A permission problem of network user home folders

I have a problem in logging in of network users. I suspect it is due to incorrect permissions at the client.  The trouble scenarios is as follows:
Hosts (all in the local network):
server.example.com (Mac mini server 10.8.4 w/ Server.app)
    provides Open Directory and AFP/SMB File Sharing
    allows remote login via SSH,
    have two network user accounts (user1 and user2), and
    have their home folders on the external HDD (/Volumes/HD1/home).
client.example.com (Mac mini 10.8.4)
    takes server.example.com as network account server and
    allows remote login via SSH.
From the third machine (third.exmple.com), both user1 and user2 can simultaneously login to server.example.com via SSH without trouble.
Their home folders (directories) are: /Network/Servers/server.example.com/Volumes/HD1/home/{user1, user2}
Problem Scenario:
(1) After rebooting both server.example.com and client.example.com,  user1 can also login to client.example.com via SSH without any trouble.
His/her home folder is /Network/Servers/server.example.com/Volumes/HD1/home/user1.  This seems correct behavior.
(2) But after the successful login of user1, user2 fails to login to client.example.com via SSH.  The error messages look like this:
user@third$ ssh -l user2 client.example.com
Password:
Last login: ...
Could not chdir to home directory /Network/Servers/server.example.com/Volumes/HD1/home/user2:     Permission denied
-bash: /Network/Servers/server.example.com/Volumes/HD1/home/user2/.bash_profile: Permission denied
user2@client$ pwd
user2@client$
At this time, the file permission of the mount point of "home" folder is like the following. I suspect that this prevents user2 to access his/her home folder.
user2@client$ ls -l /Network/Servers/server.example.com/Volumes/HD1
total 0
dr-x------+ 1 user1  staff  264 Sep  9 20:24 home
(3) Now I can observe (at server.example.com) that user1 is connecting as the AFP file service user. After disconnecting user1 using Server.app, user2 can login to client.example.com successfully. 
(4) While user2 is successfully logging in to client.exmple.com, user1 fails to login to the host. The error messages look similar to (2).
At this time, the file permission of the mount point of the "home" is taken by user2.
Sorry for the long scenario. Does anyone have clue to solve this?
I havn't encountered this sort of problem when I was using Snow Leopard Servers.
Note:
On server.example.com, /Volumes/HD1/home is configured to be share point (with guest access permission) and AFP home. Its local permission is:
user1@server$ ls -ld /Volumes/HD1/home
drwxr-xr-x+ 4 root  admin  136  9  9 20:24 /Volumes/HD1/home
On client.example.com, the permission of the directories above  the mount point of "home" is: drwxr-xr-x+ root admin
Both accounts (user1 and user2) are created using Server.app connected to server.example.com (I didn't use Workgroup manager).

Takuo,
Did you ever resolve this issue?  I'm having a similar problem.  Linc's comment (about not logging into the server with a network user) doesn't apply -- I'm not logged on with that user, and I have rebooted the server since any possible logins.
Essentially, I have a home network where I've setup OpenDirectory on a Mac Mini Server.  I'm authenticating via LDAP properly between my iMac client and my Mac Mini Server.  For example, using 'id' at the command prompt, I can properly retrieve all network information, and can use 'ldapsearch' to query user IDs from the server.  Perhaps most importantly, I've got pGina setup on a Windows XP machine, and I can authenticate via LDAP against the Server as well -- so I'm pretty sure that I've got the LDAP & DNS parameters all properly configured.
But what I can't seem to figure out is why my SMB shares are failing.  Whenever a network user's home directory attempts to get mounted on the iMac client, the home directory authentication fails.  For example,
vimac:~ kris$ su - kmv
Password:
su: no directory
On the server-side, I'm seeing:
2014-03-26 8:58:24.256 PM digest-service[43828]: label: default
2014-03-26 8:58:24.256 PM digest-service[43828]:           dbname: od:/Local/Default
2014-03-26 8:58:24.256 PM digest-service[43828]:           mkey_file: /var/db/krb5kdc/m-key
2014-03-26 8:58:24.256 PM digest-service[43828]:           acl_file: /var/db/krb5kdc/kadmind.acl
2014-03-26 8:58:24.257 PM digest-service[43828]: digest-request: uid=0
2014-03-26 8:58:24.259 PM digest-service[43828]: digest-request: netr probe 0
2014-03-26 8:58:24.260 PM digest-service[43828]: digest-request: init request
2014-03-26 8:58:24.327 PM digest-service[43828]: digest-request: init return domain: VSERVER.LOCAL server: VSERVER indomain was: <NULL>
2014-03-26 8:58:24.330 PM digest-service[43828]: digest-request: uid=0
2014-03-26 8:58:24.330 PM digest-service[43828]: digest-request: init request
2014-03-26 8:58:24.534 PM digest-service[43828]: digest-request: init return domain: VSERVER.LOCAL server: VSERVER indomain was: <NULL>
If I use 'smb://' (with a username & password), I also get denied, and the same error about the "NULL" indomain appears in the log. 
Is this similar to what you saw?  I've been scouring the web for info about digest-request, but am fairly new to OS X, so my progress has been slow...
Kris

