Failure of ACL setting for CIFS share resource on Windows client logined with administrator account

Hi,
  We accounter a puzzle of ACL setting for a CIFS share resource. In our application, we use the
administrator account to login a Windows 7 OS which is used as the CIFS client. We can access the share resource by "\\server_ip" on  this CIFS client,  but we can't add
a new ACE to the ACL of a CIFS share resource provided by a CIFS server.
Why dose this hanppen? Note that the CIFS server maybe a Windows OS or a self-developed CIFS server. 
  The operation details as followed:
1.Access the share resource by "\\server_ip", login the CIFS server by a valid account on the CIFS server.
2.On the Windows client, select the "Security" panel in the mouse-right-button properties dialog of a cifs share resource.
3.To add a new ACE for someone eg. user0, we input "user0" in the "Select Users ans Groups" dialog popped up.
4.Click OK, but the Windows client will not get the user information for user0 from the CIFS server.
WHY?
5.By wireshare network trace, we find the Windows client didn't send any SAMR requests to the CIFS server.
6.Restart the Windows client OS and login again with another account except administrator, carry out the above operations. We find that the Windows client can get the user information, opposite with the step 4 above.
WHY?
7.By wireshare network trace, we find that the Windows client has sent SAMR requests to the CIFS server to get user informations. But that is different from step 5,  WHY?
If the Windows client OS is login with administrator account, is there any configuration on Windows client to decide whether request user information on CIFS server when setting ACL for CIFS share resource?
Expect your help.Thanks.
Best wishes.

The purpose of this forum is to support the Open Specifications documentation. You can read about the Microsoft Open Specifications program here,
http://www.microsoft.com/openspecifications/en/us/default.aspx
The library of Open Specification documents is located here,
http://msdn.microsoft.com/en-us/library/dd208104.aspx
It doesn’t appear that you are implementing one of the protocols cited.  Your question may be more applicable to Technet's Windows Server Platform Networking forum at
https://social.technet.microsoft.com/Forums/en-US/home?forum=winserverPN or the File Services and Storage forum at
https://social.technet.microsoft.com/Forums/en-US/home?forum=winserverfiles.
If you are working on implementing a protocol using the specifications cidet above, please provide more detail.
Bryan S. Burgin Senior Escalation Engineer Microsoft Protocol Open Specifications Team

Similar Messages

  • Can I set my kids up under my apple ID but with separate accounts so they all have their own cloud memory?

    can I set my kids up under my apple ID but with separate accounts so they all have their own cloud memory?

    YYes.  https://www.apple.com/support/icloud/family-sharing/
    BUt separate I'd for imessage, icloud and FaceTime.

  • "Block EDIT option*" for all WEBI Reports with Administrator Account

    Hi,
    I had opening CMC with Administrator Account.Due to some reasons i want to "Block EDIT option" for all WEBI Reports.Just Viewing is sufficient.In the same way for Universe"Blocking EDIT object option".Instead of Administrator guide reference (chap no 18 &19)option.Could you help in steps resolving issue.Thanks in advance.
    Regards,
    Swapna.

    Hi Swapna,
    You could perform the following steps:
    1. Login to CMC.
    2. Go to Folders >> Manage >> Top Level Security
    3. Click on Add Principal and add the user or group for which you have to set the security.
    4. Click on assign Security >> Advanced tab >> Add/Remove Rights.
    5. Select Content >> Web Intelligence Report
    6. assignt "Edit Object" right as denied and click on apply ok.
    This would help you to block edit option for only webi reports and all the webi reports in your environment.
    Regards,
    Nakul

  • When i login with microsoft account cannot access with administrative share c$

    i have a problem when i login to windows with microsoft account cannot access any network computer with administrative sharing c$,d$ with windows 8.1 
    but when i login with local account can access
    and some people tell  me create key in regedit t fix it 
    after enter user name and password show this error 
    and i apply your instruction  and not fix until now
    note:
     my Machine windows 8.1 if another machine in network windows 7 can access a hidden share if machine in network windows 8.1 show this message in image 2 
    but if i login with local user can i access all machine hidden share network windows 7 and 8.1

    yes this computer i want to access  name poland2-work and have two users 
    first :administrator
    second : poland 2

  • How do I share the music of my library with another account on same computer

    how do I share the music of my library with another account on same computer

    How to share music between different accounts on a single computer

  • Hello, i ordered 2 32GB white iphone 4s online as a guest user. The mobiles has been delivered, but i cant print the invoice for that. They ask me to login with the apple ID. But as i mentioned i logged in as guest so there's no AppleID associated. HELP !

