Network users can not read Applications or Library

Not sure exactly where to post this but I think the server section will have more expertise than the desktop section.
We have 10.5.4 clients authenticating against a 10.4 Open Directory master. Prior to upgrading the clients to 10.5.5 everything was working fine. After upgrading the clients network users could no longer read the Applications or Library folders. When logging in all the icons in the dock would be replaced with the generic application icon and when trying to launch one the system reports the application could not be opened because it may be damaged or incomplete.
Viewing the iMac hard drive in a Finder window the Applications and Library folders have the do not enter sign on them. Viewing Sharing & Permissions under the Get Info window as the local admin user shows Read & Write for system and admin and Read only for everyone. This looks correct.
An `ls -l` on the root directory in Terminal as a network user reports that Applications and Library do not exist (no such file or directory). When running `ls -l` as the local admin the two folders appear and have a + sign after their permission strings which indicates extended security attributes (an ACL). I cannot find a command line tool to display or manipulate ACLs (such as getfacl and setfacl in Solaris) other than fsaclctl which enables and disables ACLs for an entire filesystem.
I disabled ACLs for the root fileystem (sudo fsaclctl -p / -d) and then network users could read the Applications and Library folders without problem. So there must be something in the ACL for those two folders that is restricting network users.
One other thing I noticed was that I tried to add a network user to Sharing & Permissions under the Get Info window, I could search for network users in the pop-up window but they would not get added to the list when I clicked select. So perhaps the problem is not with the ACL on Applications and Library but with 10.5.5 somehow not recognizing network users.
Installing Security Update 2008-007 does not resolve the issue. In fact it re-eanbles ACLs and they have to be disabled again in order for network users to work properly.

I eventually managed to fix it again - don't know exactly what broke it and what resulted in a fix.
Check what groups your network users are in, in a terminal enter the command:
groups <username>
My machine was only reporting the primary group of the user - none of the secondary groups were listed. This machine has a Open Directory custom mapping to force local home folders (a special case, we generally use NFS homes), and when I removed and re-added this mapping (rebooting in between changes) the groups command began to work correctly again and access to these folders was restored.
I was able to confirm that the ACL was the problem, removing it allowed the network users to gain access, restoring it broke it again.
BTW, the error messages you got when you ran the ACL removal chmod command are nothing to worry about, these are just device special files (representing hardware devices in the filesystem), I doubt that ACLs can be setup for these.

Similar Messages

  • I can not read my library

    When I try to open Iphoto, I can not read my my library.
    What must I do?

    Make a temporary, backup copy (if you don't already have a backup copy) of the library and apply the two fixes below in order as needed:
    Fix #1
    Launch iPhoto with the Command+Option keys held down and rebuild the library.
    Select the options identified in the screenshot. 
    Fix #2
    Using iPhoto Library Manager  to Rebuild Your iPhoto Library
    Download iPhoto Library Manager and launch.
    Click on the Add Library button, navigate to your Home/Pictures folder and select your iPhoto Library folder.
    Now that the library is listed in the left hand pane of iPLM, click on your library and go to the File ➙ Rebuild Library menu option
    In the next  window name the new library and select the location you want it to be placed.
    Click on the Create button.
    Note: This creates a new library based on the LIbraryData.xml file in the library and will recover Events, Albums, keywords, titles and comments but not books, calendars or slideshows. The original library will be left untouched for further attempts at fixing the problem or in case the rebuilt library is not satisfactory.
    OT

  • How do I find the bookmarks file when I can not load the application? I.e., I can not get to the library.

    My laptop died. The hard drive is in a case and accessible. It is connected to a 10 year old Pentium. How can I retrieve the bookmarks file from the Laptops drive when I can not load Firefox from that drive? I.e., I can not get to the library on the Laptop drive. I do have full access to it.