Similar Messages

  • Can't add users' home folders to Windows Libraries - "unindexed network location" error

    I am unable to add our users' home folders to their Windows Libraries on client PCs.  Windows is giving an unindexed network location error.
    This worked perfectly fine in WHS 2011, but is failing on WSE 2012 R2 Essentials.
    I've checked the indexing settings on the server, and the correct locations are in fact being indexed. 
    Since several of our clients have limited local storage, I can't solve this by turning on Offline Files.
    Is this behavior by design, or am I seeing a bug? 
    I'm guessing that on WHS 2011 the user folders are special-cased somehow, as normally one would need to include the share root in a library for federated indexing to work correctly.  What is it about WHS 2011 that makes this work, and is it possible
    to replicate these settings on our WSE 2012 R2 server?
    Thank you.

    No, our clients are not domain joined.
    To clarify, I'm not trying to redirect local folders, but rather to add the (automatically provisioned) user folder on the server to local libraries.  Federated search does support this scenario in WHS, so I assume it should work in WSE. 
    Trying to understand why I'm seeing the error.  Thanks.

  • Users home folders not accessible on SMB, OS X 10.6.4

    Hello,
    I'm facing this very weird problem upon trying to connect my Windows XP SP3 clients to their respective home folders on Mac OS X Server 10.6.4.
    The other shares and public folders however work just fine.
    So, upon connecting to the home folder of the user from Windows, (on \\serverIP\username\ ) I keep getting the authentication login form as if I'm typing the wrong username or password.
    Of course the user's password is correct.
    Oddly enough I can connect and see all the users shares if I go on My Computer and type \\serverIP\ and then enter username and password. I can access the "Users" share and even see other users documents and files!
    It used to work very well before a server restart last night, I decided to update to 10.6.4 to see if the problem would go away but no luck.
    In the SMB service log I see the following everytime I try to connect directly to the users home folders:
    [2010/06/23 14:29:14, 0, pid=2834] /SourceCache/samba/samba-235.4/samba/source/smbd/service.c:makeconnectionsnum(1047)
    '/Network/Servers/macmini-server.solinf.org/Users/silvia' does not exist or permission denied when connecting to [silvia] Error was Host is down
    What puzzles me is that if I navigate from shell to /Network/Servers/macmini-server.solinf.org/ I find an alias called "users" that I cannot access.
    Anyone has any ideas what is causing this direct access to fail?
    Thanks in advance
    CS8

    HI,
    If you have ClickToFlash installed, that could be a factor.
    Also, follow the instructions here to clear the Flash cache.
    http://discussions.apple.com/thread.jspa?messageID=11672709&#11672709
    Carolyn

  • How to have the network users home folder on the server

    I have snow leopard server up and running and I want to have the network users home folder on the server, instead of it being located on the connected computers. This way the users can access their folders from other computers in the network

