Permissions for Linux user accessing Leopard share

We have a very simple networking setup at our video post production facility. Basically, files are shared everywhere and to everyone. No open directory or DNS serving. Just AFP and SMB.
Our Linux based Smoke/Flame/Lustre system needs access to the files severed/shared by an Xserve with a big attached RAID. It has no problem connecting or seeing the files. However, it typically is denied write permissions. When the Smoke operator creates a folder on the share he can't access the folder until I grant the Others/Everyone group read and write perms. The Linux user logs in with the same user account that everyone else uses.
Some time ago, the always smashing Gerrit DeWitt gave me some terminal commands to set ACLs for users/groups of this shared RAID. They work beautifully and I have had no permissions issues since applying them. Except for this Linux system.
Would it be good practice to use this command to set the Everyone group permissions for this share?
sudo chmod -R +ai "group:everyone allow readattr,readextattr,readsecurity,\
list,search,read,execute,writeattr,writeextattr,delete,\
append,write,deletechild,add_file,addsubdirectory,\
fileinherit,directoryinherit" "/Volumes/RAIDH/Smoke_InfernoStorage"
Also, is there some configuration change I could make to the Linux system to make it a little more Mac compatible in this area?
Thanks

It's worth checking into - let us know what you find. What you describe certainly sounds like a problem with permission propagation settings for SMB / Samba since the AFP side works fine.
I've seen other posts about problems that crop up because of differences in the versions of Samba employed between systems, so that's a possibility as well. And I'd have no suggestions for you in that regard other than some searching of the web for clues as to how to work with that issue.
-Doug

Similar Messages

  • How to setup for multiple users accessing same share?

    Hi!
    Recently picked up Mac Mini Server and have some configuration questions related to sharing files & information over the internet. Whenever possible, prefer to use the built-in features & tools, not 3rd party tools.
    My setup & needs are this:
    - Have folders & sub-folders with files to share.
    - Wish to give individuals access to the shared folders, each with their own account (and access logging).
    - Shared folder and files should be visible via web to authenticated users only (so no special client or setup is needed).
    Right now, have added a Website via Server.app that points to the folder with files to share, and that works somewhat, but doesn't support individual user accounts separately?
    Thought maybe to setup VPN but that seems like massive overkill for this (and is a pain in the butt for non-technical users to setup).
    Editing httpd.conf for user support is a possibility, but seems /etc/apache2/httpd.conf only applies to the default web server (on port 80) not the one i set up in Server.app?
    Can anyone recommend the best approach, given the above needs?

    I have a related question. i created 2 websites/domains then i went to users and created 2 seperate "network" users then i went to ftp and selected each website and added only user A to site A and user B to site B. what's weird is that when i try to ftp using either of the users it seems to land on the same site. i looked at shared security for the folders and it only shows user a on site a folder and user b on site b folders. am i doing somehitng wrong or is this how it works in mountain lion server? i just want to give the domain owner ftp access so they can manage their files and only thier files. i also had to turn on open directory so that it would not create a local user but a network user. do i need to turn that off and just deal with having a bunch of local users as ftp user? i want to host multiple websites on the server and NO users remote on to server besides ftp.
    edit 1: i only have 1 IP running on the server which i don't think it has any affect on this but thought i mention it :-)
    edit 2: i just noticed one more thing that may help. i used filezilla to remote in using both users, one at a time. it seems to allow both users in but then it shows same directories. i then created a file using the one that was not supposed to have acces and it never sows up. but if i remote desktop to server i can see the new file in the correct folder. so it may have something to d o with the directory listing.