    You can locate main bookmarks file, '''places.sqlite''', for restoration in another Firefox install, in your profile directory.
    Since you profile is on another hard drive, the normal shortcuts to find it won't work.
    On Windows XP, you can find the profile here:
    ''C:''\Documents and Settings\''Windows login/user name''\Application Data\Mozilla\Firefox\Profiles\''xxxxxxxx.default''
    Where:
    * C:\ is replaced by the drive letter you mounted the laptop drive on.
    * Windows login/username is replaced with your windows user name you used on that hard drive.
    * xxxxxxxx.default is replaced with 8 random characters followed by .default, and should be the only folder in Profiles.
    Once you've found the old profile, you can copy files over to a new profile. See https://support.mozilla.com/en-US/kb/Profiles#How_to_find_your_profile and [[Recovering important data from an old profile]] for other files you may want to restore.

  • HT1766 Recently updated my iPhone 4s to the iOS 6. Now I can not install application updates, my music library has vanished, iTunes Match (in Settings) keeps setting itself to "Off".

    I recently updated my iPhone 4s to the iOS 6. Now I can not install application updates, my music library has vanished, iTunes Match (in Settings) keeps setting itself to "Off". I have also logged off of iTunes in Settings, and it will not let me log back in. Just a few moments ago when I again tried to log into iTunes, it asked me for my Password, then replyed that I had no Match account; but I do. Is Restore the best option?
    Any suggestions

    I couldn't find the edit button on my original post so I am posting an update here.
    I have gone through more apps and have had good luck on all but one more.  And it's not that the app doesn't work, I am talking about the Yahoo Weather app, It works fine, but when you swipe between cities the screen lags a bit and it sometimes doesn't move between pages the way it should.  On iOS 7.1.2 it was smooth as butter but on iOS 8.0, not so much.  I will post a note in the app store to let them know.  I really like the Yahoo app better than the new stock app.
    I have been going through my games and they all work fine. Angry Birds (Original and Stella), Canabalt, Minecraft, Bejeweled 2, Silly Walks, PopWords, Doodle Jump, Deep Green all seem to work just fine. 
    Starbucks app works as it should. 
    I will stop back again next week after I have had the weekend to play with it in detail and post my thoughts again.

  • I am not able to Sync. My iPOD classic 80Gb. It tells that as iTunes can not read the contents-restore to factory settings- after restoring – it tells that it can not be restore bcause there are files that are used by other application. I am having Widows

    I am not able to Sync. My iPOD classic 80Gb. It tells that as iTunes can not read the contents-restore to factory settings- after restoring – it tells that it can not be restored bcause there are files that are used by other application. My iPOD appears in My Computer in drive H as a mass storage generick volume

    Try disabilng the Enable Disk Use option from under the iPod's Summary tab, applying the changes, and seeing if that helps.
    Otherwise, temporarily disabling any antivirus, security, firewall, or file indexing software that may be running on your system and then try restoring your iPod again.
    B-rock

  • Help required please. "Itunes can not read the contents of my iphone"

