Is adjusting permissions for LightRoom based archive management worthwhile?

I'm trying to set up an archive that is managed through a LightRoom Catalog. I was wondering if anyone has done this before and adjusted the permissions of their files to read only to ensure that LightRoom Catalog metadata changes do not alter or get saved to files.
I plan to have the archive set up in 3 locations with copies of the LightRoom Catalog. I will need to be able to add keywords and collections to a catalog at 2 of the locations. I am interested in using permissions to ensure that the catalog is the only file that needs to travel between the locations. I don't want to get into a situation in which altering the LightRoom Catalog might alter files and necessitate that I either save new metadata to files with each keyword/collection addition or that I regularly synchronize the entire archive to ensure all 3 copies of the archive are mirrors of one another.
I have three serious concerns about the longterm viability of managing file permissions:
1. I worry that it will be difficult to manage the user/s who have the privileges to manage these permissions and that it will be difficult to do so in different locations and on different computers
2. I worry about whether permissions management might introduce some form of file corruption
3. I worry about the time involved in altering an entire archives worth of permissions to read only and the time involved in reversing this every time I want to unarchive content for new projects
I have also posted this question to Luminous Landscape here: Adjusting Permissions for LightRoom Catalog Based Archive Managment. Worthwhile?

... and adjusted the permissions of their files to read only to ensure that LightRoom Catalog metadata changes do not alter or get saved to files.
By default, Lightroom does not write anything to your photo files. Of course, there's no way to prevent a user from changing this default behavior and writing information to the files. I suppose making the directories read-only helps, but people could still change that. If the directories are on a server, then only the server admin could change the permissions.
2. I worry about whether permissions management might introduce some form of file corruption
I never heard of such a thing, but this is an operating system issue, not a Lightroom issue.
I worry about the time involved in altering an entire archives worth of permissions to read only and the time involved in reversing this every time I want to unarchive content for new projects
I don't think you understand how Lightroom works. There would be no need to reverse anything to "unarchive" the content  — although in my opinion, the idea of "archiving" content in the first place doesn't feel right ... if the photos are imported into Lightroom at one time, leave them in Lightroom, don't go through an archive process removing the photos from Lightroom followed by unarchive process, that is something that is ineffective and causes numerous problems with non-expert users. When you import photos into Lightroom, the photos still remain on your hard disk somewhere, Lightroom does not actually keep a copy of the photo. Lightroom keeps pointers to the photo's locations and stores any metadata and edits. Removing a photo from Lightroom (archiving) is the equivalent of deleting the metadata and edits, and I cannot see a reason to do that.
So, bottom line, to answer your title question, "Is adjusting permissions for Lightroom based archive management worthwhile?" — without further discussion of your setup and goals, I see no reason to even spend your time on this, unless you are the server admin of the location where the photos are stored, in which case then the answer is go right ahead and make them read-only.

Similar Messages

  • Support for Internet based client Management - SCCM 2012

    Hi There,
    My Company wants to go for Internet based client Management in SCCM 2012 SP1 R2 and here is the design I'm proposing. I'm getting a bit confused at one point and need suggestion....
    Everything would work on HTTPS ( PKI Certificate based )... LAN and Internet.
    1 Primary ( with non-client facing roles installed ) on LAN with two site systems.
    - One Site System configured for INTRANET support only with MP, DP and SUP -> To support LAN users ( Allow
    Intranet-only connections )
    - One Site System configured for INTERNET support only with MP, DP and SUP -> To support Internet users ( Allow 
        Internet-only connections )
    The INTERNET facing site system is in DMZ network connected to parent Primary via Firewall.
    We want internet clients to talk to ONLY DMZ SCCM Site System and no connection to corporate LAN. We cannot open any ports for internet based clients to LAN.
    If this is the supported scenario, then why we need to put the Internet FQDN in the Primary server Site System property. This server would not be available to internet. It should only be my DMZ SCCM server client should connect for MP, DP and SUP and only
    this DMZ server should be accessible to client over internet.
    Also, what least ports should be opened between :
    - Parent Primary and its internet facing site system kept in DMZ
    - DMZ Site system and internet clients.
    Thanks in advance for your suggestions.
    Sam

    The FQDN has only to be specified on the Internet facing site system. You can leave this field blank on the primary site Server.
    Ports to Open:
    Internet --> DMZ Site Server:
    TCP Port 443
    TCP Port 80, if Fallback Status Point is installed
    DMZ Site Server --> Primary Site:
    TCP 135, 49152-65535
    TCP 445
    TCP 135, 24158 (fixed with
    http://msdn.microsoft.com/en-us/library/bb219447(v=vs.85).aspx )
    TCP 80, 443
    If you have some other roles installed, please consult this page:
    http://technet.microsoft.com/en-us/library/hh427328.aspx
    Cheers,
    Thomas Kurth
    Netree AG, System Engineer
    Blog:
    http://netecm.netree.ch/blog | Twitter:
    | LinkedIn:
    | Xing:
    Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