    In addition you have to make the sharepoint able to be automaticly mounted. The manual say this is very important.
    But you should really read the announced manual. All the manuals all filled with step-by-step instructions for modifiing many preferences... That´s my experience!
    Now I´ve got a question, too...
    My OD-Master is bound to AD. I try to use win-Accounts for workin on mac. It work pretty good, by using an group-account. In this group-account I cennect the win-accounts to instruct all the restrictions I´ve set for user-accounts.
    But this way I can´t create a homefolder on a share...
    The share(netusers) is on the same server(mac-server2) like OD-Master is running. I´ve set the path for creating homefolders in Mobility option on "//mac-server2/netusers" for the group-account the AD-user is member of.
    Is it the wrong way?

  • 10.6 server on w2k AD domain, trouble making new user home folders

    i recently starting working as a public school which has over 800 macs, both intel and ppc, laptops and desktops. there are also 300 windows machines as well. my job is to create the new user accounts for the students and staff as well as perform routine maintenance on the computers/servers. there are 3 xserves (intel) running 10.6.8 and 3 windows boxes running 2000 server. (i know thats old but it was top of the line when the building was build in 2002) the windows machines perform the user authentication via active directory and the xserves house the home folders stored on an xserve raid. the problem i am having it that i cannot create the new home folders for the incoming students on the xserve. the accounts are created in AD with no problems, and everything points to where it should be. however, when i try to manually create them (either by createhomedir in terminal, or by a script one of the previous system admins made) nothing happens. both active directory and open directory are up and running and all the servers seem to be talking to each other. on a side note, if i deleted an existing home folder and than ran the terminal command, it creates it perfectly. in one last attempt i re-bound all the mac servers to the AD and now it wont even let me re-create an existing home folder. anyone have any thoughts or ideas?? i have about a month left to get this fixed and all the computers imaged with the new config. i'd rather not have to re-build the AD domain but if it comes down to it, i may not have any choice.

    sorry i havent posted back sooner. i tried server cleanup and it did seem to fix other minor issues with the server, and it mapped the correct path to the user home folders. but it won't let me fix the permissions. when a student logs in to a client machine their home folder window opens up and all the folders are there but it won't let you open them stating that "you do not have the correct permissions" i ran fix permissions in server cleanup a few times, but it didnt fix the situation. also, i noticed that when i tell SC to look at the active directory domain, i get an error window and it stops loading users after the C's (alphabetical by last name) could this be because the AD domain is windows 2000 server? i just got 2 win2003 server machines freed up that i could migrate the AD domain to. that might fix some issues.

  • How do I move users' home folders to another disk other than boot disk

    I would like to move all of my various users' home folders to a different disk. How is this done?
    Do I need to then have the disk mount before any users log in? If so, how do I mount it?

    But if you are using Leopard (since you are posting in the Leopard category) and simply forgot to update your profile, you can select the location of your home directory by going to System Preferences Accounts pane, and right (control) clicking on your user name to get the +Advanced Options+. You may need to +unlock the lock+ (give authorization) first.
    Here are more specific directions.
    http://www.macosxhints.com/article.php?story=20071025220746340

  • Best way to migrate local users to the network - move home folders?

    Hi everyone,
    I am about to set up my Mac mini server (Snow Leopard Server). I have one iMac with three user account on it (local), another iMac that we just bought and my MacBook Pro with my admin account on it (Snow Leopard). So all have Snow Leopard.
    What would be the best way to move the three local accounts AND their home folders to the server?
    What would be the best way to make my portable user account into a mobile user account on the server?
    I am planning to create all users on the server (with the same username and passwords etc.) then move the local home folders from the iMac to the server through some direct wired connection. My concern is with this move - will there be permissions mismatch issue? I am sure there will be as the UID would be different for the same accounts (pre-existing and newly created, eventhough their username and passwords are the same).
    Any best practices? strategies?
    Does Apple have any documentation on this specific topic? - that is moving local user accounts and their corresponding home folders onto the server?
    Thanks much!
    Kenneth

