Lighttpd https redirect for only certain directories

This works great for redirecting all traffic to https on my home server:
# Redirect all http requests to https
$SERVER["socket"] == ":80" {
$HTTP["host"] =~ "(.*)" {
url.redirect = ( "^/(.*)" => "https://%1/$1" )
However, I'm trying to exclude one directory from this (other people using it, self-signed ssl messages...you get the idea ) and I can't quite wrap my brain around it. Server Fault and Stackoverflow had some examples that were close, but I couldn't manipulate them into doing what I wanted. A gentle shove in the right direction would be much appreciated.
Very simple layout: /srv/http/<dir1> /srv/http/<dir2> /srv/http<dir3> etc. Call it 'foo-dir' that I want to exclude. The server sits behind a consumer router with all port 80 and 443 traffic directed to the server's static IP.  External IP via dyndns.
Thanks!
Scott

SFTP is a subset of SSH. Currently Apple uses OpenSSH which does not have any kind of chroot jail for SFTP as it does for FTP. If you want to have an SFTP chroot jail, you will need to do some alterations. Currently there are two methods which are documented here:
http://www.schwie.com/brad/macosxsftpchroot/
  Mac OS X (10.4.4)  

Similar Messages

  • Display webpage for only certain time.

    Hi,
    I want to display a new webpage from a link for only certain amount of time and get back to original webpage(dont care about the size of webpage).
    I know to do in javascript but i was wondering if it is possible using JSP & servlets.
    appreciate any reply.
    Thank you.

    My application for mobile browsers which are not powerful enough to handle java script so need to handle everything on server side. any solution,suggestions please

  • Enable WebAuth on WLC to intercept https (or https redirection) for authentication

    Hi all
    My company is using WLC with Guest access feature, and use Layer 3 security authentication to permit only Guests who provided valid user/password to access.
    But we met a issue that, when guests connect to Guest SSID successful, on PC they have to open web browser and access to 1 website by http, after that WLC will intercept and redirect to authentication page.
    If customer access to https (as google, gmail, ...) WLC cannot intercept and redirect to authentication. Because almost customers access to https://google.com at first by their habit.
    On my firewall, I can do intercept by both http and https, so I wonder on WLC I can enable intercepting and redirecting to authentication of https also
    If possible, please advice us how to enable this feature.
    Regards
    Hai Dao Tuan

    Thanks all
    I also just found a link that mentions about this case clearly and commands to enable it
    https://supportforums.cisco.com/document/12398536/understanding-https-redirect-over-web-auth
    (WLC)> config wlan security web-auth enable <wlan-id>
    (WLC)> config network web-auth https-redirect enable

  • "Error - Printing" for only certain PDFs to certain printers with Reader 10.1.3

    One of my users is unable to print specific PDF files to a particular printer.  The same PDFs will print to other printers successfully from the Windows 7 machine.  But, for certain PDF files the printer queue will show status = "Error - Printing".  We have tried to print as image, saved the PDFs as different filenames but it still fails.  There seems to be no pattern for the PDF types.  One PDF is a scanned document and another is not scanned.  The machine is able to print most other PDF files just fine to this printer and can print successfully from all other applications except for Reader 10.1.3 for these certain PDF files.  The printer driver has been updated to the latest.  The printer is a Xerox DocuCenter-IV 2060.  AR 10.1.3 has been re-installed.
    The PDF files in question open fine and can be viewed in their entirety (i.e. they don't appear to be corrupt).  The fonts used are not any different from others used in PDFs that DO print ok.  This is a complete mystery so, if anyone has ideas, please pass them along.  Thanks so much

    This is a public forum; please do not post your email address or other private information.
    Regarding your issue; it appears you have already tried everything possible - I have no other ideas what to try with 10.1.3.
    The only solution for now I can see is to revert back to 9.5.1; is this a problem for you?  This should be only temporarily until a new version of 10.x or 11.x becomes available.

