How are user groups defined in Mac OS 10.x

Thus far, my guess is that Mac OS determines which users are members of particular pre-defined groups.
For example, if I want to give other users in my home network read and write permissions to a particular folder, I might add the pre-defined group 'netuser' to group in the get info window and give the group right and write permissions.
I am correct in this?
I used to administer a Windows NT server and workstations and could give permissions to domain users, as opposed to local users on the various machines.
I imagine it might be pretty much the same if I had Macintosh server software installed or whatever.
My chief concern is understanding permissions in relation to Qmaster distributed processing with a home network.
Advice and clarifications are most welcome.
--Cris

Thanks for the link to the ars tecnica site article on permissions and acl's.
Actually, I am quite happy with Unix group limitations. I am just still trying to understand how to create a group, and users to the group, and to control how new folders and files are given permissions inside their parent folders.
Can you recommend an article that explains how to create new groups, and associate users with groups?
I now have a case where I am trying to figure out how to use QMaster for distributed processing. I was observing problems writing to the second computer, a service node. Even when the first machine, client and cluster controller, was not listed in the upper pane of QAdmin as belonging to the cluster, cluster storage would default to the first machine. So, I made the second machine a cluster controller and service node as well, and sent a job from my first computer, the client, to a cluster that only had the second computer. This worked. Only problem, is that the new folders and file written in the cluster storage assigned to a folder on the second computer have ownership and group changed to the user which is my log in (admin) on the first computer. That in itself wouldn't necessarily be a problem save that I cannot delete the files from the first machine as my account doesn't have necessary permissions. Perhaps that is because earlier, in a botched effort to get Qmaster to work for me, I had created a local account on the second machine with the same name as my admin account on the first machine. That account is now deleted, and I have reset Qmaster preference many times since then, so this is may be a red herring.
The Apple document "Distributed Processing Set-up" says:
"All the computers in a cluster need Read and Write access to any computers (or storage devices) that will be specified as output destinations for files."
I'm just not sure how to go about that.
Thanks,
Cris

Similar Messages

  • SQ03 Standard Area user group

    Hi All,
    How to get all standard area user group from sap tables or RFC?
    ( For getting global area user group table AQGDBBG is wrking fine).
    Regards,
    Anuj Jain

    solved.

  • ERecruitment - How are support groups created?

    Prior to support packs we maintained support team groupings in the following IMG location:  SAP E-Recruiting -> Technical Settings -> User Administration -> Define User Lists for Support Team
    This IMG config no longer exists and it appears this has been replaced with support groups.  Where are support groups configured?
    Thanks,
    Jeff

    Hi,
    generating direct links to bsp applications is not the common way for e-recruting. Creating support groups is an administrator task so you find the link to the application on the standard admin startpage (ID 0004). If you plan to have your admin / key user maintaining the support groups in production you should include the link in your customer startpage, too.
    As you mention the old version prior to EhP3. If you used the former group customizing be sure to migrate the old lists to the new support groups.
    Rgds.
    Roman

  • Looking for LA area user group

    Are there any user groups in the LA area, google was no help & what I did find were flakey groups that did not answer emails. I am looking for serious user groups in the LA area.
    Thanks :)

    well, i was disappointed in the first one, as I received no response. The second lists the same groups, but I may contact the Orange County group. Thanks

  • How to update group policy on MAC OS 10.6.8

    Hi,
    I am not able to update group policy on MAC 10.6.8 like gpupdate comand from terminal.
    Regards
    Govind Singh

    OK, makes sense. Any idea what the DMG preference should be in Firefox?
    It was set to "Always Ask"
    ... and I changed it to "Use MacOS"
    The funny thing is that all the other updates (these were Add On updates) that I ran downloaded the DMG file and it started right up. It is only the Adobe products (Acroread, Flash, ect) that are having troubles, and they all get the same error.
    BTW - Thanks for helping!
    NEW UPDATE:
    Found /System/Library/CoreServices/DiskImageMounter.app and set the Firefox preferences DMG file to use that now.

  • How are user-entered MIME applications defined to open certain file types. This used to be standard in browsers.