    Hello, i ordered 2 32GB white iphone 4s online as a guest user. The mobiles has been delivered, but i cant print the invoice for that. They ask me to login with the apple ID. But as i mentioned i logged in as guest so there's no AppleID associated. HELP !

    Contact Apple customer support via the "Contact Us" link at the bottom, they may be able to assist you.

  • Lanovo ix4 300d and european character set for samba shares

    Hi,
    I am installing a couple of IX4-300d at a client site, struggling to set and fix the samba character set for the Windows shares. Here in Italy everyone is used to put western european characters into filenames (for example è ò ° €) but the NAS acts wierdly when it finds such caracters in folder names and file names.
    As you know samba gives the possibility to declare dos charset= ISO8859-1 and unix charset= ISO8859-1 in the smb.conf file but the option is not present in the IX4 setup pages.
    Is there an easy way to circumvent the problem and fix this option? As it is now the machine is fearly useless, at least if you need to migrate files and folder from a server or storage with ISO8859 charset already applied.
    thanks a lot
    np
    Solved!
    Go to Solution.

    This issue has been raised on all iomega drives since day 1. although 'documented' it is still shame, that units sold to 'r-o-w' means rest-of-world, outside US, are stuckto Aa-Zz09 basically wheras client systems ( windows, linux, ios ) don't care and take what they are supposed to do.
    Take it or leave it. ( I mean, take another vendor), I do not believe someone ever has taken that seriously or will do it......
    Various PCs / Laptops ( sorry I still really love Dell and Fujitsu ;-))
    Supporting Customers ix2s and ix4s -- Love Networking ( not only technically ).
    I am not a Lenovo Employee.
    If you find a post helpful and it answers your question, please mark it as an "Accepted Solution"!

  • Factory set password for Windows Vista built-in administrator account?

    I am attempting access the Vista built-in administrator account, which normally is not passworded unless the user does so. Mine, however, has a password that was set 11/20/2010 at 9:57:24 PM.
    Was this p/w set by Toshiba? I assume so, as it was purchased directly from Toshiba. If so, any idea what that p/w would be?  I need to use this account to recover my own admin account due to this error: The User Profile Service failed the logon. User profile cannot be loaded.
    Machine is a Satellite P300 S/N 29020124W, Part # PSPC8U-01G00Q.
    Thanks.

    Satellite P300-ST3712
       You receive a "The User Profile Service failed the logon” error message
        How to Fix the Error "Your user profile was not loaded correctly! You have been logged on with a tem...
    Was this p/w set by Toshiba?
    No. But some programs like the Google Updater (if you added the Google Toolbar, Chrome or Google Earth) have been known to cause this problem. 
    -Jerry