  • Renewed Cert, now http redirect for OWA no longer works

    From this previouse thread, where I was discussing cert issues, I renewed my cert (to expire in a few days) from my third party (GoDaddy).  I installed the new Cert via teh GoDaddy instructions:
    http://support.godaddy.com/help/article/4877/installing-an-ssl-certificate-in-microsoft-exchange-server-2007
    now, when attempting to connect to http://mail.MyDomain.com, I get the dreaded "403: Forbidden: Access is denied" message
    If I put in https://mail.MyDomian.com, it opens OWA normally.  I do have (and have had) redirect of http enabled as shown in this Miscrosoft Article:
    http://technet.microsoft.com/en-us/library/aa998359(EXCHG.80).aspx, so that's not hte issue.
    Any ideas please...
    James

    Well, solved it myself.  Not sure what was differnt before now however, I went to this document from Microsoft (note: this says for Exchange 2010, but also applies to 2007, which is what I am running):
    http://technet.microsoft.com/en-us/library/aa998359.aspx
    And there at the yellow box, it says:
    In the Default Web Site Home pane, click SSL Settings.
    In SSL Settings, clear Require SSL.
    If you don’t clear Require SSL, users won’t be redirected when they enter an unsecured URL. Instead, they’ll get an access denied error.      
    After that, if someone goes to http://mail.MyDomain.com it redirects to
    https://mail.MyDomain.com as needed.  Why did the cert update bring this problem to the surface, not sure.
    Thanks,
    James

  • Https redirect for SGD 4.4

    Hello,
    I am attempting to set up the apache webserver to redirect http traffic to https.
    I originally was able to achieve this in SGD 4.3 by using the RewriteEngine in the httpd.conf file to simply rewrite all requests to https, but this appears to no longer work for SGD 4.4.
    I have properly configured SSL support, and going to https://<servername> works just fine, I'd just like to able to force traffic over https for convenience and security for my users.
    Any help would be greatly appreciated.
    Adam

    Hello,
    That worked, and I was redirected to an https connection until I attempted to log in. The following error was returned:
    javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
    Any suggestions?
    UPDATE: A google search suggested that this may be a result of my using a selfsigned cert for testing purposes. See:
    http://dreamingthings.blogspot.com/2006/12/no-more-unable-to-find-valid.html
    I'll try using the InstallCert.java and see if it works.
    Adam
    Edited by: adamallred on Mar 6, 2008 3:02 PM

  • Silent override setting for only certain people?

    There is one thing stopping me from buying an iPhone and I'm really hoping somebody has a fix for me. On my Blackberry, I'm able to assign a ringtone and volume to certain people...making it possible to switch my phone to silent when I go to sleep, and only 2 people will wake me up if they call. I work nights and am on call. I CAN'T buy an iPhone until this is possible :0(

    There is a way to create a silent ringtone. I am sure there is one on iTunes. If the 10,000 free ringtones app still works it had one. Or you can create the ringtone through the Voice Memo.
    Then you could assign only those two people their own ringtone- and then when you don't want to be bothered switch the generic ringtone to the "silent" one that you created.

  • IPhone loses playcount for only certain songs

    I have been having a bizarre problem ever since I upgraded to iOS 6 on my iPhone 4S. Every now and then, when I sync the phone with iTunes (running on a Windows 7 system), the play count for some songs is completely lost. The last played date/time is properly updated, but the play count disappears.
    I use a smart playlist that only plays songs that have been played less than X times and which haven't been played in the last week so that I guarantee that I will go through my entire library. When my smart playlist has no songs left in it, I edit it to increase the "playcount less than" by 1, and all the songs show up again for my next pass through them. I was up to having songs played 20 times (this goes back to my first iPod in 2006), but then I noticed that some of them were showing up on my smart playlist again, When I looked more closely, the 19-20 plays were gone - the play counts were just blank. The last played was correct, though.
    This was not consistent - it happened for one entire album at one time (weird, since the songs played at widely-separated times over the course of a month), but otherwise only for a few songs here and there, and they were getting lost at seemingly random times after a sync. So, I thought that maybe my play count metadata was somehow corrupt. I reset the play counts for all my music to 0, and then started over (with a playlist that only includes songs played less than one time). This had no problems for several weeks, but I just today noticed a song that showed up again on my smart playlist. It was last played on January 15th, but it has no play count even though I haven't reset them since January 3rd. There were plenty of songs played immediately before and after it on that same day, and they still show a play count of 1, but this one song shows nothing.
    Has anyone else seen this? I have been relying on the play count for my smart playlist since I got my first iPod 7 years ago, but if it's not going to work any more, then that's going to cause me a real problem.