    In the not-terribly-recent past, browser Preferences allowed users to create associations between a file type (really, a file extension indicating its type) with an application used to run that type of file. Firefox seems to have buried this (on the Mac) in ~/Library/Application Support/Firefox/... ;in which seem to be an xml file.
    Is it possible to edit this xml file directly, and if so, where in the xml file should a new entry be placed, and what is the explicit syntax of an entry (other than obviously copying present entries)?
    These used to be called MIMEs.

    I am trying to use a rather older programming language called Mozart, an extension of OZ. I installed it as a binary, but instead of storing its component binaries in a place like /usr/local/oz/bin/. they are all enclosed inside the /Applications/Mozart.app/Contents/Resources/bin/. which cannot be opened nor can a soft link be made to it located outside the Mozart.app wrapper.
    The only alternative is to try to edit the mimeTypes.rdf files, and give it the full path name to the inside of Mozart.app were the program used for web applications is stored. It is stored in ~/Library/Application Support/Mozart/, which can only be accessed in more recent Mac OS X by going to finder and holding the Option key while opening the Go menu; this will make the ~/Library visible and accessible.

  • Make Open Directory Users/Groups Administrators on Mac clients

    I have setup a OS X 10.8 server with Open Directory and have 2 mac os x mountain lion clients.  I would like for the user accounts I have created in the Open Directory to have admin access to the 2 mac client machines.  How can I do this?  I am new to OS X server.  Is there a Group Policy type equivalent like in Windows? 

    Ah! Thanks! No wonder I cannot do this...
    Unfortunately, the printers are all USB shared printers connected to computers on the network. Is there anyway to preset these printers? They don't show up in the Print manage settings at all.

  • How are users associated to service principals?

    Hello,
    I am trying to implement Kerberos authentication on a Windows machine and have trouble understanding how users are mapped to service principals.
    I understand that the ktpass or Setspn tools are used to associate a service principal to an Active Directory account because a service that is being secured by Kerberos needs to be mapped to an Active Directory account(e.g. account X). So, when executing a command from either one that account X only is mapped to the service principal.
    Now, say user user1 having account Y tries to access the service corresponding to the above service principal.
    My question is how does Kerberos know that account Y is allowed to access the secured application? How can I associate account Y with the above principal?
    Thank you,
    Savvas.

    savvas.andreas wrote:
    right..I think I see what you mean. So, it is true then that any user who has logged on to his/her windows account can access any application on the domain they've logged on to because they are authenticated against that domain?Yes, that is correct if no further action is taken.
    One thing that still confuses me though is why does that second phase in Kerberos authentication needs to be applied? What I mean is that from what I was able to read, at a very generic level, Kerberos employs a two-phase process:In the first phase the client authenticates itself through the "Authentication Service" of the "Key Distribution Centre" and receives back a Ticket Granting Ticket (TGT). But then, in the second phase the same client requests a "Service Ticket" from the "Ticket Granting Service" of the "Key Distribution Centre" by presenting the TGT acquired earlier. If any authenticated user is allowed to access any resource why is that second phase (specific to the service for which access is requested) necessary? wouldn't just the first authentication phase suffice?
    I appreciate your solution and it's something we also considered initially but we were hoping Kerberos would provide this process for us :)No it wouldn't. After the first phase the client is only known to the KDC. No service is aware of any client. With the creation of a specific service ticket the service knows that the user is seriously trustworthy. Kerberos is based on a shared secret which means only the KDC knows that the client and user are real. The KDC acts as a trusted 3rd party. That's why all import authn goes thru it. Read this artice for further clarification: [http://simple.wikipedia.org/wiki/Kerberos_%28protocol%29]

  • How are users getting the flashback virus

    I don't have a virus, but I sure don't want to expose my computer.  So how is the virus downloaded?  What do I watch out for?