    Hi again,
    I haven't gotten round to it - but may have an alternative route in the mean time: the brand new 27" iMac just arrived, and rather than doing a full 'migration assistant' setup, I am going to try the following:
    1. on the new iMac: only create a local Admin account, user name totally unrelated with any other account name;
    2. on the server: settle all the network user account settings, portable home directories, managed preferences etc. for each user;
    3. on another computer: log on under the corresponding local user account, and copy one's home folder entirely to an external drive - do not use this machine again under this user account;
    4. on the new iMac: log in as a network user, make sure the home folder and library syncing works as desired, set some preferences (and check that this gets synced to the server drive); copy the parts of the home folder & library for this user from the external drive - wait until it all gets synced back and forth - and check any permissions, preferences whatever issue (the local account on the other computer is available for cross-checking, just don't change any documents or settings on that one)
    5. if all works well on the new iMac: delete this local user account on the other computer.
    6. repeat steps 3-5 for each other computer where this user has a local account (one 'old' iMac, one 13" MB) - will also allow to check and filter any duplicate documents which have accumulated over the different machines.
    7. create the network accounts for this user on the other computers, and check the syncing etc.
    8. repeat for each user (4 in total for us).
    I think this might just work, since the new iMac at present has no accounts - so no possible issues with similar account names & passwords etc - and you keep the 'old' local account on the other machine as a safeguard anyway.
    Any particular thoughts or comments on this proposed process??
    How about permissions: does the copying to an external disk, and then back onto another computers disk solve that??

  • User home folders Upper and Lower case problem in FPN

    Hi Sdn,
    I am facing a wiered problem in FPN. I configured FPN between EP and BI portal.
    EP is using UME as LDAP
    BI portal is using UME as ABAP
    configured KM folders on to EP using Webdav scenario
    now when I try to save KM book marks, it is saving perfectly in EP
    the problem is saving bookmarks in the userfolder with Uppercase like USER
    the KM favorites iView with the path (/alias/userhome/<user.id>/favorites)is trying to look into the userfolder with lowercase like user and displaying nothing
    plese help me in solving this for KM iView to ignorie case
    Thanks!
    Regards
    Srinivas

    Hi Simon,
    I understand that this problem is because of UME as LDAP and ABAP .
    I tried to create a KM Navigational iView for favorites folder /alias/userhome/<user.id>/favorites.
    but here problem is I am not able to convert user.id to Ucase
    As per your suggestion, it is not possible to create one KM navigational iView to peep into multiple folders
    for this the solution might be in two ways. creating KM iView to ignore case and look into the user home folder
    if so, How to make the iView to ignore case
    second option is to configure BEx broadcaster to publish in USER.lower folder
    is so, How to achieve this
    being people started using FPN most frequently and moving BI to seperate Portal and use ABAP as ume.
    users will start encounter this problem most often. SAP has to come out with solution for this
    Srinivas

  • New OSX Server Installation - User Home Folders Dissapear after on logout

    hi all,
    Can anyone help me identify this problem that i`m getting with a new fresh install and setup of OSX-server 10.4.10? Basically i have setup the server but when users are logging out of their binded 10.4.10 macs their home folders are dissapearing off of the server. If anyone needs anymore detailed information on the configuration please let me know
    thanks,

    Hi
    You will see the 99 folder on the Server. It will be in the folder designated for Home Folder creation and automounting. It gets created if there are no home folders.
    Is this the only server on the network?
    What happens if you create a new user and home folder, one whose log in name and password does not exist anywhere else and is also not the clients local admin account. On the client click other and log in with that account. On logout does this users home folder disappear off the server?
    Tony

  • Syncing Windows users with Mac users home folders

    Hello,
    I have setup my 10.6 XServe to allow Windows user to connect.
    The Windows machines log into the server just fine but when they save something to their Documents, Desktop etc... it doesn't show up when they log into a Mac machine and vice versa.
    I did find a script on WazMac for a logon vbs but that does not work.
    Any help?

