooper Richey
		403 974 6946