    For what it's worth, and for the benefit of anyone else searching for this problem who comes across this thread, I think I've come up with a solution for the "resetting play count" bug, or at least the version I've been seeing.
    As various people have pointed out in this thread the problem is related to iTunes Match, which I have enabled in order to have access to my whole library on my iPad. I don't use Match on the iPhone because I want to be able to control its contents with Smart Playlists.
    It was incompatibilities between these two systems that lead to my problems with play counts, or Plays as Apple now calls them. No matter what I tried there were several albums and a handful of individual tracks that would keep randomly resetting their Plays to zero and thus populating themselves onto my Unplayed playlist where they didn't belong. More often than not this would happen when my iPhone had been switched off and on, or when iTunes Match was updated manually.
    What follows are the only solutions I've found that seem to eradicate this problem. They're annoyingly fiddly, but I've had 100% success with them over the last couple of days.
    The short version (for iTunes experts or those who want to find their own method):
    Delete the problematic tracks from iCloud.
    Set their Plays to non-zero in the local library.
    Add them back to iCloud with a non-zero initial Plays count.
    The step-by-step version using two machines (very reliable):
    To use this method you will need to have two Macs or PCs running iTunes and iTunes Match; a "master" machine that holds all of your media and your main iTunes library, and a "slave" machine with an otherwise empty iTunes library linked to the iTunes Match account. An iOS device will not work for this because it won't let you delete tracks from iCloud.
    It might be possible to use a Virtual Machine or even just a second, empty, iTunes library as the slave but I haven't tried this and it would be exceptionally time consuming, especially the two-libraries method with all the switching. I just used an old laptop I had lying around.
    Make sure that iTunes Match is active on both machines using the same Apple ID. The slave machine, having no media of its own, should only be showing iTunes Match songs in its library.
    In the libraries of both machines use the search box to find some tracks for which the Plays keep resetting. You need to be looking at the same tracks in the main library on each machine, not in a playlist. Use the Songs view so you can see as many columns as possible.
    Make sure that the iCloud Download, iCloud Status and Plays columns are all visible on the master machine's library (right-click the column header and select them if they aren't).
    On the slave machine, highlight the problematic tracks and hit Delete. Because the tracks aren't stored locally, iTunes will ask you if you want to delete them from iCloud instead. Confirm the deletion.
    The tracks will disappear from the slave machine's library. Wait a few seconds and the tracks' iCloud Status on the master machine should change from Matched (or Uploaded) to Removed and the iCloud Status icon should change to a cloud with an X inside.
    On the master machine, highlight the Removed tracks and reset their Plays to 1. If you're running Windows you can use the script mentioned in the posting above, otherwise you will have to play each track and use the scrubber control to jump to the end. Continue until each track is showing a Plays count of 1.
    Still on the master machine, select the newly updated tracks, right click and choose Add to iCloud from the menu. iTunes match will report that it is "sending information to Apple" followed eventually by "waiting for Apple to deliver your iTunes Match results", and the iCloud Status will change to Waiting.
    You may have to wait a while as the iCloud data is updated, especially if the track can't be matched and have to be uploaded. After a few minutes the iCloud Status for the tracks should change to Matched (or Uploaded) and they should also reappear in the slave machine's library.
    Repeat for any additional problematic tracks.
    The step-by-step version using one machine (potentially less reliable):