  • For Your Consideration: Ultimate Lync 2010 client install with SCCM 2007

    While the subject of my post may be very presumptuous, I submit the following for your consideration to answer the often-asked question about how to deploy Lync 2010 client with SCCM.
    Background:
    I cannot understand why Microsoft made the Lync install so darned confusing, complex, and convoluted.
    After our Lync 2010 FE server was up and running and all users migrated off our OCS server to the Lync environment, I spent about a month and a half trying to figure out how to:
    1.  Uninstall the OCS 2007 R2 client
    2.  Install all prerequisites for the Lync client
    3.  Install Lync on all user workstations silently.
    While researching this, the simple answer I kept seeing given to this question was, "just use the .exe with the right switches according to the TechNet article here: http://technet.microsoft.com/en-us/library/gg425733.aspx".  Well, my response is, I
    tried that and while the program installed itself correctly pushed through SCCM, because I was doing it using an administrative account (i.e. the SYSTEM account) due to our users not having admin rights, when the install was done, Lync would automatically
    start up, but in the SYSTEM context so that the user couldn't see it was running, they go to run it and it won't run for them.  I was unable to find any switch or option to prevent the automatic launch.  I suppose the simple solution to that would
    be to have the user reboot, but that's unnecessarily disruptive and was contrary to the desire to make this a silent install.
    The next simplest answer I saw was, "extract the MSI and use that with the right switches".  Problem with that is that the MSI by itself doesn't remove the OCS client or install the prerequisites, and also either requires a registry change to even allow
    the MSI to be used or a hacked MSI that bypasses the registry key check.  I tried to put a package together to uninstall OCS, install the prereqs, and use a hacked MSI, but I never could get the MSI hacked properly.  The other problem I ran into
    was detecting if the OCS client was running in a predictable way so I could terminate it, properly uninstall it, and then do the rest of the installations.  It was this problem that ultimately led me to the solution that I'm about to detail and that has
    worked marvellously for us.
    Solution:
    As I said before, when I first looked at this problem, I started by building a typical software deployment package (Computer Management -> Software Distribution -> Packages) and then created the programs to do the install.  My first attempt was
    just with the .exe file provided as-is by Microsoft using the switches they document in the link above for IT-Managed Installation of Lync, and...well, the end result wasn't quite as desirable as hoped.  So, my next attempt was to extract all the prerequisite
    files and the Lync install MSI (both for x86 and x64), attempt to hack it to get around the "UseMSIForLyncInstallation" registry key, and make the command-lines to terminate OCS and uninstall it.
    In the past when I had an install to do with SCCM that also required uninstalling an older version of a given application, I typically used the program-chaining technique.  That's where you have, for example, 3 or more programs that run in a package
    in a sequence and you have Program 3 be set to run after Program 2 does and then set Program 2 to run after Program 1 so you get the desired sequence of Programs 1-2-3 running in that order.  So, I created programs to 1) kill Communicator.exe 2) uninstall
    Communicator 2007 R2 by doing an "msiexec /uninstall {GUID}" 3) install Silverlight 4) install Visual C++ x86 5) optionally install Visual C++ x64, and then 6) install the Lync x86 or x64 client.  That final step was always the point of failure because
    I couldn't get the hacked MSI for the Lync Client install to work.  I also realized that if Communicator wasn't running when the deployment started, that step would fail and cause the whole process to bail out with an error.  That's one of the downsides
    of program-chaining, if one step fails, SCCM completely bails on the deployment.  This is what also led me to the key to my solution:  TASK SEQUENCES.
    I'm not sure how many people out there look in the "Operating System Deployment" area of SCCM 2007 where Task Sequences normally live, but I also wonder how many people realize that Task Sequences can be used for more than just Operating System deployments. 
    One of the biggest advantages of a task sequence is you can set a step to ignore an error condition, such as if you try to terminate a process that isn't running.  Another advantage is that task sequences have some very good built-in conditionals that
    you can apply to steps, for example, having the sequence skip a step if a certain application (or specific version of an application) is not installed on the machine.  Both of those advantages factor highly into my solution.
    OK, for those who already think this is "TL;DR", here's the step-by-step of how to do this:
    First, you need to extract all the files from the LyncSetup.exe for your needed architectures.  We have a mix of Windows XP and Windows 7 64-bit, so my solution here will take both possibilities into account.  To extract the files, just start up
    the .exe like you're going to install it, but then when the first dialog comes up, navigate to "%programfiles%\OCSetup" and copy everything there to a new location.  The main files you need are: Silverlight.exe, vcredist.exe (the x64 LyncSetup.exe includes
    both x86 and x64 Visual C++ runtimes, you need them both, just rename them to differentiate), and Lync.msi (this also comes in an x86 and x64 flavor, so if you have a mix of architectures in your environment, get both and either put them into their own directories
    or rename them to reflect the architecture).
    For my setup, I extracted the files for the x86 and x64 clients and just dumped them each into directories named after the architectures.