  • How to check whether a file got read permissions for perticular user

    Problem: Let JRE is running with some x as effective user in LINUX then while checking file permission it is checking permission on that file for that x user.
    File f = new File(�file name�)
    if(f.exists())
         System.out.println(�exists�);
    Else
         System.out.println(�does not exists�);
    The above code prints exists only when x user have permissions on that file
    Requirement: I would like to check whether a file got read permissions for particular user i.e. whether y user got permissions on that file.
    Any help is appreciated

    In Linux a user has to have read permission on a file to even see that it exists. As a result, if a user (or a group to which they belong) doesn't have read access to the file File.exists() will return false. Windows which doesn't have as tightly controlled access to files will admit that a file exists whether it can be read or not.
    PS.
    This is proof that I should never answer a question off the top of my head when I haven't had my red bull yet. This is wrong. You will be able to see it if you have read and execute on the directory.
    thumps self in head
    Message was edited by:
    puckstopper31

  • Password security - set permissions for different users

    I am using Abobe Acrobat 9 Pro.
    In the HELP menu, there is a security section in the contents, In the overview, it states the following:
    "Each security method offers a different set of benefits. However, they all allow you to specify encryption algorithms, select the document components to encrypt, and set permissions for different users."
    I would like to know how you can set permissions for different users using Password Security.
    I am the only one in the company who has Acrobat 9 Pro and all others have Adobe Reader 8.
    I have created a PDF file in Acrobat 9, this file is accessible to anyone with Abobe Reader. I would like to set different permissions for different users. For example, i would like certain individuals to print the document and other individuals to not be allowed to print. Can this be acheived using Password Security?
    Many Thanks

    I have created a PDF file in Acrobat 9, this file is accessible to
    anyone with Abobe Reader. I would like to set different permissions for
    different users. For example, i would like certain individuals to print
    the document and other individuals to not be allowed to print. Can this
    be acheived using Password Security?
    No.

  • Files to download without any permissions for guest user.

    Hello, i have created a KM Navi Iview, with path to /documents/.../...
    When i go to
    http://portal/irj/portal/anonymous i see a list of files, but i can copy,delete and rename files (permissions for guest are: read), how can i solve this, if i need only download permissions for guest?

    Hello Artem,
    Please do not remove the Guest User from its groups.
    The Guest User is an integral part of the "Anonymous Users" group which ultmately falls under "Everyone" Group. How did you remove Guest User as only Config tool allows you to do that.
    What I suggest is make a Portal Group of Users and add all your regular users to it. Give Read/Write permission to this group. Then add only Read permissions for Anonymous Users Group.
    Hope this helped.

  • Widgets for Business User Access to SC Approval

    We learnt with SRM 7.0, widgets would have been one of the distincting features. Does anyone know what it takes to setup one ? Widgets Features.
    Widgets for Business user access (pre-packaged and custom)
    Process controlled SRM Business Workflow
    Harmonized, UI for seamless usability across ERP and SRM
    Robust mobile and desktop support
    Non-disruptive innovation via EhP
    Easy, low-cost customization with WebDynpro

    I did not try this, but maybe I've got an idea...
    You can catch the onload event of the BP form and the switch record event (First, Previous, Next & last record button in the data menu). The first (onload) do you need when someone enters the BP form by clicking elsewhere on a linked button. The other you need when someone is walking through the records on the BP form. (by accessing the form using the menu)
    Catching those two events, you can get the value of the BP Code field, and check if the current user is allowed to see it. If not, disable (if they are not allowed to edit) or hide (when not allowed to see) the items on the screen (that are a lot of items, I know) and display a nice message that they are not allowed to edit/view that BP.
    The ID's of the form and the buttons:
    - FormUID BP: 134
    - MenuUID First record: 1290
    - MenuUID Previous record: 1288
    - MenuUID Next record: 1289
    - MenuUID Last record: 1291
    Hope it helps...

  • SharePoint 2013 permissions for each user

    I am working on my own SharePoint 2013 test site and I need to grant permission to the test accounts. I want to make certain the 3 test accounts can not see the lists, files, and workflows that the other users created.
    Do I need to grant permission at the site level, user level, custom list level, for each workflow, and/or for each custom form? Do I invite each user and/or 'share' with each user? Can you tell me and/or point me to a source that will tell me what level
    of permission I need and how to grant this type of permission?

