OD Groups and Perms not updating?

I have a file server (to be used by about 60 people) that connects to an OD master for account info.
When changing a users group on the OD Master (which affects which shares are available), the change doesn't seem to propagate to the file server right away and can take a random amount of time to make it through.
Shouldn't this type of thing be instant, or is it just how it works?
Is there a way to force an update or to speed the update up? Sometimes it doesn't happen at all until i share or unshare something, which doesn't always work either.
I suppose I could set up a replica on the file server itself, but the apple manuals usually allude to specializing services to max out performance.

I suppose I could set up a replica on the file server itself, but the apple manuals usually allude to specializing services to max out performance.
That is because Apple wants to sell hardware. Realistically, an Xserve can handle the load of 60 concurrent AFP connections (not 60 network home folders). Running both AFP and OD on a single box is not going to kill it. There are many deployments that have one Xserve and they run 10 or more services on one box. Not everyone can afford separation of services.
Additionally, if you have an OD Master, you probably should be running an OD Replica. Just for the safety net that it provides. For example, having you users, groups, passwords, and policy automatically replicating is a nice warm and fuzzy. Plus, if you have a problem with the OD Master, you environment can still function.
That being said, configuring as connected to directory system is generally a good solution to avoid the extra services of directory services. Normally, this is a live lookup and no local storage is needed. Where are you not seeing the updates? In Server Admin when configuring permissions? What if you use dscl to browse the parent domain? Do you see the new groups, users, etc?
If this were a replica, the duration of time in which a sync occurs can be set. But in a connected to role, the lookups should be dynamic and this instant.
Hope this helps

Similar Messages

  • Export and import Sharepoint group and permissions

    We have some custom sharepoint groups and permissions created.How can i just export and import
    these group and permissions into another server.
    I do not want to restore entire site collection.
    just the groups and permissions...

    hey,
    You can find some code from Powershell here:
    http://geekswithblogs.net/bjackett/archive/2009/04/24/the-power-of-powershell-and-sharepoint-enumerating-sharepoint-permissions-and.aspx
    Or
    http://get-spscripts.com/2010/07/adding-groups-with-permission-levels-to.html
    Founder of SharePoint CookBook:
    http://www.GokanOzcifci.be
    Microsoft Certified Technology Specialist: SharePoint 2010, Configuring
    Microsoft Certified Personal

  • Hi - my Mu was "buggy" and would not update - so i threw the APP in the trash - but now CC will not allow me to Re-Install because it thinks i already have the APP - any advice?

    hi - my Mu was "buggy" and would not update - so i threw the APP in the trash - but now CC will not allow me to Re-Install because it thinks i already have the APP - any advice?

    restore your app from the trash and then properly uninstall.
    if that fails, CC desktop lists applications as "Up to Date" when not installed

  • When connecting to an external projector, an old photo is displayed and does not update

    When connecting to an external projector, an old image is displayed and will not update.   I am working on a 2009 Mac Book Pro.

    This is the Mac Pro desktop forum. I requested your post be moved to the MacBook Pro laptop forum.

  • My iphone was stolen and my mother gave me her 3GS, however she never updated the soft ware. It is on 3.13 and will not update to IOS 5.  Help!

    My iphone was stolen and my mother gave me her 3GS, however she never updated the soft ware. It is on 3.13 and will not update to IOS 5.  Help!

    How about the issues with 3.1.3 on the 3GS?
    3.1.3 battery problem
    OS 3.1.3 battery issues
    3.1.3 upgrade - shortened battery life?
    Battery life cut after 3.1.3 update on iPhone 3G
    3.1.3 Firmware is a battery killer - how do I back out this upgrade?
    Some users have problems with any release. iOS 5 is no different, not better, not worse.

  • HT4796 i have successfully migrated the music but it just shows up in my files and has not updated my iTunes library which is still getting the music from iCloud and is not using the migrated files. Any ideas?

    I have successfully used windows migration software to move my music library from a PC to my MacBook Air.
    However the music files are just stored in my file system and have not updated my itunes files. Itunes is still getting the music down from icloud instead of using the music files.
    Any ideas?

    If you're using Windows Movie Maker and HP Photo to build slide shows, this is not an iPod touch issue (nor an iTunes issue), so I'd suggest you take up the problem on a web site that deals with Movie Maker or HP Photo issues. It's really not something we can help with in this forum.
    If you're building this slide show on your iPod, please post back and tell us what app(s) you're trying to use, and whether the iPod app on your iPod touch shows and plays your songs correctly. Knowing the specific model of iPod you have and the version of iOS it's running will probably also help.
    Regards.