    Next, move these files into a directory to your SCCM file server, whatever it might be that you deploy from, in our case, it was just another volume on our central site server.  Go to the SCCM console into Computer Management -> Software Distribution
    -> Packages and then create a new package, call it something meaningful, and then point to the directory on your SCCM file server for the source files.
    Now you need to create 3 to 5 programs inside the package:
    1.  Name: Silverlight
       Command Line: x86\Silverlight.exe /q     (remember, inside my main Lync install folder on my distribution point, I have an x86 directory for the files from the x86 installer and an x64 folder for the files from the x64 installer. 
    The fact is the Silverlight installer is the same in both, so you only need one of them.)
       On the Environment tab:  Program can run whether or not a user is logged in, runs with administrative rights, Runs with UNC name
       On the Advanced tab:  Suppress program notifications
       All other options leave default.
    2.  Name:  Visual C++ x86
        Command Line:  x86\vcredist_x86.exe /q
       On the Requirements tab: Click the radio button next to "This program can run only on specified client platforms:" and then check off the desired x86 clients.
       Environment and Advanced tabs:  same as Silverlight
       (If you have only x64 clients in your environment, change all x86 references to x64.  If you have a mixed environment, create another program identical to this one, replacing references to x86 with x64.)
    3.  Name:  Lync x86
        Command Line:  msiexec /qn /i x86\Lync.msi OCSETUPDIR="C:\Program Files\Microsoft Lync"  (The OCSETUPDIR fixes the issue with the Lync client wanting to "reinstall" itself every time it starts up)
        Requirements, Environment, and Advanced tabs:  Same as with Visual C++ and Silverlight
        (Same deal as above if you have all x64 clients or a mix, either change this program to reflect or make a second program if necessary)
    Now you need to make the Task Sequence.  Go to Computer Management -> Operating System Deployment -> Task Sequences.  Under the Actions pane, click New -> Task Sequence.  In the Create a New Task Sequence dialog, choose "create a
    new custom task sequence", Next, enter a meaningful name for the task sequence like "Install Microsoft Lync", Next, Next, Close.
    The task sequence will have up to 12 steps in it.  I'll break the steps down into 3 phases, the prereqs phase, uninstall OCS phase, and then Lync install phase.
    Prereqs Phase:
    These are the easiest of the steps to do.  Highlight the task sequence and then in the Actions pane, click Edit.
    1.  Click Add -> General -> Install Software.  Name: "Install Microsoft Silverlight".  Select "Install a single application", browse to the Lync package created earlier and then select the Silverlight program.
    2.  Add -> General -> Install Software.  Name: "Install Microsoft Visual C++ 2008 x86".  Install Single Application, browse to the Lync package, select the Visual C++ x86 package.
    As before, if you're an all-x64 environment, replace the x86 references with x64.  If you have a mixed environment, repeat step 2, replacing x86 with x64.
    3.  Add -> General -> Run Command Line.  Name: "Enable Lync Installation".  This step gets around the UseMSIForLyncInstallation registry requirement.  The Lync client MSI simply looks for the presence of this key when it runs, so
    we'll inject it into the registry now and it doesn't require a reboot or anything.  It just has to be there before the client MSI starts.
    Command Line: reg add "hklm\Software\Policies\Microsoft\Communicator" /v UseMSIForLyncInstallation /t REG_DWORD /d 1 /f
    Uninstall OCS Phase:
    This part consists of up to 6 Run Command Line steps.  (Add -> General -> Run Command Line)
    4.  Name: "Terminate Communicator".  Command Line: "taskkill /f /im communicator.exe".  On the Options page, check the box next to "Continue on error".  This will terminate the Communicator process if it's running, and if it's not, it'll
    ignore the error.
    5.  Name: "Terminate Outlook".  Command Line: "taskkill /f /im OUTLOOK.exe".  Check the "Continue on error" on the Options page here too.  Communicator 2007 hooks into Outlook, so if you don't kill Outlook, it might prompt for a reboot
    because components are in use.
    (NOTE:  If necessary, you could also add another step that terminates Internet Explorer because Communicator does hook into IE and without killing IE, it might require a restart after uninstalling Communicator in the next steps.  I didn't run into
    this in my environment, though.  Just repeat step 5, but replace OUTLOOK.EXE with IEXPLORE.EXE)
    6.  Name: "Uninstall Microsoft Office Communicator 2007".  Command Line: "msiexec.exe /qn /uninstall {E5BA0430-919F-46DD-B656-0796F8A5ADFF} /norestart" On the Options page:  Add Condition ->  Installed Software -> Browse to the
    Office Communicator 2007 non-R2 MSI -> select "Match this specific product (Product Code and Upgrade Code)".
    7.  Name:  "Uninstall Microsoft Office Communicator 2007 R2".  Command Line:  "msiexec.exe /qn /uninstall {0D1CBBB9-F4A8-45B6-95E7-202BA61D7AF4} /norestart".  On the Options page:  Add Condition -> Installed Software ->
    Browse to the Office Communicator 2007 R2 MSI -> select "Match any version of this product (Upgrade Code Only)".
    SIDEBAR
    OK, I need to stop here and explain steps 6 and 7 in more detail because it was a gotcha that bit me after I'd already started deploying Lync with this task sequence.  I found out after I'd been deploying for a while that a tech in one of our remote
    offices was reinstalling machines and putting the Communicator 2007 non-R2 client on instead of the R2 client, and my task sequence was expecting R2, mostly because I thought we didn't have any non-R2 clients out there.  So, at first I just had our Help
    Desk people do those installs manually, but later on decided to add support for this possibility into my task sequence.  Now, when you normally uninstall something with msiexec, you would use the Product Code GUID in the command, as you see in steps 6