    Greetings all,
    I know this question has been asked before and I apologize for asking again but all the solutions provided don't seam to work for me, can anyone help me please.
    I am receving the message: "Itunes can not read the contents of the iPhone. Go to the summary tab In iPhone Preferences and click restore torestore this Iphone to factory settings".
    Now a little about my iphone, Itunes and my laptop and what steps i havealready tried.
    I have an iPhone 4 running software 5.0
    My itunes version is 10.5.0.142
    I know these are not the most up to date versions but I have had this issue for almost 3 months now and updating the software back then was the first step I tried. I don’t believe updating to the latest will fix this issue as updating the last two times did nothing.
    Every so often after starting Itunes, The program will stop responding and will require the three finger death kill (CTRL, ALT, DELETE) to open task manager to end the task of Itunes. Once it shuts down, I restart the iTunes and it runs smoothly, apart from not reading my iPhone.
    When I run a diagnostic in itunes under the help tab, I get these fail messages:
    Network Connectivity test: Secure link to Itunes store fail
    Device connectivity test: Under support services: Itunes helper is not running. And under ports: No iPod, iPhone or iPad found.
    Device Sync test: No iPod touch, iPhone or iPad found.
    *See below for full diagnostic report*
    I have restored back to factory settings twice.
    I have shut down and restarted both my iPhone and laptop.
    I am running Windows 7 32-bit on my laptop.
    I am using ZoneAlarm as my fire wall, and have been disabling it when syncing my iPhone to prevent other error messages.
    The iPhone is plugged into a genuine Iphone USB cable and is plugged into a USB port not a USB hub on my laptop, I have tried plugging it into all 4 USB ports and this issue still persist. The Cable is less then 5 months old, is not frayed or damaged in any way, have also borrowed 2 other cables from friends and still the same issue.
    The iPhone does not even come up in windows explorer as a digital camera.
    The iPhone is NOT jailbroken
    I do not live close to a so called genius bar, however I have made the journey to them on 3 separate occasions last year when I first received my iPhone for a different issue, the so called genius's could not fix the problem so they just gave me a new (refurbished) iPhone, which did not extend my warranty. I will not be taking the iPhone back to them as I believe they can not resolve many issues, this is why I am reaching out to the power of the people in the wider apple community.
    I have read in other forums about ifunbox and other programs for jail broken iPhones to isolate folders “iTunesDB” and "iTunesCDB" and delete them. If this is the issue is there a way to access these files through windows explorer as my iphone is not jailbroken.
    I hope I have provided enough information and someone can help me fix this issue. If I have left anything out, please let me know. I thank everyone in advance for your patience and support.
    Thanks
    Hoggie27
    FULL DIAGNOSITC REPORT
    Microsoft Windows 7 Home Premium Edition Service Pack 1 (Build 7601)
    Hewlett-Packard HP Pavilion dv6 Notebook PC
    iTunes 10.5.0.142
    QuickTime not available
    FairPlay 1.13.35
    Apple Application Support 2.1.5
    iPod Updater Library 10.0d2
    CD Driver 2.2.0.1
    CD Driver DLL 2.1.1.1
    Apple Mobile Device 4.0.0.96
    Apple Mobile Device Driver 1.57.0.0
    Bonjour 3.0.0.10 (333.10)
    Gracenote SDK 1.9.3.494
    Gracenote MusicID 1.9.3.106
    Gracenote Submit 1.9.3.136
    Gracenote DSP 1.9.3.44
    iTunes Serial Number 001BAD14XXXXEA78
    Current user is an administrator.
    The current local date and time is 2011-11-16 10:04:53.
    iTunes is not running in safe mode.
    WebKit accelerated compositing is enabled.
    HDCP is supported.
    Core Media is supported.
    Video Display Information
    NVIDIA, NVIDIA GeForce GT 230M 
    **** External Plug-ins Information ****
    No external plug-ins installed.
    The drive H: Vodafone  USB SCSI CD-ROM Rev  USB is a USB 1 device.
    **** Network Connectivity Tests ****
    Network Adapter Information
    Adapter Name:    {97524DB0-B9DC-41DB-8AFA-0CE6938F7C95}
    Description:    PC
    IP Address:    (HAS BEEN REMOVED FOR PERSONAL REASONS)
    Subnet Mask:    255.255.255.255
    Default Gateway:    0.0.0.0
    DHCP Enabled:    No
    DHCP Server:   
    Lease Obtained:    Thu Jan 01 11:00:00 1970
    Lease Expires:    Thu Jan 01 11:00:00 1970
    DNS Servers:    10.143.147.147
            10.143.147.148
    Adapter Name:    {BFF0456E-DE42-4FEF-B1FA-1EA1C5EDEE42}
    Description:    Vodafone Mobile Broadband Network Adapter (ZTE)
    IP Address:    0.0.0.0
    Subnet Mask:    0.0.0.0
    Default Gateway:    0.0.0.0
    DHCP Enabled:    No
    DHCP Server:   
    Lease Obtained:    Thu Jan 01 11:00:00 1970
    Lease Expires:    Thu Jan 01 11:00:00 1970
    DNS Servers:   
    Adapter Name:    {D5511FFD-0CA8-4F62-B3CA-E90384FFCD03}
    Description:    Broadcom 43225 802.11b/g/n
    IP Address:    0.0.0.0
    Subnet Mask:    0.0.0.0
    Default Gateway:    0.0.0.0
    DHCP Enabled:    Yes
    DHCP Server:   
    Lease Obtained:    Thu Jan 01 11:00:00 1970
    Lease Expires:    Thu Jan 01 11:00:00 1970
    DNS Servers:   
    Active Connection:    PC
    Connected:    Yes
    Online:        Yes
    Using Modem:    Yes
    Using LAN:    No
    Using Proxy:    No
    SSL 3.0 Support:    Enabled
    TLS 1.0 Support:    Enabled
    Firewall Information
    Windows Firewall is on.
    iTunes is NOT enabled in Windows Firewall.
    ZoneAlarm Firewall is installed.
    Connection attempt to Apple web site was successful.
    Connection attempt to browsing iTunes Store was successful.
    Connection attempt to purchasing from iTunes Store was successful.
    Connection attempt to iPhone activation server was successful.
    Connection attempt to firmware update server was unsuccessful.
    The network connection timed out.
    Connection attempt to Gracenote server was successful.
    Last successful iTunes Store access was 2011-11-16 09:59:57.
    **** CD/DVD Drive Tests ****
    LowerFilters: Afc (1.0.0.2),
    UpperFilters: GEARAspiWDM (2.2.0.1),
    F: hp CDDVDW TS-L633N, Rev 0300
    Drive is empty.
    **** Device Connectivity Tests ****
    iPodService 10.5.0.142 is currently running.
    iTunesHelper is currently not running.
    Apple Mobile Device service 3.3.0.0 is currently running.
    Universal Serial Bus Controllers:
    Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller - 3B34.  Device is working properly.
    Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller - 3B3C.  Device is working properly.
    FireWire (IEEE 1394) Host Controllers:
    1394 OHCI Compliant Host Controller.  Device is working properly.
    Most Recent Devices Not Currently Connected:
    iPhone 4 (GSM) running firmware version 5.0
    Serial Number:    85107XQLA4S
    **** Device Sync Tests ****
    No iPod, iPhone, or iPad found.
    < Edited By Host >