  • [svn:fx-i11] 5489: i11 branch: Fix SDK-20148 Group bounds do not update after moving a child UIComponent

    Revision: 5489
    Author: [email protected]
    Date: 2009-03-23 10:04:25 -0700 (Mon, 23 Mar 2009)
    Log Message:
    i11 branch: Fix SDK-20148 Group bounds do not update after moving a child UIComponent
    Fix: add a method in GroupBase that's called whenever child x,y changes in UIComponent. GroupBase invalidates layout when autoLayout is true.
    QE Notes: None
    Doc Notes: None
    Bugs: SDK-20148
    Reviewer: Deepa
    tests: checkintests, mustella
    Ticket Links:
    http://bugs.adobe.com/jira/browse/SDK-20148
    http://bugs.adobe.com/jira/browse/SDK-20148
    Modified Paths:
    flex/sdk/branches/i11/frameworks/projects/flex4/src/mx/components/baseClasses/GroupBase.a s
    flex/sdk/branches/i11/frameworks/projects/framework/src/mx/core/UIComponent.as

    FYI - This regression has been filed here: http://bugs.adobe.com/jira/browse/SDK-31989

  • Installed iTunes on a 1TB drive designated H:. Bought a 3TB drive designated G:. Downloaded iTunes update. On "Run" command, it will not let me change the destination drive, so it registers an error, and will not update. Help

    Installed iTunes on a 1TB drive designated H:. Bought a 3TB drive designated G:. Downloaded iTunes update. On "Run" command, it will not let me change the destination drive, so it registers an error, and will not update. App freezes, windows says to upgrade it.

    I went to Edit>Preferences>Advanced, G: is showing as the destination drive.

  • My Adobe Reader Updater appears to be stuck and is NOT updating.  Any suggestions?

    My Adobe Reader Updater appears to be stuck and is NOT updating.  Any suggestions on how to fix?

    Download and run the Adobe Cleaner to completely remove Reader.
    Download the offline installer here: http://get.adobe.com/reader/enterprise/ and run it.

  • Hi, My iPad has iOS 5.1.1 and is not updating automatically. Yes I reconfigured as it came yesterday

    Hi, My iPad has iOS 5.1.1 and is not updating automatically. Yes I reconfigured as it came yesterday

    I thought about that, but where he states that "Yes I reconfigured as it came yesterday," I assumed that this was a new iPad 2 that he just received yesterday. The tagline shows iPad 2, FWIW.
    However, your assumption may be probably is correct.

  • When Firefox opens my MSN homepage is out of date and will not update

    When Firefox (v 4) opens my homepage is out of date and will not update to the current date even when reloaded

    I'd recommend you delete the URL to your homepage which is causing the problem via Tools | Options | General and then go to the MSN homepage again and click the button "Use Current Page".
    MSN may have changed the coding in the URL which is causing Firefox to load an outdated page with your current settings.

  • HT204266 The APP update request came for 4 apps.  I submitted update all, but the system is stuck and will not update. Further, I cannot use those apps.  How do I fix this?

    The APP update request came for 4 apps.  I submitted update all, but the system is stuck and will not update. Further, I cannot use those apps.  How do I fix this?

    Two other things to try -
    Power your iPad off for a minute and then back on again.
    Double tap the Home button, locate the updating apps (one by one) in the bottom task bar, press on it until the red minus sign comes up and click it. Repeat for the remaining apps. Try the updates again but do them one by one rather than Update All.

  • 10-local.rules not setting correct group and permissions

    I have a custom rule for one of my removable storage devices. The rule sets the correct symlink, but it doesn't honour the mode and group settings. Here's the rule.
    BUS=="scsi", SYSFS{vendor}=="IIT-22 ", KERNEL=="sd?1", MODE="0666", GROUP="datamode" SYMLINK="mymp3"
    The group exists in /etc/group and the users who need access to the device are appropriately listed.
    udev has always been mu Nemesis, and I'd love to get this sorted!
    ls -l /dev/mymp3
    lrwxrwxrwx 1 root root 4 2010-02-07 13:03 /dev/mymp3 -> sdb1
    [hierro@el-diablo]#
    ]ls -l /dev/sdb1
    brw-rw-rw- 1 root storage 8, 17 2010-02-07 13:03 /dev/sdb1
    [hierro@el-diablo]#
    Any advice?
    Cheers
    GregW

    Hey brebs
    brebs wrote:10 is too low a number for the filename. Use e.g. 91, because one of the standard rules files is overruling it (e.g. 50-blah.rules)..
    Thanks for the reply. I always thought that the lower numbered rules too precedent..... I should read the wiki more. I'll try this when I get home.
    Cheers
    GregW

  • Address Book and iCal not updating in iTunes

    After I make changes to my address book I try to sync the changes the old groups, information, and photos are not updating to iTunes and therefore nothing is changing on my devices.  I followed directions from this link http://support.apple.com/kb/ts2481 and now it's cleared all my contact and calendar data in iTunes and therefore cleared all my contacts and calendar data on my iPhone and iPad.  Anyone know how to get iTunes to recognize the current data in my apps?

    Answered by finding out elsewhere that the iSync tool has an option to refresh all old sync history.