  • Permissions for software use in managed account

    I have developed educational software that I cannot access through a managed account in 10.4 and 10.3. When installed in 10.4, I can access it from an admin account, but in a managed account, I get a message saying I do not have permission. In System Preferences>Accounts>Managed Account>ParentalControls>Finder&System>Applications, the software is not included in the list, but clicking Locate lets me click it from a list but the message comes up that the software "...does not work with the limitations you have selected." I do not see where I selected any limitations except to make the account managed. In 10.3, I went into SystemPreferences>Accounts>Managed Account and the list of software to assign permissions in managed account (Limitations) has a place to check a box in front of the software, but the box does not stay checked after trying unsuccessfully to open the software. I use PackageMaker as my installer software and have checked all the permissions for read/write/execute (0777) for owner, group, and others. However, when I go into the installed software's GetInfo Ownership & Permissions and the owner is the managed account, the pull-downs are grey and disabled. The same happens when I merely drag/drop the software into the Applications folder.

    ..." I get a message saying I do not have permission"...
    That message really annoys me because it is an example of a poorly worded (misleading) dialogue - the problem has nothing to do with unix "permissions". It just means the app isn't in the list of applications approved by the "admin" for use in the managed account.
    If you are the developer, make sure you have given your app a unique 'CFBundleIdentifier' or else it likely won't be possible to add the programme to 'mcx_settings', meaning it won't work in a "managed" account.
    http://docs.info.apple.com/article.html?artnum=300842
    http://developer.apple.com/qa/qa2004/qa1373.html
    If the app isn't a "package", give it a unique "creator" code there is probably some procedure somewhere about figuring out what is allowed or what has already been taken, but I'm not a developer so I can't give you any more details...

  • Ideas for text based budget management and software

    I'm looking for suggestions for text-based software or just basic scripts for tracking expenses.
    For the last six months I've been recording my purchases in text files, one file for each month.
    An entry looks like this:
    01/01/2013,Schnucks,banana, groceries,1.00,cash
    It works pretty well for recording info, no alternative system could be much faster than just adding a line to a text file.
    Now that I've been recording data for about 6 months, I'm more interested in parsing through it to see what I'm spending in each month and in various categories. At the moment, I just run the files through grep and awk to get what I want. I'm contemplating writing a python program to let me filter and calculate totals and do whatever else comes to mind: importing credit card statements, generating graphs, etc. But at that point, I feel like I'm probably just re-inventing the wheel.
    Does anybody want to share how they are handling a similar case?
    I'm ok with changing my entry format, but I'm pretty attached to handling things as text files. I don't need anything more complex if it adds to the overhead of creating an entry.

    Hey, I been doing something very similar!
    Except it also will measure income, so I can know how much I have done/expend this month, week, etc.
    I don't have it at hand atm, but I use : to separate the fields, and use slashes to escape it (like \:)
    Yes, that is a DSV file.
    I haven't dedicated time to work on it lately, but I was writing a perl script to do the calculations.
    One idea I have is to create an additonal file for a list of expenses names, like this:
    milk-z:Milk brand Z:milk
    milk-y:Milk brand Y:milk
    the first field is an unique code for the product, second field a description, and third field is a category.
    That way I could see how much I have expend on milk, no matter the brand.
    On the expenses file, an expense would be similar to this:
    2012-12-20:expense:milk-z:5.0
    The first field has the date, in the format YYYY-MM-DD; that order is important to be able to sort the file if is necessary
    Second field has "expense"; it could be "income" if it was an income
    Third field is the product code - if its something I don't buy regulary, I could be only a name (like "new led tv" or something), if is an income, the reason behind the income.
    And fourth field is just the amount of money.
    Oh, I think I'll dedicate some time to the project again

  • How to enable for Internet-Based Client Management existing "intranet" clients

    Hello,
    Step #1
    I have an existing "intranet-only" SCCM 2012 SP1 CU1 environment. It is made of HTTP Intranet-Only MP.
    All clients are properly communicated with one of the intranet MP
    All clients are leveraging auto-enrollment of our AD PKI and have a working client certificate recognized by SCCM client
    Step #2
    I expanded the above infrastructure to support IBCM clients. Basically I want the existing intranet clients still be managed when they are outside our network
    I added MP, DP, SUP, FSP on dedicated DMZ servers. It has been published on Internet, and properly declared with public DNS
    The DMZ MP has been configured for HTTPS / Internet client only
    When I tested first this setup in my lab, it was working fine, and my "intranet" client moving to Internet was properly detecting this configuration, and was starting to contact the "DMZ/Internet MP" without any problem
    I did the same on my production environment but this time, my client moving to "internet" detectes it is connected on Internet but does not have any clue about the DMZ/Internet MP to contact. According to logfile, it is trying to check on DNS,
    WINS, etc. but obviously it is already too late when in Internet, this information is no longer available.
    I guess I did something in my lab environment to make it work but I don't what. Any idea how to tell to existing clients they should use a new "Internet-Only" MP when they are on Internet ?
    Regards.