    and 7.  All applications have a Product Code that's unique to a specific version of an application, but applications also have an Upgrade Code GUID that is unique for an application but common across versions.  This is part of how Windows knows that
    Application X version 1.2 is an upgrade to Application X version 1.1, i.e. Application X would have a common Upgrade Code, but the Product Code would differ between versions 1.1 and 1.2.
    The complication comes in that Communicator 2007 and Communicator 2007 R2 have a common Upgrade Code, but different Product Codes and the "MSIEXEC /uninstall" command uses the Product Code, not the Upgrade Code.  This means that if I didn't have step
    6 to catch the non-R2 clients, step 7 would be fine for the R2 clients, but fail on non-R2 clients because the Product Code in the MSIEXEC command would be wrong.  Luckily, we only had one version of the non-R2 client to deal with versus 4 or 5 versions
    of the R2 client.  So, I put the command to remove Communicator 2007 non-R2 first and checked for that specific product and version on the machine.  If it was present, it uninstalled it and then skipped over the R2 step.  If non-R2 was not present,
    it skipped that step and instead uninstalled any version of the R2 client.  It's important that steps 6 and 7 are in the order they are because if you swap them, then you'd have the same outcome as if step 6 wasn't there.  What if neither is on the
    machine?  Well the collection this was targeted to included only machines with any version of Communicator 2007 installed, so this was not a problem.  It was assumed that the machines had some version of Communicator on them.
    8.  Name:  "Uninstall Conferencing Add-In for Outlook".  Command Line:  "msiexec.exe /qn /uninstall {730000A1-6206-4597-966F-953827FC40F7} /norestart".  Check the "Continue on error" on the Options Page and then Add Condition ->
    Installed Software -> Browse to the MSI for this optional component and set it to match any version of the product.  If you don't use this in your environment, you can omit this step.
    9.  Name:  "Uninstall Live Meeting 2007".  Command Line:  "msiexec.exe /qn /uninstall {69CEBEF8-52AA-4436-A3C9-684AF57B0307} /norestart".  Check the "Continue on error" on the Options Page and then Add Condition -> Installed Software
    -> Browse to the MSI for this optional component and set it to match any version of the product.  If you don't use this in your environment, you can omit this step.
    Install Lync phase:
    Now, finally the main event, and it's pretty simple:
    10.  Click Add -> General -> Install Software.  Name: "Install Microsoft Lync 2010 x86".  Select "Install a single application", browse to the Lync package created earlier and then select the "Lync x86" program.  As before, if you
    only have x64 in your environment, replace the x86 with x64, or if you have a mixed environment, copy this step, replacing x86 references with x64.
    And the task sequence is done!  The final thing you need to do now is highlight the task, click Advertise in the Actions pane, and deploy it to a collection like you would with any other software distribution advertisement.  Go get a beer!
    Some final notes to keep in mind:
    1.  You can't make a task sequence totally silent...easily.  Users will get balloon notifications that an application is available to install.  The notifications cannot be suppressed through the GUI.  I've found scripts that supposedly
    hack the advertisement to make it be silent, but neither of them worked for me.  It was OK, though because in the end we wanted users, especially laptop users, to be able to pick a convenient time to do the upgrade.  The task sequence will appear
    in the "Add/Remove Programs" or "Programs and Features" Control Panel.  You can still do mandatory assignments to force the install to happen, you just can't make it totally silent.  On the plus side, the user shouldn't have to reboot at any point
    during or after the install!
    2.  In the advertisement setup, you can optionally show the task sequence progress.  I've configured the individual installs in this process to be silent, however, I did show the user the task sequence progress.  This means instead of seeing
    5 or 6 Installer windows pop up and go away, the user will have a single progress bar with the name of the step that is executing.
    3.  One step that I didn't consider when I actually did this was starting the Lync client as the user when the install was complete.  The user either had to start the client manually or just let it start on its own at the next logon.  However,
    while I was writing this, I realized that I could possibly start the client after installing by making another Program in the Lync Package with a command line that was along the lines of "%programfiles%\Microsoft Lync\communicator.exe" and then in the Environment
    tab, set it to "Run with user's rights" "only when a user is logged on".
    4.  My first revision of this task sequence has the Prereqs phase happening after the OCS uninstall phase, but I kept running into problems where the Silverlight installer would throw some bizarre error that it couldn't open a window or something wacky
    and it would fail.  Problem was, I couldn't re-run the task sequence because now it would fail because OCS had been uninstalled, so that's why the Prereqs happen first.  It ran much more reliably this way.
    5.  For some reason that baffles me, when I'd check the logs on the Site Server to monitor the deployment, I'd frequently see situations where the task sequence would start on a given machine, complete successfully, almost immediately start again, and
    then fail.  I'm not sure what is causing that, but I suspect either users are going to Add/Remove Programs and double-clicking the Add button to start the install instead of just single-clicking it, or the notification that they have software to install
    doesn't go away immediately or Lync doesn't start up right after the install, so they think the first time it didn't take and try it a second time.
    I hope this helps some of you SCCM and Lync admins out there!