    Mac OS X versions 10.6.7 and later have built-in detection of known Mac malware in downloaded files. The recognition database is automatically updated once a day; however, you shouldn't rely on it, because the attackers are always at least a day ahead of the defenders. In most cases, there’s no benefit from any other automated protection against malware.
    The most effective defense against malware is your own intelligence. All known malware that affects an up-to-date Mac OS system takes the form of trojans that can only operate if the victim is duped into running them. If you're smarter than the malware attacker thinks you are, you won't be duped. That means, primarily, that you never install software from an untrustworthy source. How do you know a source is untrustworthy?
    Any website that prompts you to install a “codec,” “plug-in,” or “certificate” that comes from that same site, or an unknown site, merely in order to use the site, is untrustworthy.
    A web operator who tells you that you have a “virus,” or that anything else is wrong with your computer, or that you have won a prize in a contest you never entered, is trying to commit a crime with you as the victim.
    “Cracked” versions of commercial software downloaded from a bittorrent are likely to be infected.
    Software with a corporate brand, such as Adobe Flash Player, must be downloaded directly from the developer’s website. No intermediary is acceptable.
    Disable Java (not JavaScript) in your web browser(s). Few websites have Java content nowadays, so you won’t be missing much. This setting is mandatory in Mac OS X 10.5.8 or earlier, because Java in those versions has bugs that make it unsafe to use on the Internet. Those bugs will probably never be fixed.
    Follow these guidelines, and you’ll be as safe from malware as you can reasonably be.
    Never install any commercial "anti-virus" products for the Mac, as they all do more harm than good. If you need to be able to detect Windows malware in your files, use ClamXav — nothing else.

  • How are "Internet Accounts" shared across Macs?

    I use several Macs (office, home, notebook). I noticed that when I add a new account in "Internet Accounts" on one of the Macs, it may appear on another Mac or may not even if I'm signed in iClouds with the same Apple ID. I wonder how I can control whether a newely added Internet Account is shared across all my Macs.
    Sorry for a trivial question, but I could not find any info on this.

    Hey there zornie,
    It sounds like the features you are describing are part of iCloud Keychain.
    iCloud Keychain can also keep the accounts you use in Mail, Contacts, Calendar, and Messages up to date across all of your Macs. If you're signed in to Facebook, Twitter, Linked In, or any other accounts in Internet Accounts on OS X Mavericks, iCloud can push those accounts to your Macs as well.
    From: iCloud: Frequently asked questions about iCloud Keychain
              http://support.apple.com/kb/HT5813
    If you would like one of your devices to not automatically have accounts setup with iCloud Keychain, you would have to turn off the feature in your settings.
    iCloud: Change iCloud feature settings
    http://support.apple.com/kb/PH2613
    Thank you for using Apple Support Communities.
    Take care,
    SterlingD

  • How are Tab Groups superior to using windows for tab groupings?

    With Mac OS 10.5 I have been using windows as a defacto method for tab groupings. When tabs get two crowded, I open a new window. I have to move between windows to get to all tabs in a group.
    The Tab Grouping instructions don't address moving tabs from multiple windows into a single large group, say, for charts on a large number of stocks.
    [A disadvantage with my multiple window system has been my occasional misstep, e.g., closing a window full of tabs with the red button when I intended to minimize the widow with the yellow button, or, worse, when I get the option after a Firefox crash or power loss to Restore windows and tabs or Start a New Session and I hit the Start New session Button; in either event I lose the tabs and/or windows affected.]

    I don't ever use it because I think it is odd to have tabs floating around my desktop but you can drag Snippets, Connections and Reports outside the SQL Developer Window - Detail tabs and the Worksheet can't be. Not sure if this works on a Mac or if this is what you were looking for but wanted to mention it.
    -- Sharon

  • How are users provisioned?

    User's are provisioned through LDAP. In a standard configuration in which Sun ONE Messaging Server 5.X is the mail server, users would typically be provisioned using Sun ONE Delegated Admin (iDA). iDA creates users in LDAP. In a portal server deployment, the portal administrator would provision users with the Identity Server Console which uses an internal LDAP directory to provision users.