    Basically I found my problem...
    In my lab, I manually configured the SCCM client option Internet-based management point (FQDN) to use the public DNS address of my Internet/DMZ MP.
    If I do the same for my production sample client, it works fine now.
    Question: how can I enforce this change on all my existing clients ?

  • Is Intune a feasible solution for Internet-Based Client Management?

    Our organization is looking at implementing SCCM 2012, with a key requirement being that we need to be able to manage Windows updates to clients off site. My understanding is that we must have a PKI in place to do this. However, our environment is complex
    enough that PKI may not be an option.
    My question is, would leveraging Intune and SCCM 2012 be a possible solution? I understand Intune is geared towards MDM, but I'm trying to figure out if we could "assign" off-site clients to SCCM via Intune and manage Windows updates like we do
    with on-site clients.
    I apologize ahead of time if this question has already been answered, but I'd appreciate any insight you all have. Thanks.

    No, unfortunately you can't do that. Computers are handled differently than mobile devices in the Unified Solution of ConfigMgr and Intune.
    Mobile Devices - enrolled with Intune and managed via ConfigMgr (must set the Mobile Device Authority to ConfigMgr).
    Computers - they can have an Intune client OR a ConfigMgr client. They cannot have both. Therefore if you enrol and computer with Intune you cannot manage it with ConfigMgr.
    Are these remote computers domain joined? Have you considered Direct Access as a possible solution. It's straightforward to implement.
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

  • [Solved]Archive Manager 3.14.1 won`t open RAR5 archive

    Hello again
    Today I make a RAR5 archive for testing if Archive Manager can open, but he cant.
    In vbox I have Ubuntu 14.10 and use Archive Manager 3.10.2.1 an can open archive.
    How repair this bug on 3.14?
    I use LXDE, file-roller for pcmanfm.
    Tks
    Last edited by xxvirusxx (2014-11-04 12:48:02)

    I don`t know, but I have libarchive installed.
    Archive Maanger open .RAR but not RAR5. (photo)
    Also I reported this bug on file-roller
    I will try to find differences from 3.10.2
    Last edited by xxvirusxx (2014-11-03 18:22:01)

  • Remote Desktop Service Manager - configure permissions for Remote Desktop Users to Send Message, Disconnect, Logoff

    Hello, dear colleagues.
    We are using Windows Server 2012 R2 as Remote Desktop Server. Also use Windows Server 2008 R2 with Remote Desktop Service Manager to control RDS user sessions (Send Message, Disconnect, Logoff, Query Info). 
    Send Message, Disconnect, Logoff options works only for users in Administrators group.
    I can't to configure permissions for Remote Desktop Users, specific user or AD group. 
    To set permissions I'm running RDS Host Configuration on Windows Server 2008 R2 and connect to Windows Server 2012 R2. Then double-click
    RDP-Tcp, Security tab, add specific user account , AD group or configure
    advanced permissions
    for Remote Desktop Users.  
    But, as I sad above, these options works only for users in Administrators group. How to make it work for Remote Desktop Users or specific user, AD group?
    Thanks.
    P.S. If move specific user from Remote Desktop Users group to Administrators group on
    Windows Server 2012 R2 - it works. 

    Hi,
    You can prevent administrators from changing the permissions for a connection by applying the
    Do not allow local administrators to customize permissions Group Policy setting. 
    This Group Policy setting is located in Computer Configuration\Policies\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Security
    Apart there is one command with which you can set the permission for that check the related
    article. Additionally checkthis
    thread for more detail.
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Any direct installer for Lightroom?  Adobe Application Manager crashes every time (Mac OS 10.9.4)

    I'm trying to migrate from Aperture to Lightroom.  Needless to say the existing help documentation assumes the installer software doesn't crash!
    When using this page:
       https://creative.adobe.com/products/download/lightroom
    The only download link I can access is:
       aam://SAPCode=LTRM?productVersion=5.6?passPhrase=dlC9juiw9Uf9g+Vks1IUflaugqLAqM2EyWucW2/M huZnOYOCur4ZPchERE/PxfIlqFF7/QWRqz+ih8+bvn+J39PlBZwWu33FApnWWqGJO6opmjCzfoFwO73gjpPwAh42tt vFTOwPE+BJB8N6wUFykA/PdAxD9Sn9L2OFSEge5I8=
    Which attempts to launch the Adobe Application Manager to perform the installation.  However, after displaying the loading screen for approximately one second, it crashes.  Is there any way to get a direct download for LightRoom?