  • Groups and permissions

    I'm preparing a script where some local groups need to be created then domain groups added to them. Also it'll create some folder structure and assing my local groups with the right permissions. I thought that rather than hardcodding all that it would be
    better to make it more general so if groups need to be changed or folder structure modified it can be easily done. Hence I decided to use it as a good opportunity to learn to work with functions to extend my beginner's PS skills.
    I started with creating text files with what will be needed later. So I have folders.txt, LocalG.txt and DomainG_A.txt DomainG_B.txt all put in variables
    $folders = Get-Content .\folders.txt
    $LocalG = Get-Content .\LocalG.txt
    $DomainG_A = Get-Content .\DomainG_A.txt
    $DomainG_B = Get-Content .\DomainG_B.txt
    #######  Functions   #################
    # Test if folders exist and if not create them
    Function TestFolders ($folders){
                  foreach($folder in $folders){
                           if((Test-Path $folder) -eq $False){
                                New-Item -Path $folder -ItemType Directory -Force
    # Remove all ACLs from existing folder structure in case it's incorrect
    Function RemoveACL ($folder) {
    $acl = Get-Acl $folder
    foreach($access in $acl.Access){
             $acl.SetAclAccessRuleProtection($True, $True)
             $acl.RemoveAccessRuleAll($access)
    Set-Acl $folder $acl
    # Create Local Groups
    Function AddLocalGroups ($Groups){
    foreach ($group in $Groups){
             $cn = [ADSI]("WinNT://$env:computername")
             $gp = $cn.Create("Group", "$group")
             $gp.setInfo()
    # Here I would like adding domain groups A and B to some of my local groups
    Function AddTo_A_Group ($AGroups){
    foreach($gp in $AGroups){
               $gr = $gp.Replace('\','/')  # as we will likely see domain\group format in the text file
                $objGroup = [ADSI]"WinNT://$gr"
                $objGroupA1 = [ADSI]("WinNT://Test Group 1 A")
                $objGroupA1.PSBase.Invoke('Add',$objGroup.PSBase.Path)
                $objGroupA2 = [ADSI]("WinNT://Test Group 2 A")
                $objGroupA2.PSBase.Invoke('Add',$objGroup.PSBase.Path)
    Function AddTo_B_Group ($BGroups){
    foreach($gp in $BGroups){
                  $gr = $gp.Replace('\','/')
                  $objGroup = [ADSI]"WinNT://$gr"
                  $objGroupB1 = [ADSI]("WinNT://Test group 1 B")
                  $objGroupB1.PSBase.Invoke('Add',$objGroup.PSBase.Path)
                  $objGroupB2 = [ADSI]("WinNT://Test group 2 B")
                  $objGroupB2.PSBase.Invoke('Add',$objGroup.PSBase.Path)
    }  # surely this can be done better
    # To add a group and assign e.g. read and execute permissions
    Function ModifyACL($folder,$group){
    $acl = Get-Acl $folder
    $rule = New-Object System.Security.AccessControl.FileSystemRule -ArgumentList @(
                   $group.Name,
                   "ReadAndExecute",
                   "ContainerInherit, ObjectInherit",
                   "None",
                   "Allow"
    $acl.AddAccessRule($rule)
    Set-ACL $folder $acl
    AddLocalGroups($LocalG)            # create local groups based on the contents of LocalG.txt
    AddTo_A_Group($DomainG_A)     # add A domain groups to Local groups with A in their name
    AddTo_B_Group($DomainG_B)     # add B domain groups to Local groups with B in their name
    foreach ($folder in $folders){
               TestFolders($folder)          # test if folders exists and create as needed
               RemoveACL($folder)          # remove all current permissions
               foreach($group in $LocalG){
                       if($group -match "A"){          # for all groups with A in their name
                                ModifyACL($folder, $group)      # add group and give it R&E permissions
    Running the above Local groups get created and this is as far as it gets :)
    When the script gets to AddTo_A_Group function it throws an exception calling Invoke with 2 arguments: Unknown name(0x80020006 (Disp_E_UNKNOWNNAME) on my $objGroupA.PSBase.Invoke('Add',$objGroup.PSBase.Path)
    Some help would be much appreciated.
    yaro

    Yeah, PSBase is a sort of great unknown for me. I suppose I use [ADSI] as most of similar code (including your neat one-liner :) ) uses it presumably not to need to have connection with any DC.
    After adding a couple of write-hosts here and there I'm seeing that although the group name $gr looks correct (here contoso.net/GroupA1) in the next line the $objGroup shows up as System.DirectoryServices.DirectoryEntry and same for $objGroupA1
    where I was expecting to see contoso.net/GroupA and contoso/Test Group A 1. $objGroup.Path doesn't show anything but $objGroup.PSBase.Path shows System.DirectoryServices.DirectoryEntry again...
    yaro

Maybe you are looking for