    Hi aapl.crox have a look at this pdf and use it as a guide, it is written for tiger but should be basically the same.
    http://www.wazmac.com/quickstarts/pdf/osxserver/tiger/090_clientsetup.pdf
    There is also some 10.5 documentation here http://www.wazmac.com/serversnetwork/fileservers/osxserver_setup/osxserver105setup.htm that is worth looking at too.
    Cheers.

  • How are user points calculated? I'm missing some.

    Recently I noticed that my user points is at 0, which odd because I've been around for a bit, and I know I've made at least one contribution to the community. So I looked up a discussion I was on where I had given a correct answer. I also took a screenshot. Its pretty funny, because something just doesn't add up at all.

    There is/was a known bug during the change-over from AD to ASC. Several of us actually LOST points! On the last day of AD, Friday April 15, 2011, I had 515 points. On Saturday night, April 16th, when ASC went live, I now had only 505 points! Anyway, I've earned a further 30 points in the last month, so I'm now at 530. There is a thread on this:  https://discussions.apple.com/thread/3002188
    Since you answered the question while we were still under AD, the suggestion that you marked your own post as "Correct" is invalid as that was impossible to do under the AD system. That ability was added as part of ASC but it does not earn you points.
    So what can you do? Well, hopefully a host will see this and correct it, but don't hold your breathe. I'm STILL waiting to hear back from them myself about my missing 10 points.

  • AE 5.2: Using user groups as a dropdown function

    Hi All
    We would like to use the user group functionality on CUP but the client does not have the same user groups across all systems.
    Our suggestion is that they have all user groups defined across all the systems.
    Is there a way that we could accomodate the client as per the current set-up where not all user groups are defined on all systems?
    Any assistance on this matter will be appreciated.

    Hi,
    I'm not sure of all the complexities around this but we had a similar problem where the user respository we used could not be connected using LDAP.
    The solution that was implemented was to create an ADAM (Active Directory Application Mode) directory, which is connected to the user repository - ADAM is then connected the UME for AE as the LDAP server.
    Probably not the most elegant solution, but we have been using this in  PRD environment for a couple of months now without any performance issues.
    Unfortunately I don't have all the details to guide you through all the config that was required, but perhaps you could investigate this as an alternative solution.
    Regards

  • Provisioning of User Group to BI systems

    Hello there,
    I am struggling a bit to find any documentation of how the User Group (BAPILOGOND-CLASS) can be provisioned to a BI system. We are already provisioning Valid From (BAPILOGOND-GLTGV) and Valid To (BAPILOGOND-GLTGB) so was imagining that it would be straight forward to provision the User Group as well. Any ideas?
    Best regards,
    Anders

    Can't have any more open questions

Maybe you are looking for

  • How to deal with the "driver not installed" message?

    My issue, and it seems many others here have it too, is how to install a printer driver in the face of the "driver not installed" message. In my case, it's an HP4160 Rendevous printer. I've deleted the com.apple.print files in the Library, reinstalle

  • Followed step by step instructions on Imaging Windows 8.1 tablets using USB drive ad WINPE however it keeps erroring and I get the following log file.

    2014-07-30 10:51:44, Info                  DISM   API: PID=2012 TID=2008 DismApi.dll:                                            - DismInitializeInternal 2014-07-30 10:51:44, Info                  DISM   API: PID=2012 TID=2008 DismApi.dll: <----- Sta

  • Connectivity - airport/Itunes

    My itunes connectivity (to to airport express and to my stereo) worked flawlessly when i had the base station set up as a separate network. The down side was I couldn't be online at the same time. Now that I figured out how to set up under the same n

  • TV SideView support for Xperia ZL IR blaster

    Phone: Xperia ZL C6506, Android 4.2.2 build 10.3.1.A.2.67 TV SideView version 2.2.2 I have my cable STB box added via the built-in Remote Control app and the box can be successfully control from the phone. However, it seems that the TV SideView app t

  • How do I make make the ethernet cable for Bt Infin...

    I have all the required parts, some good cat5e cable, rj11s and a crimper.  Which wires need conecting to which pins to make it work?  The one installed by BT appears to have just 2 wires connected? The cable I want to make is the one from the master