    This method may appear simpler than the one above because it only uses a single machine, but in my experience it requires certain tasks to be done in a timely manner if it's to be successful and it's very easy to do the wrong thing at the wrong time or drag-and-drop the wrong file and screw things up. I prefer the two-machine method but if you don't have access to a second machine this is, sadly, the only way.
    Note also that these instructions are for Windows, and will vary slightly for the Mac. For instance I believe the Show In Windows Explorer option has a Show In Finder equivalent on OSX, and the Recycle Bin is called Trash. Beyond that I have no idea as I'm not an OSX user. If you're on a Mac, be sure you know what you're doing before you try this method.
    Make sure that iTunes Match is enabled in iTunes.
    In the iTunes library use the search box to find some tracks for which the Plays keep resetting. You need to be looking at the tracks in the main library, not in a playlist. Use the Songs view so you can see as many columns as possible.
    Make sure that the iCloud Download, iCloud Status and Plays columns are all visible (right-click the column header and select them if they aren't).
    Select a problematic track, right-click and select Show In Windows Explorer. This will open a window containing the actual MP3 or AAC file (or files if there are multiple tracks that are part of the same album). Leave this window open and available.
    Back in iTunes, highlight the problematic track or tracks whose files are in the Explorer window and hit Delete. In the dialog that appears, tick the box labelled Also delete this song from iCloud then click Delete Song(s).
    Another dialog will appear asking if you want to move the files to the Recycle Bin or keep them. Click Keep File(s).
    Wait a few seconds for the track(s) to disappear from the iTunes library. If you have another machine or iOS device linked to the same iCloud library you will see the tracks disappear from there as well.
    Go to the window you opened in the earlier step and drag-and-drop the relevant MP3 or AAC file(s) onto the iTunes window. The deleted track(s) should reappear in the library with an iCloud Status of Waiting.
    Using either the script method mentioned in the earlier post above, or by playing each track and scrubbing to the end, make sure that the Plays count is made non-zero for each newly added track.
    It is VITALLY IMPORTANT that you do this quickly before iTunes begins to update iTunes Match with the track information. If you're not quick enough, iTunes will update the tracks in iCloud with an initial Plays count of zero and you can find yourself right back at square one with tracks whose Plays keep resetting. Trust me, I've seen it many times. If you feel you might not get all of the Plays set to non-zero values quickly enough, consider yanking the network cable out of the computer while you're doing this bit. I'm not kidding. Once iTunes starts uploading that data it's anybody's guess as to whether the Plays counts will stick or not.
    Once all your Plays are non-zero, wait (plug the network back in if you pulled it!) and after several seconds iTunes will start to display a series of feedback messages in the display window starting with "Sending information to Apple" and will conclude by matching your track(s) to iTunes and uploading if necessary. These operations may take considerable time especially if there were many tracks added simultaneously. Once concluded the iCloud Status for the track(s) should change to Matched or Uploaded.
    Repeat for any additional problematic tracks.
    Please note that I've only used these methods to work around the intermittent resetting of Plays. For other issues raised in the thread linked above, including the loss of Last Played dates, these methods may be of limited use or no use at all but they may serve as a jumping off point for others to find their own solutions.
    I've still got no idea what causes certain tracks to suffer from phantom Plays resets in this way, although I did do an awful lot of switching iTunes Match on and off on various devices when I first subscribed so it's possible I'm at least partly responsible even if it's ultimately an Apple bug that's manifesting. All I know is that for the first time in months I'm reasonably confident that my Unplayed playlist won't suddenly repopulate with old tracks.
    I pray the next few days don't prove me wrong.

