MBP, 1-user, 2-logins (work vs personal), trouble setting ACL's

I'm fairly accustomed to setting ACL's and permissions (not overly confident with chmod) but the challenge I've had is establishing standard ACL/permissions for directories that I want to share between each of my logins but still lock out anyone else from even reading it.
_Here's what I've done:_
Under "Macintosh HD:Users:Shared:" I have a folder titled "Personal" which I share between my personal login and my work login. I've set the ACL's of that folder as follows:
(personal login) Read & Write
(work login) Read & Write
everyone No Access
I have access without issue at this point but even though I propagated permissions to all enclosed items, any new items are restricted. Is there a way to set the default ACL on new items to reflect that of the permissions of the parent folder rather than that of the user?
I'm not a fan of keeping the "everyone" to even "Read" or "Write only (Drop Box)".
Any suggestions would be really appreciated! Thanks!

It appears that ACLs set from the "Get Info" box do not set the inheritance options, even when applied to "enclosed items", which seems to be a one shot deal. For example, when a new rule is created in "Get Info" to allow a different user to "read & write", with 'ls -led /path/to/folder' I see:<pre style="overflow:auto; padding: 5px; width: 500px ; font-size: 10px; border:1"> 0: user:username allow list,addfile,search,add_subdirectory,deletechild,readattr,writeattr,readextattr,writeextattr,readsecurity</pre>
In this case, rule "0:" can be ammended to include the "inherit" options using:<pre style="overflow:auto; padding: 5px; width: 500px ; font-size: 10px; border:1">chmod =a# 0 "username allow list,addfile,search,add_subdirectory,delete_child,readattr,writeattr,readextattr,writeex tattr,readsecurity,file_inherit,directoryinherit" /path/to/folder</pre>The "username" and "/path/to/folder" are placeholders, of course.
While ACLs can allow for files to inherit the ACLs from the parent, the catch is that the items have to be created new within the folder with the ACL. An existing file or folder moved into the shared folder won't inherit ACLs, whereas an existing folder copied directly into the shared folder will.

Similar Messages

  • Deny any user to login to any work station

    Dear Support,
    presently I see any user who is 'domain user' member can log in to any system in Domain to any user's PC. I am looking for best possible approach/practice to deny the log in attempt of any user to any work station in company.
    I found a way while doing google search on internet which tells me in order to have above it is required to do below settings in 
    - gpedit.msc > local computer configuration > Windows Settings > Security Settings > Local Policies > deny log on locally
    and this to be done in every system , is this correct ?
    please advise

    Hi,   
    In AD, if you want that a user can only log on to specific computers, we can follow the steps below to do this:
    In ADUC, select the
    properties of the user.
    Click
    Account tab, and click Log On To… bottom.
    Under
    this user can log on to option, select the following computers.
    Add computer name to the list.
    Best Regards,
    Erin

  • How can I set the default home page in Firefox 4 for all users that login to a PC on a Win 7 PC?

    I work at a community college in upstate NY.
    We use Firefox as the default browser at our institution and we have always set the default homepage to be our homepage for all users that login to the PC. We had a procedure to to that that worked with Windows XP and FF 3 or earlier
    We would do the following:
    1. go to: c:\Documents and Settings\Administrator\Application Data\Mozilla\FireFox\Profiles\<profile_name>\prefs.js
    2. Add the line: user_pref (“browser.startup.homepage”,”http://www.genesee.edu”);
    3. Copy the Folder
    C:\Documents & Settings\Administrator\Application Data\Mozilla
    To
    C:\Documents & Settings\Default User\Application Data\Mozilla
    4. Restart the computer
    We're going to Win 7 and Firefox 4 and things seem to be different in terms of files and file structure. Does anyone know how to accomplish this?
    Thanks in advance.