    Wendy,
    In sharepoint, you can grant permission at any level you want. That permission will carry forward by default until someone break them and configure unique permission.
    In ideal case, we recommend to use share security group to grant permission and not grant to individual user. Also try to restrict 2 default site group (Owner/member/viewer) as much possible, but in reality ppl break these rule often and eventually end up
    with maintenance overhead.
    I will recommenced you and everyone to go through this nice ppt which clears sharepoint permission idea in our mind.
    Here you go - SharePoint
    Permissions Worst Practices
    Please 'propose as answer' if it helped you, also 'vote helpful' if you like this reply.

  • Mac user locks files for Windows users on NFS shares

    Hi Everyone,
    We run a mostly Windows environment here at my school and have two AD servers which also do our file shares for AD users. Every user has a network drive mapped to L on Windows, and this is mounted on the dock of our Mac users (all Macs are bound to the AD for auth and the OD for management). We also have shared folders for different groups of people, such as admissions or art (where the issue is). Most of these divisions are only Windows, so file sharing isn't and issue - but this is not the case in our Art department.
    We have a shared folder (T on Windows) setup for users of the Art department with mostly Office docs in it. Windows users can write to the share just fine, just as the Mac users can. The issue comes up once a Mac user edits and saves the file (all to the share) - Windows users are now locked out of the file because the permissions are reset. What can we do to fix this issue? It's obnoxious having to go and reset the permissions after every edit from a Mac user.
    Thanks,
    -MRCUR

    We also have that same problem. We don't actually solved the issue but we what we do did is just unlock the files once and even they are edited or opened in windows or mac, it does not lock the file. We use windows pc and connect to the drives and just simply right clicking the file then properties a button will show in the properties window saying "unlock". After we did that, those files was never locked out again.

  • Unbootable after Permissions for "Everyone" = "No access"

    I may have done something bad. I happened to look at permissions for my main (internal) drive for my iMac, "Macintosh HD." It said that access for "Everyone" was "Read only." I thought to myself, "I don't want everyone able to read everything on my disk." I also vaguely remembered (possibly incorrectly) that I might have changed that myself in the past. So I thought I would try it set at "No access." The first bad symptom was that my laser printer stayed in a state of being paused, regardless of hitting the "Resume printer" button repeatedly. So I thought something was hung up only with printing, and I tried to reboot the computer. Unfortunately, it would not boot back up, getting hung up at the gray screen with Apple logo and “spinning Stonehenge”! It did boot up with the Mac OS X Install DVD, which saw “Macintosh HD,” so I used Disk Utility to repair the drive, which Disk Utility said was OK, and it repaired some corrections (nothing conspicuously about “Macintosh HD” as a drive). Rebooting to “Macintosh HD” still did not work! (For some reason, it would not boot into the recent version of Drive Genius DVD.) It booted into TechTool Pro 6.0.3’s DVD, which made some favorable changes to the volume structure, and it corrected some permissions. Afterward, the iMac still would not boot into “Macintosh HD.” My latest Time Machine backup is a little bit old (a week or two), and I do have newer backups of certain files on an external drive, so I could restore it via Time Machine if necessary. But I suppose I would rather undo what caused this inaccessibility, tentatively my change of the permissions because all of this happened immediately after that change, and have everything as it was yesterday. Any advice and lessons would be appreciated.

    Thanks for your quick reply. I'm not with my iMac now but will try it tonight. Regarding your solution A1: does Command-S work as Terminal, or is Terminal needed at all? Does it matter if the screen at which it is stalled is not blue (which might be the background before Users' accounts appear?)? It is a gray screen with Apple logo. I have also found the following post which gives a different solution:  https://discussions.apple.com/message/15469394#15469394 That user described the stall as similar to mine: "the gray screen of death with the perpetual wheel." That solution apparently requires use of Terminal. Can I access that via the Mac OS X Install DVD?