  • Why cant i change user password or pwdlastset after delegation for only certain users in an ou?

    I remembered a while ago I used delegate control to assign the ability to reset pwd and reset change on next logon.  It seems to work for some users but not others in same ou.  effective permissions shows I have write access to the attribute for
    the user; see imgur link below.  the box for change pwd at next logon is gray.  attribute editor tab doesn't allow me to edit it either.  domain admins can change it.  I'm wondering what else I should check out cus everything I know says
    I have the right to change it.
    forest / domain level 2003
    http://imgur.com/1VHuh7h
    mydomain\Allow Reset Win Pwd   was used for delegation and the user trying to change the password is a part of that group. they are also a member of account operators
    Owner: mydomain\Domain Admins
    Group: mydomain\Domain Admins
    Access list:
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS
                                          READ PERMISSONS
                                          LIST CONTENTS
                                          READ PROPERTY
                                          LIST OBJECT
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS
                                          READ PERMISSONS
                                          LIST CONTENTS
                                          READ PROPERTY
                                          LIST OBJECT
    Allow mydomain\Domain Admins          SPECIAL ACCESS
                                          READ PERMISSONS
                                          WRITE PERMISSIONS
                                          CHANGE OWNERSHIP
                                          CREATE CHILD
                                          DELETE CHILD
                                          LIST CONTENTS
                                          WRITE SELF
                                          WRITE PROPERTY
                                          READ PROPERTY
                                          LIST OBJECT
                                          CONTROL ACCESS
    Allow mydomain\Enterprise Admins      SPECIAL ACCESS
                                          READ PERMISSONS
                                          WRITE PERMISSIONS
                                          CHANGE OWNERSHIP
                                          CREATE CHILD
                                          DELETE CHILD
                                          LIST CONTENTS
                                          WRITE SELF
                                          WRITE PROPERTY
                                          READ PROPERTY
                                          LIST OBJECT
                                          CONTROL ACCESS
    Allow BUILTIN\Administrators          SPECIAL ACCESS
                                          DELETE
                                          READ PERMISSONS
                                          WRITE PERMISSIONS
                                          CHANGE OWNERSHIP
                                          CREATE CHILD
                                          DELETE CHILD
                                          LIST CONTENTS
                                          WRITE SELF
                                          WRITE PROPERTY
                                          READ PROPERTY
                                          LIST OBJECT
                                          CONTROL ACCESS
    Allow NT AUTHORITY\Authenticated Users
                                          SPECIAL ACCESS
                                          READ PERMISSONS
                                          LIST CONTENTS
                                          READ PROPERTY
                                          LIST OBJECT
    Allow NT AUTHORITY\SYSTEM             FULL CONTROL
    Allow mydomain\Allow Reset Win Pwd    SPECIAL ACCESS   <Inherited from parent>
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS   <Inherited
    from parent>
                                          READ PERMISSONS
                                          LIST CONTENTS
                                          READ PROPERTY
                                          LIST OBJECT
    Allow BUILTIN\Terminal Server License Servers
                                          SPECIAL ACCESS   <Inherited
    from parent>
                                          READ PERMISSONS
                                          LIST CONTENTS
                                          WRITE SELF
                                          WRITE PROPERTY
                                          READ PROPERTY
    Allow mydomain\Enterprise Admins      FULL CONTROL   <Inherited from parent>
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS   <Inherited
    from parent>
                                          LIST CONTENTS
    Allow BUILTIN\Administrators          SPECIAL ACCESS   <Inherited from parent>
                                          DELETE
                                          READ PERMISSONS
                                          WRITE PERMISSIONS
                                          CHANGE OWNERSHIP
                                          CREATE CHILD
                                          LIST CONTENTS
                                          WRITE SELF
                                          WRITE PROPERTY
                                          READ PROPERTY
                                          LIST OBJECT
                                          CONTROL ACCESS
    Allow mydomain\Delegate-Join-Domain-Rights
                                          SPECIAL ACCESS for computer  
    <Inherited from parent>
                                          CREATE CHILD
    Allow Everyone                        SPECIAL ACCESS for computer   <Inherited from parent>
                                          CREATE CHILD
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Account Restrictions
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Account Restrictions
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Logon Information
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Logon Information
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Group Membership