    Making customisation from the default profile is generally considered poor practice and quite often doesn't work out as planned. (If you're interested in some more information on this, [http://mockbox.net/windows-7/227-customise-windows-7-default-profile.html see here] see here)
    This article should help you with developing and deploying your customised Firefox 4 installation (without touching the Windows 7 default user profile):
    http://mockbox.net/configmgr-sccm/174-install-and-configure-firefox-silently.html

  • Parallel How many times user can login to the SAP system through ITS

    Hello all
    We are using the ITS ---620 and following 46D R/3 system 
    R/3 system details:
    Kernal :
    kernel release :46D
    O/S :SunOS 5.8 Generic_108528-05 sun4us
    We would like to now, At a time How many times user can login to the SAP system through ITS
    Kindly letus know  if any one have idea about parameter which can restrict the end users to u201CNu201D times/ sessions.
    Transaction SITSPMON/SMICM are not working in R/3 system as it is 46D.
    We found that parameter u201Clogin/disable_multi_gui_loginu201D works with SAPgui logons.
    System logons using the Internet Transaction Server (ITS) or Remote Function Call (RFC) are not affected by this Parameter u201Clogin/disable_multi_gui_loginu201D
    I need similar parameter u201Clogin/disable_multi_gui_loginu201D for the ITS users.
    Thanks

    I have searched all docs and notes.
    Everytime the answer is PArameter for multi_gui_logonis not applicable for SAP Gui for HTML ( Browser )
    The functionality does not exist for SAP Gui for HTML.
    Regards,

  • I've just purchased a new 2014 15" MacBookPro to replace my much missed 17" MBP. I got the works: OS 10.9.4, 2.8GHz Intel i7, 16GB memory and a 1 TB SSD, but despite the expense, I still don't have a computer that works...  The problem is that every

    I've just purchased a new 2014 15" MacBookPro to replace my much missed 17" MBP. I got the works: OS 10.9.4, 2.8GHz Intel i7, 16GB memory and a 1 TB SSD, but despite the expense, I still don't have a computer that works...
    The problem is that every time I try to open any program from Office 2011, I immediately get the following window, for example for Word: "Microsoft Word has encountered a problem and needs to close. We are sorry for the inconvenience." This happens each and every time I try to open Word or other Office 2011 component.
    Thinking it might be a licensing issue, I purchased and downloaded a new copy of Office 2011 from Amazon and installed it on my new MBP. Same issue once again.
    I tried to remove all copies of Office 2011 from the MBP, but the instructions provided by Microsoft required about three page and seventeen steps and the page was somehow corrupted and would not print in its entirety, nor would it e-mail as anything other than a link to the corrupted page. Not trusting my memory, I decided not to try this without adult supervision.
    I used Disk Utility to repair Disk Permissions, as described on an existing thread regarding the same problem, but to no avail.
    I removed and later replaced the "Microsoft User Data" folder from the Documents folder, but that was no help.
    I have copied the short version of the "Microsoft Error Reporting log version: 2.0," below, for those of you with a deeper knowledge of the internal workings, or non-workings of things Mac when crossed with things MS.
    Error Signature:
    Exception: EXC_BAD_ACCESS
    Date/Time: 2014-08-28 03:31:31 +0000
    Application Name: Microsoft Word
    Application Bundle ID: com.microsoft.Word
    Application Signature: MSWD
    Application Version: 14.4.3.140616
    Crashed Module Name: CoreFoundation
    Crashed Module Version: 855.17
    Crashed Module Offset: 0x00018442
    Blame Module Name: MicrosoftOleo
    Blame Module Version: 14.4.3.140616
    Blame Module Offset: 0x000017f3
    Application LCID: 1033
    Extra app info: Reg=en Loc=0x0409
    Crashed thread: 0
    Surely others have encountered and solved this same problem, and I'm hoping they can help me do the same. I don't know if this is a known issue or simply a matter of my having bumbled naively through a process far more complex than I was led to believe.