    On Step 8 I found multiple product codes for the Conferencing Add-In for Outlook.  Here's a list of the ones I found in the machines on my network:
    {987CAEDE-EB67-4D5A-B0C0-AE0640A17B5F}
    {2BB9B2F5-79E7-4220-B903-22E849100547}
    {13BEAC7C-69C1-4A9E-89A3-D5F311DE2B69}
    {C5586971-E3A9-432A-93B7-D1D0EF076764}
    I'm sure there's others one, just be mindful that this add-in will have numerous product codes.

  • Significant difference in response times for same query running on Windows client vs database server

    I have a query which is taking a long time to return the results using the Oracle client.
    When I run this query on our database server (Unix/Solaris) it completes in 80 seconds.
    When I run the same query on a Windows client it completes in 47 minutes.
    Ideally I would like to get a response time equivalent on the Windows client to what I get when running this on the database server.
    In both cases the query plans are the same.
    The query and plan is shown below :
    {code}
    SQL> explain plan
      2  set statement_id = 'SLOW'
      3  for
      4  SELECT DISTINCT /*+ FIRST_ROWS(503) */ objecttype.id_object
      5  FROM documents objecttype WHERE objecttype.id_type_definition = 'duotA9'
      6  ;
    Explained.
    SQL> select * from table(dbms_xplan.display('PLAN_TABLE','SLOW','TYPICAL'));
    PLAN_TABLE_OUTPUT
    | Id  | Operation          | Name      | Rows  | Bytes |TempSpc| Cost (%CPU)|
    |   0 | SELECT STATEMENT   |           |  2852K|    46M|       | 69851   (1)|
    |   1 |  HASH UNIQUE       |           |  2852K|    46M|   153M| 69851   (1)|
    |*  2 |   TABLE ACCESS FULL| DOCUMENTS |  2852K|    46M|       | 54063   (1)|
    {code}
    Are there are configuration changes that can be done on the Oracle client or database to improve the response times for the query when it is running from the client?
    The version on the database server is 10.2.0.1.0
    The version of the oracle client is also 10.2.0.1.0
    I am happy to provide any further information if required.
    Thank you in advance.