  • Wrong home directory permissions for new users

    Hi everyone.
    I reinstalled my laptop the other day and ran into a rather strange problem: after a system update new users had their permissions totally screwed. It took me 3-4 reinstalls to notice, as i was also playing with lvm2 &co. Anyway, on fresh installations from either 2008.06 or 2009.02, everything works fine. As soon as i update to the latest package versions (including 2.6.29 kernel) and create a new user, permissions on the new home directory are screwed up to the point where the user can't access it.
    Old directory permissions:
    drwx------ 33 jasn users 4,0K 17. Apr 13:21 jasn
    drwx------ 2 root root 16K 17. Apr 12:15 lost+found
    New directory permissions:
    drw-rw--w- 2 jasm users 4,0K 17. Apr 13:43 jasm
    drwx------ 33 jasn users 4,0K 17. Apr 13:21 jasn
    drwx------ 2 root root 16K 17. Apr 12:15 lost+found
    Logging in to "jasm" results in
    No directory, logging in with HOME=/
    [jasm@host /]$
    The whole mess can be fixed by changing the permissions on the home directory, but all that can't be on purpose, can it? I also don't know which package update (if it even was caused by one) causes this behaviour and if this only happens to me, so i didn't file a bug report.
    Has anyone already seen this? I solved it after 1.5 days of puzzled (and strangely unsuccessful) googling and reinstalling, so perhaps someone who runs into the same problem can use this to fix it.
    Last edited by JASN (2009-04-17 17:09:34)

    umask is not really the correct thing to do in this case, as this resets the permissions for every file the user creates. Afaik, the umask setting has to be installed on every machine via the launchd-user.conf file (to contain simply: umask 002) (or whatever is appropriate for your facility), as umask is a property of the process, not the connection.
    What might work better for your problem is make the homedirs world and group non-readable. That way the user creates files within their homedirs and anywhere below, but everyone else can't read them regardless of the files' permissions because the directory itself is unreadable.

  • Read/Write Permissions for all users and all objects in Users:Shared

    Hi:
    I am using an application called "iView" to manage my image files. When importing images from my camera through that application, it creates a folder with the current date. The root folder is "Users:Shared:Images", so that everyone using our Mac can access the files. However, the files' permissions are only read/write for the user who downloaded the files (typically me), but I want everyone to be able to edit and delete files. Of course I can change the permissions manually, but there has to be a better way. (In addition, changing the permissions manually afterwards causes Time Machine to backup the files with the modified permissions again).
    What do I have to do?
    Thanks in advance.
    Hinrich

    That is the way that permissions work. If you are the owner of a file and want others to be able to read and write it, then you have to give them the permission to do so. To automate this, you can attach a folder action to the shared folder, for example:
    <pre style="
    font-family: Monaco, 'Courier New', Courier, monospace;
    font-size: 10px;
    margin: 0px;
    padding: 5px;
    border: 1px solid #000000;
    width: 720px;
    color: #000000;
    background-color: #FFDDFF;
    overflow: auto;"
    title="this text can be pasted into the Script Editor">
    on adding folder items to ThisFolder after receiving AddedItems
    repeat with AnItem in AddedItems
    tell application "Finder" to set everyones privileges of AnItem to read write
    end repeat
    end adding folder items to
    </pre>

  • Required permissions for SCVMM 2012 R2 Library Share - SOFS on Clustered Storage Volume

    Setup / Notes:
    SCVMM 2012 R2
    SCVMM Library Server - SOFS Role on 2 Nodes of Clustered Storage Server 2012 R2
    Library Server and Nodes show up under Fabric->Infrastructure->Library Servers
    Server and Nodes show no errors or problems
    Shares have been added in SCVMM and able to refresh properly
    Problem:
    I cannot do any job which involves writing to these shares. Import Resource, Create VM Template, etc. Everything fails with Error (2910) VMM does not have appropriate permissions... Access Denied.
    Solutions Tried:
    I have setup FULL CONTROL Share and Security permissions for Administrators Domain and Local, SCVMM Service Account, SCVMM Run as Account, Everyone Account, SYSTEM, Hyper-V Computer Accounts basically everything in my domain. I still get access denied to
    the Library Server Shares.
    Other Notes:
    I do have shares configured for VM / shared storage for hosts. These are working great and appear to be configured completely by SCVMM.
    What are the required permissions? Are they manually setup or controlled by SCVMM? Why does it appear that nobody has had this problem before me on the interwebs? Am I an idiot?