    http://www.microsoft.com/mac/support
    http://answers.microsoft.com/en-us/mac/forum/macword?auth=1
    http://answers.microsoft.com/en-us/mac/forum/macoffice2011-macword/microsoft-wor d-for-mac-2011-will-not-open-error/ecc42616-6f49-40bb-b8f5-e21c711ea359

  • We are a creative design studio, we need to use apple mac pro server , so we can make more than a different user to use at the same time doing different activities, on different screens, is it possible?what is the max. no. of users that can work efficient

    we are a creative design studio, we need to use apple mac pro server , so we can make more than a different user to use at the same time doing different activities, on different screens, is it possible?what is the max. no. of users that can work efficient.
    Appreciate your support and if possible , how to do this?

    If you want to work with Mac OS X, you need one computer per simultaneous user.
    What you are describing, " Multiple simultaneous logins to a single computer" is not avialable on a regular Mac of any description, unless you decide to use Unix tools instead of Mac OS X.
    Server will happily store files for many, many users and provide them to multiple (up to hundreds) of computers at "near hard Drive" speeds over Gigabit Ethernet. It can make the File Sharing part easy.

  • Windows users doesn't work after migrating from old to new server!

    We have done a complete re-install on our XServe with OD. We have about 10 Windows users, and after the installation all their settings and mail are gone. All the "normal" files are there though.
    I'm not sure we have done it the right way though: We did a backup from the old server (a bootable copy with Super Duper), then we formatted and installed everything. We made new accounts (with different names if that's good to know) and copied the users home folders to the new location. The Mac clients seem to work good, but all the settings on the Windows clients are gone...
    Is there an easier way to this? We still have the workable copy from the old installation. There seems to be some kind of export/import way to do this, but I haven't got a clue how to do that...
    Please help!

    davidh,
    We didn't reintegrate smb.conf, but set the new server up just like the old one. We did however compare these files to see that the vital parts (netlogon, shares and so on, and of course basic settings) were correct.
    We also copied the user files and profiles and made them identical on the new server, except for placing them under the new usernames.
    Regarding the Local Settings folder, it doesn't exist on the old server, that's one of the weird things. We've checked the profile for a user on the client machine, and it is a roaming profile. That's why we're a bit puzzled as to why the login works and all files are there, but the user preferences and Outlook doesn't work.
    I know I've read somewhere that the Local Settings aren't replicated like the other files in a roaming profile, but I haven't finished checking up on that. I wouldn't expect anything else than that Windows takes care of Outlook e-mail for a roaming profile as well though; I mean, the user must be able to read his/her mail from any computer in the domain, what else would the purpose of a roaming profile be?
    Except for the weird thing about us not being able to find the user preferences or Outlook files for the client amongst the files on the server, I feel we're missing something; Apparently Windows isn't as straight forward as one would expect (not sure why I did expect anything, come to think of it).
    We're going to give it a new go next weekend. Except for doing further research we're thinking of copying /etc/smb.conf and the files in /var/samba and /var/db/samba to the new server, along with exporting and importing the old user accounts to the new server, and then see if everything works as expected.
    If so, we'll see if we can change the account names in a nice way, it's really desired to do so.
    If not, we really need to do some more research, but if I'm not mistaking, the Samba-related files I just mentioned are the ones that pretty much make up the Windows Services in OS X, isn't that so?
    Thanks!

  • Differences between Roles, Schemas, Users and Logins.