    I have a query which is taking a long time to return the results using the Oracle client.
    When I run this query on our database server (Unix/Solaris) it completes in 80 seconds.
    When I run the same query on a Windows client it completes in 47 minutes.
    There are NO queries that 'run' on a client. Queries ALWAYS run within the database server.
    A client can choose when to FETCH query results. In sql developer (or toad) I can choose to get 10 rows at a time. Until I choose to get the next set of 10 rows NO rows will be returned from the server to the client; That query might NEVER complete.
    You may get the same results depending on the client you are using. Post your question in a forum for whatever client you are using.

  • I am unable to update Pages through the App store. It appears someone else used my machine to update Pages previously.For the update,  I am asked to login to another account. I want to remove it and download the latest version. Can I do this?

    I was notified that Pages and one other application have updates. When I tried to login, the Apps page asks me to login to an account I am not familiar with. I imagine that this machine was used by someone else to update or download 2 apps. I would like to delete them and download the latest apps using my account. Can I do this?

    You can log in to your own account at any time and access the appliactions you have paid for, just fill in your own Apple ID.
    Peter

  • Sun Filer - can you automate ACL permissions for all shares?

    Does the Sun Filer have an automation tool that will allow me to change all share permissions?
    As I'm a windows admin, does the filer have a powershell snapin?
    I havent been able to find much on the internets in regards to this topic.
    Thanks

    So... chmod -R on its own doesn't do anything, obviously. chmod +a returns "Failed to set ACL on file 'Tests': Operation not supported." Sure enough, the volume has "ignore ownership" enabled. I'm pretty sure I don't have ACLs running on that volume.
    1. Does "ignore ownership" mean ACLs get turned off?
    2. Other than that little switch in Finder, how do I control the ACLs volume-wide? I have neither fsaclctl nor fsctl on that server. Do I need to copy fsaclctl from a Leopard client?
    3. The deeper question is, do I want to enable ACLs? All the employees store all their files on that volume (it's a small company); will ACLs wreak havoc? Aside from official documentation, you sometimes get the feeling that ACLs are broken altogether.
    As for a 3rd party content management system, I need file-level access for users. A tool that manages the file storage, controls and audits access for end users, and avoids filename collisions and related issues sounds to my like AFP and Mac OSX Server.... Is there any 3rd party tool that can do that and supports things like resource forks?

  • Which Audio Setting for MPEG share for use on PC or burning to DVD???

    I just "shared" a movie (a slide and video show with soundtrack edited on Premier Elements 8)  to "Use for playback on this PC or burning to DVD"  (created an MPEG).  The audio export didn't work though.  I used the NTSC DVD Standard preset that gives the 192 kbps, 48 kHz, Dolby Digital audio setting.  Is this the setting I should use, or is there another audio setting that would work?  There is just silence on the end product.  Thanks for any help.

    Now, are you burning to a DVD-data, or to a DVD-Video?
    If the latter, then you can either Burn to Disc from PrE, or can Burn to Folder, and then use Roxio, Nero, or the great, free burning utility, ImgBurn to do the physical Burn.
    Some time back, WMP had the DVD playability disabled for all burned DVD-Videos. Not sure if MS has added that back in. To the best of my knowledge, WMP has no burning capabilities in it, but could be wrong with the newest versions.
    Hope someone else has ideas, and a better knowledge of most recent versions of WMP.
    Good luck,
    Hunt

  • SMB/CIFS share of encrypted windows directory

    I have a windows 8.1 pro stand alone computer. It has one directory that is encrypted. This computer shares that directory and others with a linux computer. Just after the windows 8.1 computer reboots, linux is unable to access the encrypted directory, but
    it can access other unencrypted directories. Once I log on the windows computer as a user with access to the encrypted directory, the linux computer is suddenly able access the encrypted folder. The linux computer can continue to access the encrypted directory
    from linux after the user logs off the windows computer.
    To be able to access the encrypted directory, I only need to log on to the windows console, i don't need to start any programs. It's as if windows cannot access some kind of key until the a user with access to the encrypted folder logs on to the windows
    system from the console. I've tried many different linux command line options for opening the windows share and it doesn't seem to change the behavior. It is typically mounted with:
    mount
    -t cifs //192.168.1.2/efsdirectory ~/mnt --verbose -o rw,user=username,uid=1000,gid=1000
    The behavior is identical if a directory above the efs directory is mounted.
    I searched all of the windows event logs for errors from the failed access to the encrypted directory, but I don't see any.
    Thanks for your help.