    Downloads available:
    Suites and Programs:  CC 2014 | CC | CS6 | CS5.5 | CS5 | CS4 | CS3
    Acrobat:  XI, X | 9,8 | 9 standard
    Premiere Elements:  12 | 11, 10 | 9, 8, 7
    Photoshop Elements:  12 | 11, 10 | 9,8,7
    Lightroom:  5.6| 5 | 4 | 3
    Captivate:  8 | 7 | 6 | 5
    Contribute:  CS5 | CS4, CS3
    Download and installation help for Adobe links
    Download and installation help for Prodesigntools links are listed on most linked pages.  They are critical; especially steps 1, 2 and 3.  If you click a link that does not have those steps listed, open a second window using the Lightroom 3 link to see those 'Important Instructions'.

  • Manage permissions for a list sharepoint 2013

    Hey
    A user, only have permission to contribute on Document Library. He can give permissions for items in this Document Library?
    This user don't have permission to  Site but just the  Document Library? 
    Thanks

    Hi  Fabio,
    No, an account with contribute permission level cannot manage the permission. For managing permissions, the account must have “Manage Permissions” permission.
    For achieving your demand, you need to create a custom permission level with Management Permissions permission   and  share the Document Library with the user  with your custom permission
    level.
    You can refer to the similar thread I had replied  for detail steps:
    http://social.technet.microsoft.com/Forums/en-US/9a6f7e55-fc39-4c47-a23b-7d709233b86d/giving-list-permission-to-users-with-no-access-to-the-main-site
    Best Regards,
    Eric
    Eric Tao
    TechNet Community Support

  • Looking for best practice white paper on Internet Based Client Management

    Looking for best practice white paper on Internet Based Client Management for SCCM 2012 R2.
    Has anyone implemented this in a medium sized corporate environment? 10k+ workstations.  We have a single primary site, SQL server and 85 DP's. 

    How about the TechNet docs: http://technet.microsoft.com/en-us/library/gg712701.aspx#Support_Internet_Clients ?
    Or one of the many blog posts on the subject shown from a web search: http://www.bing.com/search?q=configuration+manager+2012+internet+based+client+management&go=Submit+Query&qs=bs&form=QBRE ?
    Jason | http://blog.configmgrftw.com | @jasonsandys

  • Archiving flag for BP based on activity status and delete archvied BP

    Hi All,
    Can we flag archiving check box for BP based on specific activity status and delete these archived BP's using BUPA_DEL.
    Thanks

    Use Function module
    BAPI_BUPA_CENTRAL_CHANGE and set the flag CENTRALARCHIVINGFLAG to true in the structure
    BAPIBUS1006_CENTRAL.
    Thanks,
    Thirumala.

  • Are there any Hotkeys for Adjusting Temperature in Lightroom, similar to + and - for exposure?

    Are there any Hotkeys for Adjusting Temperature in Lightroom, similar to + and - for exposure?

    If you click on the word Temperature, then + and – will adjust the temperature up and down, respectively.
    Note: whenever you click on another slider name, like Exposure, then the + and – new work on the slider name you just clicked on

  • Any API for XML-based JAAS Provider management

    Hi, All:
    I am working on creating a realm based on jazn-data.xml, it is a XML-based JAAS provider. the jazn.jar shell seems to provide utilities to manage a realm. I am just wondering if there is any API available for XML-based JAAS Provider management.
    The package com.evermind.security oracle.security.jazn oracle.security.jazn.realm seems to be the proper API. However, accoring to the API doc, it seems that the API can not directly work for jazn-data.xml, any body have sugguestions?
    I'd really appreciate your help.

    Hi,
    you should look towards jGuard (www.jguard.net) which enables easy JAAS integration into j2ee webapps across many applications servers(including OC4J, tomcat, jetty, jonas, jboss ...).
    it adds many features including a taglib, some convenient loginmodules(CRL, OCSP, JNDI), and so on....
    cheers,
    Charles(jGuard team).

  • Do we have a built-in option for web based tool in Nexus 5548UP switches for management purpose?

    I have purchased Nexus 5548UP switch, i want to know if we have a built-in option for web based tool to manage and configur it just as ASA have ASDM. If there is no such options then what are the options available that can be freely available and can be used to get performance monitoring done.
    Message was edited by: Praveen Varun

    DCNM (Data Center Network Manager) runs on a server (Windows, RHEL or Solaris) and can be used to manage Nexus devices. It's free for Nexus 1K through 5K devices (paid license required for Nexus 7K management).
    http://www.cisco.com/en/US/products/ps9369/index.html
    There is not a "built-in" management product like ASDM for ASA.

Maybe you are looking for