    Hi AM_Kidd.
    Thanks for your reply.
    I have done a complete uninstall and re install of iTunes and all related apple programs from my laptop through control panel, add remove programs and also by going through program files and deleting all tracers of any left over folders remove programs may have missed.
    My apologies for forgetting to add this in my original post.
    Thanks again

  • A particular network user can't login to a mac in a classrom but other network users can. Then the network user can login to other identical macs in same classroom. Anyone seen this before?

    A particular network user can't login to a mac in a classrom but other network users can. Then the network user can login to other identical macs in same classroom. Anyone seen this before? It has happen twice. Two different teachers in two different classrooms entering the correct user name and passwords and computer won't allow them to login. Then they try in different computers in same classroom and have no problem login.

    Yes. I can login with a test user. And any other network user can login as well to this particular mac. Actually the mac has bootcamp and boots into either mac or windows. The same user entering the same login username and password can login into the windows side, but not the mac side.
    I had this same issue last semester in another classroom, another mac and a different teacher. This summer I reformatted and imaged that mac and I asked that teacher to login today to that reimagened mac and she had no problem today doing so.

  • 9.4.1 update: can not open an other library from an another computer with same update !!

    new iphoto 9.4.1 update: can not open an other library from my second computer with same update !
    this always worked properly on iphoto before ! reorganize my photo library from my other computer will break my neck !
    the first  library from my first computer works ! thanks for help !! regards

    So you have two identical copies of the iPhoto library on two different machines? YES
    and again How does the option launch and using the select library command not work ->
    it simply does not accept the copy of the imac library . if i want to choose the library, it is not accepted to be chosen.
    so i tried over network to choose the other way round as you suggested (labtop library on the imac)  and it worked , but it ruined (as i thought) my original library of the imac ! i could restore it from the back up , BUT this is simply strange, i can not find the restored libary of the imac on it´s original place  ! it must be hidden somewhere !