    Thank you Linc Davis,
    I did some investigation on the internet to see the default ACLs on the "users" folder and I noticed that I added a group access. I deleted it and ended up with the correct configuration. I have now each user accessing his own home folder with read and write access to all the folders (desktop, music, video...) and sees the others users' home folder with access denied.
    I think I can live with that configuration. Problem solved.

  • Permissions problems with networked users

    Hi,
    We use 11 intel imacs with networked users from an xserve and run Logic Pro. I have told all students to run their projects from a temporary folder on the local hard drive and then copy the final work to their desktop to secure it for next time if they use a different machine, this seems to work OKish.
    However there are a few features that refuse to work in Logic for a managed user, time stretching is one and various others so what I need to know is anyone have a comprehensive list of ALL the folders that logic would use so I can make them all read/write to everyone and see if the problems go away. A local account with admin privileges seems to work fine but I am keen to solve the problem at the root level and this seems like a good place to start.
    Anyone have any tips on networked LDAP users and Logic Pro?

    I don't know about the network stuff as such, but there are various utilities that hook into OSX to display all file activity - you can turn on logging, run the application, then look through the log to see what files that Logic was trying to access while it was running.
    It might give you some clues, beyond all the obvious stuff (application, preferences files, app support files, garageband libraries, plugin settings, plugins, sampler instruments, audio files, project manager database files and so on)

  • How to manage local user home folders?

    We are using Mac OS X 10.6.8 in a classroom. Hard drive has two partitions, one for OS and apps, the other for student's files. Computers are bind to the Active Directory. Unfortunately, local home folders are on the boot parition. Over a time when apps FCP and Avid are frequently used, the boot partition gets filled with files and finally it's full. With zero kb available, users cannot even login anymore. Manually deleting files by admin is cumbersome and time-consuming task.
    I'm looking for a way to keep /Users folder clean. Putting user's home folders to server is not an option, because of latency issues etc. Unfortunately the local home folder is the default saving place when user issues the Save As command. I've tried to tinker with the User Template to lock the Documents folder but apps like Microsoft Word and Final Cut Pro go crazy when they cannot save there.
    Forwarding /Users to other partition does not solve the problem, it just moves the problem to another place.
    Logout Hook to automatically purging the files could be an solution, but there's always one hapless soul who saves his or hers files to wrong place and loses them. Or maybe a script which looks at the modfication date and deletes old files.
    Any ideas?

    You need to set the scratch disks in FCP and Avid to fix the problem.
    Files coming from word etc, will be so minor that it'll take forever to fill up the HD with that kind of stuff.
    If you wanted to move the whole home folder to another place on the system, you need to do so using OS X server.  It's called Augmenting Active Directory User Records.
    If you don't have an OS X Server, you may be able to change the Users Home directory on each individual computer, but it's going to be pretty cumbersome.  Do so in the Accounts pane in the System Preferences.
    Once you've changed the User Home folder location, you need to copy the users home folder using rsync in the terminal.
    Like this:
    rsync -av /Users/*username* /Volumes/*drivename*/*homefolderlocation*/
    HTH
    -Graham

  • Correct permissions for user home folders?

    I recently installed a new Mac Mini with Server 10.10.2
    I have about 10 clients running off the server (an open directory master), they are setup as local network users and have home folders on the server.
    I had to copy contents of the home folders from a previous (crashed) server and I can't seem to get the permissions right.
    A couple of the users use home directory syncing, so they have a local copy of their home folder on the computer they usually use, but changes aren't getting synced across the network to the server. An example is the dock, I keep removing and replacing icons in the dock, but logging out and logging back in returns the dock to its old configuration (presumably bringing the old config back from the server).
    Is there a tool which resets user directory permissions for network home folders? Or can someone give me any guidance how to sort this out?
    Thanks
    James

    In the sidebar of the Server.app window, select the icon at the top with the name of the server. Then select the Storage tab in the main window pane.
    Navigate to the folder in question and select it. From the popup menu at the bottom with a gear icon, select
              Edit Permissions...
    Verify that the permissions are what they should be, and make changes if necessary. Then, from the same menu, select
              Propagate Permissions...
    Check all applicable boxes, including Access Control List. If in doubt, check all boxes. Click OK.