    Hi,
    Thanks for your help.
    if all your systems are in Domain or not.
    The windows and linux computers are not on a windows domain, just the same workgroup that is named "workgroup".
    Also please help confirm if "encrypted" means encrypted by EFS (or Bitlocker).
    The directory that i'm trying to access is encrypted with EFS. Since this is a desktop computer, it does not use bitlocker
    What's the exact username here in your command? Is it the same account as the one you logged on Windows 8.1?
    the username in the unix mount command is the same one used to log onto the windows system. The linux username is different, but that's specified in the mount command with the UID and GID.
    The problem occurs after a full reboot, I have disabled the windows 8.1 fast reboot 'feature'.
    I'll check tonight, but is it possible that the "Encrypting file system service" is not starting when I mount the drive? Perhaps it only starts when I log on. I noticed that this service is set to 'automatic' on another (windows 7) computer.
    Here's a timeline of what happens:
    1) Log off of the windows computer. Reboot. (not fast boot)
    2)
    mount drive on linux computer
    3)  brouse directory structure on linux. Can open files that are not in encrypted directories. Cannot open files that are in encrypted directories.
    4) log onto windows machine
    5) brouse directory structure. Now I can open files that are in encrypted directories.
    6) log off windows machine
    7) brouse directory structure. I can still open files that are in encrypted directories.
    Looking at the windows logs, I can see 2 login entries exactly when I mount the drive:
    Special privileges
    assigned to new logon.
    Subject:
    Security ID:   
    HOSTNAME\USERNAME
    Account Name:   
    USERNAME
    Account Domain:   
    HOSTNAME
    Logon ID:   
    0x43C3B
    Privileges:   
    SeSecurityPrivilege
    SeBackupPrivilege
    SeRestorePrivilege
    SeTakeOwnershipPrivilege
    SeDebugPrivilege
    SeSystemEnvironmentPrivilege
    SeLoadDriverPrivilege
    SeImpersonatePrivilege
    An account was successfully
    logged on.
    Subject:
    Security ID:   
    NULL SID
    Account Name:   
    Account Domain:   
    Logon ID:   
    0x0
    Logon Type:   
    3
    Impersonation Level:   
    Impersonation
    New Logon:
    Security ID:   
    HOSTNAME\USERNAME
    Account Name:   
    USERNAME
    Account Domain:   
    HOSTNAME
    Logon ID:   
    0x43C3B
    Logon GUID:   
    {00000000-0000-0000-0000-000000000000}
    Process Information:
    Process ID:   
    0x0
    Process Name:   
    Network Information:
    Workstation Name:   
    Source Network Address:   
    192.168.1.7
    Source Port:   
    58432
    Detailed Authentication
    Information:
    Logon Process:   
    NtLmSsp
    Authentication Package:   
    NTLM
    Transited Services:   
    Package Name (NTLM only):   
    NTLM V2
    Key Length:   
    0
    Thanks again.

  • I have set up a file share but cannot login with my account

    Hi everyone. I set up a file share using the settings in OS 10.5, however when I go to login on Windows Vista using my specially created read only account (called: remote). I cannot get it.
    I can only get in using these settings:
    user name = xxx.xxx.x.xxx\myaccount
    password = blah blah blah.
    Yet when I apply the same settings changing 'myaccount' to 'remote', I cannot get in.
    I'm not sure where I am going wrong, any help would be much appreciated. Thanks!

    No need to apologise, I'm the idiot who can't setup a home network. Although I'm sure Vista is at least to blame somehow.
    I have sharing turned on and it says "Windows users can access your computer at smb://192.168.x.xxx."
    If I click "options" it has a box which has an "on" tick box and my name. I have ticked it. When I ticked it, it asked for my admin password which I supplied.
    On the firewall front I have allow all incoming connections.
    I am trying to login to 'remote' whilst my Mac is still logged in as me, 'nathan' I have successfully logged in to the mac on the same settings using account: 'nathan' on Vista whilst still in 'nathan' on the mac.
    I am trying to connect going into network on vista and selecting my mac, correct.
    The connect works with 'nathan' if I go:
    192.168.x.xxx\nathan
    password
    but for some reason the 'remote' user I have set up wont work on vista using the same format.
    Thanks.

Maybe you are looking for