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for General Information
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for General Information
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Remote Access Information
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Remote Access Information
                                          READ PROPERTY
    Allow mydomain\Cert Publishers        SPECIAL ACCESS for userCertificate
                                          WRITE PROPERTY
                                          READ PROPERTY
    Allow BUILTIN\Windows Authorization Access Group
                                          SPECIAL ACCESS for tokenGroupsGlobalAndUniversal
                                          READ PROPERTY
    Allow BUILTIN\Terminal Server License Servers
                                          SPECIAL ACCESS for terminalServer
                                          WRITE PROPERTY
                                          READ PROPERTY
    Allow mydomain\Allow Reset Win Pwd    SPECIAL ACCESS for pwdLastSet   <Inherited from parent>
                                          WRITE PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Account Restrictions  
    <Inherited from parent>
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Logon Information  
    <Inherited from parent>
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Group Membership  
    <Inherited from parent>
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for General Information  
    <Inherited from parent>
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Remote Access Information  
    <Inherited from parent>
                                          READ PROPERTY
    Allow BUILTIN\Terminal Server License Servers
                                          SPECIAL ACCESS for accountExpires  
    <Inherited from parent>
                                          WRITE PROPERTY
    Allow BUILTIN\Terminal Server License Servers
                                          SPECIAL ACCESS for Terminal Server
    License Server   <Inherited from parent>
                                          WRITE PROPERTY
                                          READ PROPERTY
    Allow NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
                                          SPECIAL ACCESS for tokenGroups  
    <Inherited from parent>
                                          READ PROPERTY
    Allow NT AUTHORITY\SELF               SPECIAL ACCESS for Private Information   <Inherited from parent>
                                          WRITE PROPERTY
                                          READ PROPERTY
                                          CONTROL ACCESS
    Allow Everyone                        Change Password
    Allow NT AUTHORITY\SELF               Change Password
    Allow mydomain\Allow Reset Win Pwd    Reset Password   <Inherited from parent>
    Permissions inherited to subobjects are:
    Inherited to all subobjects
    Allow mydomain\Enterprise Admins      FULL CONTROL   <Inherited from parent>
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS   <Inherited
    from parent>
                                          LIST CONTENTS
    Allow BUILTIN\Administrators          SPECIAL ACCESS   <Inherited from parent>
                                          DELETE
                                          READ PERMISSONS
                                          WRITE PERMISSIONS
                                          CHANGE OWNERSHIP
                                          CREATE CHILD
                                          LIST CONTENTS
                                          WRITE SELF
                                          WRITE PROPERTY
                                          READ PROPERTY
                                          LIST OBJECT
                                          CONTROL ACCESS
    Allow mydomain\Delegate-Join-Domain-Rights
                                          SPECIAL ACCESS for computer  
    <Inherited from parent>
                                          CREATE CHILD
    Allow Everyone                        SPECIAL ACCESS for computer   <Inherited from parent>
                                          CREATE CHILD
    Allow NT AUTHORITY\SELF               SPECIAL ACCESS for Private Information   <Inherited from parent>
                                          WRITE PROPERTY
                                          READ PROPERTY
                                          CONTROL ACCESS
    Inherited to group
    Allow NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
                                          SPECIAL ACCESS for tokenGroups  
    <Inherited from parent>
                                          READ PROPERTY
    Inherited to computer
    Allow NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
                                          SPECIAL ACCESS for tokenGroups  
    <Inherited from parent>
                                          READ PROPERTY
    Inherited to group
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS   <Inherited
    from parent>
                                          READ PERMISSONS
                                          LIST CONTENTS
                                          READ PROPERTY
                                          LIST OBJECT
    Inherited to inetOrgPerson
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS   <Inherited
    from parent>
                                          READ PERMISSONS
                                          LIST CONTENTS
                                          READ PROPERTY
                                          LIST OBJECT
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Remote Access Information  
    <Inherited from parent>
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for General Information  
    <Inherited from parent>
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Group Membership  
    <Inherited from parent>
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Logon Information  
    <Inherited from parent>
                                          READ PROPERTY
    Allow BUILTIN\Pre-Windows 2000 Compatible Access
                                          SPECIAL ACCESS for Account Restrictions  
    <Inherited from parent>
                                          READ PROPERTY
    The command completed successfully