  • How do I hide the parent folder of the user home folders in File Sharing?

    In 10.6 Server I would set the parent folder so that "Everyone" could not list folder contents, then set "Everyone else" read only.  This prevented the parent folder from showing up in the list of available Share Points and allowing users to see the list of home directories.
    In 10.8, this trick no longer seems to work.  No matter what I set the ACLs to, the folder always shows up as a share point in the connection window.  2014 is the folder I've set for the Home directories of our network users (and there will be 2 more for graduating years.)  I can set the ACL so if they attempt to mount it, it just spits out an error saying they can't view the contents, but that isn't reasonable.  I don't want it to show up at all.  The only thing the students should see is their home folder.  Nothing else.
    What can I do to make it so 2014 doesn't show up in the connection window?  2014 is the parent folder for the home directories, so it can't be unshared.

    This prevented the parent folder from showing up in the list of available Share Points and allowing users to see the list of home directories.
    That second sentence should read:
    This prevented the child folder (parent folder to the home directories) from showing up in the list of available Share Points and allowing users to see the list of home directories.

  • Problems With FTP Users home directory

    Hello Everyone,
    I recently ran into a problem when setting the home directory of an ftp user. What I want to be able to do is for example I have two users, one user is User1, and the other is FTPUser. Now when people ftp into the user FTPUser I want to set the home directory to be a certain path in User1. Now I was able to successfully do this on one box when creating the FTPUser I just set the home directory to be the path in User1. And when people ftped into FTPUser they were in the right directory under User1.
    I tried to do this same procedure on another box, and after creating the FTPUser and setting its home directory to a path under User1. Now when they ftped into FTPUser it was showing that the home directory was "/". I examined /etc/passwd and it presents the right home directory that I want, yet when people ftp into FTPUser its showing the home directory to be "/". Any help would be appreciated. Thanks in advance.
    -Kevin

    Sorry for such a late reply, but I figured out my problem and will put it on here in case other people run into the same problem. You must make the FTPUser be in the same group of the normal users directory path you wish to FTP into. For example the command will look like this when making the FTP user:
    useradd -g "users group number" -d /path/to/file -s /bin/sh ftpusername
    so if user1 group id was 110 you would put 110 after -g and set the home dir of the ftpusername to be some path in user1. Thanks all for the help.
    -Kevin
    Edited by: kratkinson on Jun 22, 2009 6:46 AM

Maybe you are looking for

  • Problems with iTunes and Podcasts after upgrade to iOS 8.1.3.

    I upgraded my iPhone 5 to iOS 8.1.3, then I purchased some music on iTunes. While hearing the music, incomming call shut the Music player down. From that time on, cannot open neither Music, nor iTunes Store, Podcasts, Settings/General/About, (Nike) R

  • Hiding Cells in Visual Composer

    Hi all, I have a report where in we have three cells of a particular row hidden with the help of Cell restrictions. But when i execute the visual composer dashboard which is based on this query , i get the values as zero, instead of blank. Is there a

  • EJB Design  Pattren For File Transfer Application

    hi, My requirement is Transfer of large files (around 300-500KB) across the network with a central repository.We looking at a Solution from J2EE With EJBs. At the Central Repository we are looking for ejb-Application Server. But the the issues i come

  • MacPro's digital outs not working w/ Express

    So I have Logic Express working OK with my new MacPro's normal analog output, but it won't work with the digital outs. Why? This shouldn't be too difficult to set up. At the same time, maybe I'm missing something because I don't even see where in LE

  • Text mode applications

    I have a fascination for text mode applications. I certainly can't use them any faster than a gui application like many people can, seeing as I can barely touch type, but their simplicity, low memory use and ensuing elegance appeals to me. So my ques