    I need differences between Roles, Schemas, Users and Logins. Can anyone help me. Thanks in advance

    Roles:
    I think of creating roles in the database to group users of like
    function.  Roles are granted certain permissions in the database.  You
    should become familiar with the fixed database roles since these will be
    utilized once you start creating users within the database.  Also, once
    you see the type of permissions that are granted to each role, is makes
    more sense.
    Schema: there can be several schemas in a database,
    which will house different types of objects such as tables, indexes,
    stored procedures, functions,  etc.  Users own schemas.  Looking into
    the AdventureWorks database illustrates this concept, with several
    schemas like HR, Production, etc.
    Login: Think about login as
    gaining access to the SQL Server instance.  If a user account is not
    granted any permissions within the instance, you basically just were
    able to unlock the door and enter the room, by creating a user you then
    grant access to the database objects or principals, and can begin to
    work with them. 
    Users:  Users own schemas, and as such will be
    able to manipulate the objects they own.  Some of the manunipulations
    are very permissive, such as creating tables, indexes, stored
    procedures, functions, etc.  These are developers and administrators.
    Users
    are created and granted permissions for application use, which will
    have select, update, insert, and delete and execute permissions  to a
    finite set of objects in the schema, for which the application will need
    to function properly.
    In a client server database, as an
    example, of the structure.  Roles were defined which provides the
    permissions to the database objects in the database, which only has one
    schema 'dbo'. One SQL server login was created with the same username,
    and dbo is the assigned default schema, and the roles assigned to that
    username. 
    In the application, each specific user is given there own
    "application" login which is mapped to the one defined sql server
    login.
    Ahsan Kabir Please remember to click Mark as Answer and Vote as Helpful on posts that help you. This can be beneficial to other community members reading the thread. http://www.aktechforum.blogspot.com/

  • Unable to login network user from login windom. SSH login ok.

    I have a MacOS 10.6 client and ldap network users server by MacOS 10.4 Server. Trying to login via the login window I get "Logging in..." which tries forever (or until I reboot).
    * SSH login works fine with network users.
    * Local users can login.
    * Network access is allowed by all users (Preferences->Login)
    * Removing ~/Library/ from the network user doesn't work.
    Logging in via SSH while the login screen is hanging I get:
    [mikael@melba ~]$ ps -Umikael
    PID TTY TIME CMD
    330 ?? 0:00.03 /sbin/launchd
    480 ?? 0:00.02 /System/Library/CoreServices/CCacheServer.app/Contents
    693 ?? 0:00.00 /usr/sbin/sshd -i
    694 ttys000 0:00.12 -bash
    730 ttys000 0:00.00 ps -Umikael
    Any ideas?

    I cannot create the mobile account (real username replaced here with '<username>'). This is true whether I run the command as root or as the user in question (via ssh):
    root# /System/Library/CoreServices/ManagedClient.app/Contents/Resources/createmobilea ccount -n <username>
    createmobileaccount built Jul 23 2009 22:14:42
    2009-10-05 15:54:41.906 createmobileaccount[41973:903] MCXCCacheMCXRecordAndGraph(): [localNode createRecordWithRecordType:(null) name:"<username>"] == 4100 (Unable to create record <username> in /Local/Default.)
    2009-10-05 15:54:41.908 createmobileaccount[41973:903] MCXCCreateMobileAccount(): Failed to create account. Error = 4100 (MCXCCacheMCXRecordAndGraph failed). Cleaning up mobile account record.
    2009-10-05 15:54:41.909 createmobileaccount[41973:903] MCXCDeleteAccount(): Trying to delete user id = 0
    * mobile account could not be created: 4100 (Unable to create record <username> in /Local/Default.)
    Directory services and DNS are set manually.
    Message was edited by: BerkeleyAstroBill

  • Obsolete and batch users can receive work items

    Dear Experts,
    Currently, we have found a problem that obsolete and batch users can receive work items by manual forwarding from someone. The roles and responsibilities of obsolete users were removed and users have been locked. For Batchuser, it's only created for some certain job with limited roles.
    Could you help advise if this's a behavior of workflow or it's from some authorization problem? We have concern for business impact since no one is really handling work items and important messages are out of sight.
    Thank you very much in advance.
    Regards, Kae