  • Since the update to iTunes 11.0.4 my AppleTV can not connect to my library

    Ever since the latest iTunes update my AppleTV gen 3 can not connect to the library on my laptop. It worked perfect until this update. I checked to see if there was an AppleTV update but it says there isn't one.
    I checked that all are on the same network and Home Sharing is on and everything is signed in to the same iTunes account. All the settings are the same as they were before the update.
    Any idea how to fix this?

    Kezj,
    Apple plans to do nothing.  I just spoke with Tech Support who told me that it has been my imagination that I have been using Home Sharing without having iTunes open on my computer.  Further, that these issues are occuring and complaints about them are from other websites, he had no idea that Apple had these threads running on their website - idiot!  I guess that the only way to Home Share is to have iTunes open on your computer at all times, even if you have everything in the cloud.  He could not explain to me how every other device was able to Home Share without iTunes being open. 
    Apple is aware that these complaints are all over their site, however, they have no intention to resolve the problem and if you want someone to toy with you like you are an idiot you can purchase an extension of your Apple Care and allow them to frustrate you more.

  • TS1192 'Could not read the iPhoto Library. The library at [file path] has a corrupted AlbumData.xml file.'

    Got this msh from Piasa...any ideas?  'Could not read the iPhoto Library. The library at [file path] has a corrupted AlbumData.xml file.'

    Contact Adobe support - that is not an iPhoto message - in general Piasa has no ability to access the iPhoto library - there have been hacks but often they do not worka nd can cause problems
    You need to user either Picasa or iPHoto - using both on the same photos is problematic
    LN

  • "mount: only root can mount" or "Unprivileged user can not mount NTFS"

    I'm trying to set up an NTFS partition to use as a common data partition between Arch and Windows. I have it added to fstab so that any user in the ntfsuser group can have access to it, but if it gets unmounted accidentally from the "eject" symbol in the nautilus gui, you have to sudo to mount it back up. Is there a way for it to be remounted automatically when you click on the partition again in Nautilus? I've searched all through the forums and looked through several articles on the wiki but haven't been able to come up with anything. The error I get says
    mount: only root can mount /dev/sda4 on /home/adam/UserData
    I've tried adding the users option to fstab, but that only manages to change the error to
    Unprivileged user can not mount NTFS block devices using the external FUSE
    library. Either mount the volume as root, or rebuild NTFS-3G with integrated
    FUSE support and make it setuid root. Please see more information at
    http://ntfs-3g.org/support.html#unprivileged
    I've tried the suggestions at the link in the error, as well as tried the solutions given in [solved] Gnome : mounting NTFS partition as user and a few other posts, but still nothing. If possible, I'd prefer to stay away from the users option in fstab, since it adds a redundant link to the sidebar in nautilus with a different name.

    @Mr.Elendig: It is mounted through fstab normally, but in nautilus there's an eject icon on the sidebar next to the name of the drive which I've accidentally clicked on a couple times if I'm just trying to open the drive real quick. Once its been unmounted like that it won't let me remount unless I use sudo. I'm just looking for something to make it a little more convenient than having to pop open a cli and type in a password.
    I'll try the suid root when I get home tonight, otherwise I'll look into autofs.

  • User can not print

    One user can not print from Photoshop CC. I have test other users from the same computer and they can print.
    I use Windows 7 Ultimate and SBS 2011.
    Is there a way to clear all Photoshop CC from a user profile? it must be the first try.
    Does someone know other user related problem with printing in Photoshop?

    Thanks.
    After lots of work, I found the problem. A corrupt local user profile.
    After logon on another computer and everything work, I try to identify the cause on the user profile.
    After I remove the local profile, I using a network so it creates minor problems, everything works.
    The thing which make me not think about this was that all other program, even Adobe, could print.

  • Just upgrade to Os Maverick, IPhoto app is no longer available, now I can not open my iPhoto Library. Any solutions suggestions?