    More Information:
    It would appear that Failover Cluster Manager doesn't immediately change the permissions related to a share. I have manually gone in and set the FULL CONTROL Share and Security permissions for the Everyone Account on the Cluster Volume and the share is now
    working. I do need to lock this down for security purposes so what account/accounts does it need?
    Scratch That:
    I was able to Import a Physical resource but the saving of a VM to the library does not work... 2904 or 2910.
    Anybody?

  • Effective permissions for LDAP user that is a member of multiple groups?

    We use AD and LDAP group maps to authenticate to UCS, and I'm trying to understand the effective permissions when a user is a member of multiple LDAP groups, each with different UCSM permissions.
    I expected that UCS would grant access based on the union of the effective permissions specified in UCS, but instead it appears to use the permissions of just one of the groups, and it's unclear whether the selection is random or deterministic. If this is expected behaviour, is there a way to affect the selection process?
    Cheers,
    Paul

    Hi,
    I tested the issue on SharePoint server 2013 without sp installed. It worked and I used global security group. I will test the issue on SharePoint 2013 sp1 later, and please provide more information to narrow down the issue.
    Please go to site settings > site permissions > check permission, type in domain\user1, and post the result here.
    If the user has been granted permission, please try logging on another machine to test if Windows credential casues the issue.
    Did the issue occur to one site collection? Please test on other sites or web applications?
    Please create new user to test the issue again.
    Regards,
    Rebecca Tu
    TechNet Community Support

  • Pure-ftpd - different permissions for virtual users?

    I seem not to be able to find out how I could declare different permissions for different virtual users. In /etc/pure-ftpd.conf exists one line to declare permissions using
    #umask file:folder
    umask 133:133
    umask matches the numbers to 'UserGroupOthers'.
    Now that virtual ftp users belong to a real existing unix user / group, I wonder who is Users, Group and Others?
    Users = virtual ftp user ?
    Group = virtual ftp group ?
    Others = anonymous visitors?
    How can I tune it, so one virtual user can add files - f.e. to be used by a scan station - while others shall only read, having anonymous disabled?
    This gives me a headache.

    Ok, let me think.  What did I do? 
    I had different users.  User X, Y and Z.
    Then, I had a shared directory above their home directories.
    While in the system, (not in pure-ftpd) I symlinked.
    (Note that doing something in user X's directory, like ln -s ../shared didn't work---I had to do ln -s /usr/home/ftpuser/shared).
    Then, I ~think I played with the permissions on shared and got what I wanted. 
    Then, after a few hours on this, they changed their minds about what they wanted, everyone was allowed to use shared, but different companies had to have their own directories, so I no longer have that config.
    For what it's worth, you can take a quick look at my page
    http://www.scottro.net/qnd/qnd-pureftpd.html
    but I don't think it covers that situation.
    HTH, though I doubt that it did.

  • PCD Business Objects Permissions for Authenticated users

    Hi All,
    I am working on SRM7.0 Business package installed on Portal NW7.01.
    I wanted to understand Which permissions should i provide to "Business Objects" PCD Folder for Authenticated users.
    Should it be Administrator "None" and End User "ON"
    Or Should it be Administrator "Read" and End User "ON"
    Regards,
    Ashish Shah

    Hi Sandeep,
    I was wondering what is the need of assigning permissions to "Everyone" Group and "Authenticated Users"
    2. Group: Everyone(built in group)
    Administrator:Read
    Enduser:checked
    3. Group:: Authenticated Users(built in group)
    Administrator:Read
    Enduser:checked.
    If i am not using Anonymous users , should i only assign this permission?
    Group:: Authenticated Users(built in group)
    Administrator:Read
    Enduser:checked.
    Regards,
    Ashish Shah

Maybe you are looking for