    Hello,
    This is standard behaviour. It is even possible to send work items to users who do not yet exist (e.g. someone who is due to join the company).
    The easiest way to workaround is to set up a substitution for any users that get locked and for background users. Personal substitutes can be maintained directly in table HRUS_D2, you could possibly write your own maintenance transaction for this if it is to be an ongoing issue.
    Hope that helps,
    Mike
    Message was edited by:
            Mike Pokraka

  • How to restrict a user to login twice

    hei evryone!
    Here's my prob... I need to restrict a user to login more than once meaning, if a certain user account is currently login , that account cannot be used concurrently using another window or machine... If another user attempts to login, using that same account an error message will be displayed saying "this user account is already logged in".. i tried to do this in javascript but the code that i've got only works for IE and its kinda hard to capture the event for closing window.. plus using onunload is not advisable with my situation since my webpage can be redirected to other codes meaning the cause of unloading the page could either be closing the browser or redirecting the window to another page such as window.location="anothercode.jsp";... I was wondering if there's a way to do this in jsp...
    Any suggestions, ideas, or sample codes would be deeply appreciated. Thanks in advance!
    btw, i need to generate a code that is cross browser.. What i really need to accomplish is to be able to determine when the browser is closed either by clicking the X button on the window, alt f4 or my own close button and not when the page is unloaded.
    Here's a sample code : This only works in IE =(
    ---------- default.jsp-------------------------
    <html>
    <head>
    <script language="Javascript">
         onunload=function(e) {      
         winX = navigator.appName=="Microsoft Internet Explorer" ? window.event.clientX : e.screenX;
         winY =navigator.appName=="Microsoft Internet Explorer" ? window.event.clientY :e.screenY;
    if (winX<0 && winY<0)
              // redirect to logout.jsp n do some stuff
    </script>
    </head>
    <body>
    Logout
    List
    View Schedules
    </body>
    </html>
    the default screen would be the code above: "default.jsp" wherein there are many ways that the page
    can be unloaded such as :
    - clicking the logout link
    - click the View Schedules
    - click the x button the left side of the window
    - alt f4
    - if the window is minimized , right click then select close option
    Now, what i needed to do is to determined when the browser is closed so i reset the login flag of the account and can be used later on.

    hei everyone!
    im tryin to resolve this prob by adding a session id field on the users table. Everytime a user logs in i will update the session id field so that if anyone attempts to use the same account i will redirect the later into the login page with a warning msg. I'll do this by comparing the session id that u got from the dbase and the session id from request.getSessionId() of the browser. However, my prolem now is how to cleanup my database.. i need the cleanup coz i have a user tracking screen wherein i cud show who's account are login n who's not. I have created an applet and embed it in all of jsp files so that i cud catch the event for closing window whether by using the x button of the window or a power intrerruption. However, i need to find a way where i cud determine whether the event was really a close window or just a redirection from another page. I mean , you could leave the page either by viewing another screen or by actually closing the window.. For instance, my main page has main menu which are (1) View Users and (2) View Schedule .By default, im in the "View Users" screen . These two menus have their corresponding jsp n both jsp files have an embeded applet. So if the user click the "View Schedules " screen or if the user chooses to click the logout button or window's x button to exit the browser, then the applet will call the stop method. This what i meant by how will i determine if the user really exits on my application or not.. Coz if the user clicks from one screen to another then, user actually does not leave my application the user only exit on my application if the user logs out or close the window..
    Please help me out on this matter... Thanks in advance!

  • Restricting the Oracle user from Login

    Hi,
    I want to restrict the users from login depending on two parameters usind Database logon trigger,
    i.e
    1. MODULE (like SQL*Plus...)
    2. USERNAME
    I can get USERNAME from
    select SYS_CONTEXT('USERENV','CURRENT_USER') from dual
    But, select SYS_CONTEXT('USERENV','MODULE') from dual says invalid parameter.
    Can anybody help me?
    Ronald.