    I think this is a problem with the user object rather than the ou.  Reasoning is that I can reset a password for a user in the same OU but not for another user in the same OU.  Two users, same ou.  I can reset one but not the other.  
    Effective Permissions shows I am granted permisiion to do so.
    I believe the error was access denied when we tried to change the password via vbscript.
    @seansobey - I applied the delegation at a ou higher in the tree.  I forget how I had it apply down the tree but I confirmed that the acl is correct
    and applied to the user
    @Travis Vogel - It looks like the user with this problem is a part of Domain Users.  I think the ACL is applied to the user because it shows in
    the security window and effective permissions shows I have permission to reset the password.  However, I see this other user is a part iof the builtin user group and the problematic user account is not.  I may try adding the problematic user account
    to that group and testing.  It'll have to wait until tomorrow though.

  • "save as jpeg" not working for only certain images (pse 2.0)

    I've searched for hours, trying to figure this issue out, but there seems to be no answers to my particular perdiciment.  So I guess I'll start a new discussion with hopes to find any answer that can lead me in the right direction.  For some reason, I am now getting a program error when I try to save some images as jpegs.  It seems that only a small percentage of my pics are having this issue, and they are the ones I have taken in the past two days.  I can go back into my catalog and run any other pics through PSE and save as a jpeg with no problems.  But if I try to do any touch ups on any of the pics from yesterday or the day before, i get the error message.  I can even go back into lightroom 4 and export any pics from 3 days ago and have no issues saving them as jpegs.  I always get the option to save as a jpeg, it just errors out while trying to save.  I'm using a somewhat older laptop w/ vista 64 bit.  If anyone can help me out I would greatly appreciate it.  If you need any more info, just let me know and I'll try to reply as fast as I can. 
    Thanks in advance!    

    I just saw the end of your subject:  Are you really using Photoshop Elements 2? 
    If you Save As – A Copy and use a different name does the save work?
    Is there some background process that is analyzing the original  files, either a system-cloud backup or a PSE photo analysis for heads or other things, that might have the file momentarily in use and therefore be unwritable?
    Is your system almost out of memory, or is the hard-drive almost full or does the hard-drive have errors, or is the destination hard-drive something across a network or USB connection and that connection is iffy?

  • Looking to find out why icons appear for only certain bookmarks and how to replace the dashed rectangle with a valid icon in those cases.

    As the question explains, some of the icons for visited sites appear only as a dashed rectangle. There are several bookmarks that have been successfully imported from an html file and a few of them have no icon showing on the Firefox toolbar or bookmark list yet they did on the original browser where they wre imported from. Typically, the icons will "fill in" when each of the imported sites are visited some some do not regardless of how many times visited.
    I have checked to make sure that the fonts and colors are being selected by the site/server so that is not the problem.
    Although it is a somewhat cosmetic feature (navigation works fine, just no icons), the icons make site recognition much faster visually, making browser that much faster and easier on the eye.
    Any help to resolve this issue would be greatly appreciated for a "second-time-around" Firefox user.

    The reloader did the trick! Not sure why it took the add-on to get the correct favicon but problem solved, easily and quickly. I'll be sure to recommend the Firefox/Mozilla Support Forum to friends that use the browser. Thanks!

  • Is there a way to make Mail app badge to show the count of unread mail for only certain account?

    The mail app badge normally shows the total count of unread emails in all your accounts.  Is there a way to set it so that it only displays the count from one specific mail account?

    No.
    http://manuals.info.apple.com/en_US/iphone_user_guide.pdf    WYSIWYG

  • Mail sound for only certain accounts

    Hi. I would like to only hear the new mail sound for some accounts and not others. Is there a way I can set this up in the latest version of Mail??
    thanx.

    I'm not aware of any available sound setting that is account specific but you might take a look at creating a rule by account. I have a rule to play a different sound with recieving a message from a particular email address.

  • "General Error" and "Out of Memory" for only certain files?

    I have Final Cut Express 4 on Mac OS X Leopard and it has been working fine, up until now.
    For some reason, when I try to view two clips in the tab to the left of the screen to find sections of them to put into my project, I get a message that says, "General Error" and when I click okay it says, "Error: Out of Memory". They are both mp4 files, and are 242.9 MB and 294.2 MB, and I have viewed them both on Quicktime. I don't understand why it is saying that it is out of memory when I still have 7 GB left on my computer and it still lets me view and add other files into my sequence.
    Can someone help me out and tell me how to fix this? I'd really appreciate advise!

    MPEG-4 is not a format that works in FCE. You'll have to convert it to one of FCE's format. Without knowing details about what the original format is it's impossible to say what you should convert it to.

  • Authorization messages for only certain songs?

    two songs I recently downloaded repeatedly ask for computer authorization and when I do it says this computer is already authorized but when I try to play them the same message comes up?  Others I download work fine?

    They’re corrupt. Delete and redownload them if doing so is free in your country.
    (111788)

Maybe you are looking for