    Just up graded my iMac to OS X Maverick after saving all file on external drive.
    HELP: Can not open my iPHOTO Library file because previous iPhoto application
                 is no longer available.
                What to do? If I need new application, which is the best ?

    Have you upgraded iPhoto to the current version (9.5.1)?
    Have you failed to allow your previous iPhoto library to be upgraded?
    Have you tried holding the "option" key while opening iPhoto to point to your iPhoto library?

  • Most users can not use TEST PANELS or run EXE built vi's?

    On any fresh install of NI-DAQ, the System Administrator and the first user logged in afterwards can use the Test Panels... button in the "Measurement & Automation Explorer" as well as run the Standalone programs made by Application Builder (LabView 7.1)...all other users can not use the Test Panels... or run the Built-vi's that shows up with plenty of error code 21, "an external subroutine required for execution could not be found", and it seems to be vi's that are called by the vi's we use, like one step away. I have set the permissions to all the related files to FULL as well as hacked the registry's HKeyLocalMachine->Software->NI... as well as the CurrentControlSet->...->DAQCARD... all to full control.
    Since the Administrator and the frist user can run the programs it is definitely not a case of missing software, but just permission rights. Please help to get the other users productive as well!

    Hi, they have not got the application builder license here...

  • 10.6.8 Server. New Users can not authenticate

    We have two Xserves (one OD Master, one replica) running OS X 10.6.8 Server and about 100 client macs all running 10.6.8.
    We have a problem when adding new users in WorkGroup Manager. Users seem to be added correctly (no errors), and all info matches existing/previous users in WGM (including Kerberos and apple password entries). New users can not log into their Macs, nor authenticate to mount any volumes that also authenticate through our Master OD server. What's odd is that we can edit passwords, etc in existing/previous users and they are updated on the client end. We have also verified logs and compared new users authentication logs to existing and the logs say that the users authenticate successfully.
    We are at a loss as what to do next. Any ideas?

    We have two Xserves (one OD Master, one replica) running OS X 10.6.8 Server and about 100 client macs all running 10.6.8.
    We have a problem when adding new users in WorkGroup Manager. Users seem to be added correctly (no errors), and all info matches existing/previous users in WGM (including Kerberos and apple password entries). New users can not log into their Macs, nor authenticate to mount any volumes that also authenticate through our Master OD server. What's odd is that we can edit passwords, etc in existing/previous users and they are updated on the client end. We have also verified logs and compared new users authentication logs to existing and the logs say that the users authenticate successfully.
    We are at a loss as what to do next. Any ideas?

Maybe you are looking for

  • Memory leak in JCO when calling an ABAP-function that returns larg tables

    Hello everybody, I think discovered a memory leak in JCO when the calling functionions that have exporting tables with large datasets. For example the ABAP-function RFC_READ_TABLE, which in this example I use to retrieve data from a table called "RSZ

  • QM for Pipe line Material

    Hi Experts Scenario: We have water as Pipe line material. We have activated 89 inspection type & user is creating manual Inspection lot for the same. Since this is a Pipe line material, there will not be any PO, GR so no inspection lot at GR. We do t

  • Need help with these error.

    Hi, While trying to boot the app server i encounter these error. I notice it when i view the TUXLOG file: 114559.ehr.nc.com.my!PSADMIN.5476: Begin attempt on domain enchrms9 114601.ehr.nc.com.my!tmadmin.7308.3086382784.-2: TMADMIN_CAT:1330: INFO: Com

  • How long does it take to move files to a new MacBook Air?

    I am using Migration Assistant to move files from my older MacBook Air with 120 gb of data on it to my new one that has a 500 gb hard drive. The Assistant has been working for over 4 HOURS and still just says that it is "preparing" to move files.  Th

  • Pic Only Shows Up As Wallpaper! How Do I Get It Back?

    I have a photo in my phone that only appears as the wallpaper when my phone is "asleep." It has never uploaded into iPhoto, and it does not appear in the iPhone's Camera Roll. How do I get it back? Thanks in advance.