    Both are working fine i saw
    SQL> select SYS_CONTEXT('USERENV','CURRENT_USER') from dual
    2 ;
    SYS_CONTEXT('USERENV','CURRENT_USER')
    APPS
    SQL> select SYS_CONTEXT('USERENV','MODULE') from dual ;
    SYS_CONTEXT('USERENV','MODULE')
    SQL*Plus

  • Avoid users to login into the database thru SQLPlus

    I'm trying to use the after logon trigger described below, to avoid users to login into the database thru SQLPlus, user can only connect from from pls help me

    If your only concern is preventing users from logging in via SQL*Plus, you could use the PRODUCT_USER_PROFILE table.
    However, and this is a big however, this will not prevent users from logging in using any other tool (SQL Developer, SQL Programmer, TOAD, etc) if they know the Oracle user name and password. You can create a login trigger that generates an exception if the program that the client reports is connecting isn't on a list of valid products, but this sort of thing is easily circumvented just by renaming the executable on the client machine.
    Fundamentally, if you have given a person an Oracle user name and an Oracle password, whatever privileges are available to the Oracle account are available to that individual. No matter what tool that person uses to connect to the database, they are going to have the same privileges. That's why you ideally want to restrict what users can do to the point that you don't care what tool they're using. Barring that, you can enable auditing and let the users know what they are and are not allowed to do by policy and use the audit logs to ensure compliance.
    Justin

  • HR Work Center Persons folder

    Hi,
      I would like to sychronize the PERSON's From 1 HR Work Center(A- HR) associated to a Work Center (A) to another HR Workcenter(B-HR) associated to Work Center (B).  I would like to do this because I maintain to differenent Work Centers different plants but the share the same PERSONS.
    I would like to be able to mass upload the contents of the original  HR work center Persons into the new HR work center.
    I have approx. 90 Work centers to convert and would likd to automate the process.  Does anyone know of a Bapi I could use to achieve the upload.
      Of course, after the initial upload we would not want the user to update the same info in both work centers so we would use the Bapi to update the contents of the new Persons follder in the HR work center(B-HR) with the changes occurring the original work centers Persons folder(A-HR) .
      Of course, if anyone has a simpler way of maintaining the synchronization I would love to hear it.
    Antonio

    Hi Fernando,
    For HR work center assignment, the icon in the assignment area is a yellow-colored folder.
    For org unit, on the other hand, it is the gray-colored rectangle.
    Moreover, if you select "change layout" button at the top of "assignment" area and add key to displayed columns, that key is A for work center and O for org unit.
    Is this what you're asking or are you looking for some other answer?
    Regards,
    Dilek

  • ZENworks user source login won't go away

    Not sure where the best place to put this is.
    ZCM 11.2.1
    Server 2008R2 - Embedded DB
    Win7 Clients - Not sure about XP, we're moving to Win7 only ASAP
    Active Directory
    When logging into a laptop and NOT connected to the domain LAN, it gets stuck on the Novell ZENworks user source login windows indefinitely. I can try logging into local machine and this happens every time.
    In my old environment, with Novell Client, I could click workstation only and get the ZENworks login and cancel.
    Not sure what to do to fix this or change the behavior.
    Suggestions? TIA!

    Originally Posted by farmeunitWPSD
    Sorry, gave up on getting help with this.
    After logging into AD, a "User Source Login" box appears in the upper left. There are no buttons or prompts at that point. Just the box. The box NEVER goes away. If we put the laptops to sleep instead of shutting down, then they can login normally. I found ONE thread about holding SHIFT down before hitting enter after entering login credentials. If they hold SHIFT until the ZENworks login box comes up, then they can cancel that and are logged in fine.
    Any chance they're using wireless adapter and have it set to auto-connect?
    We have the same thing, but only on Windows XP being reported. Seems it only happens if the person has added a wireless network (XP has slightly diff. options than Windows 7) AND have it set to auto-login/connect.

Maybe you are looking for