Setting up permissions on a central file server...

I am setting up a central file server in a small network enviornment where the users will share a drive and jobs on the drive. Problem I am having is if I set up seperate users and one group that they all belong to, when someone creates a job in there home directory and then copies it to the server, the rest of the users access it as read only. I need them to be able to read and write to each others folders. Any solution other than creating one user that they all share (since that kind of defeates the perpose).
Thanks in advance,
Larry

The solution to your problem depends on whether you want to use ACLs or not.
If you are managing a server, you should crack open the manuals- the answer to your question lies within those pages. To point you in the right direction.....
If ACLs are NOT enabled for the volume. When you click the Share Point in WorkGroup Manager, then click the Protocols tab, you will see a check box for "Inherit Permissions from Parent". This is what you want.
If this option is greyed, then you DO have ACLs enabled for the volume.
The explanations for this are not short and managing a server requires reading, research and frustration.
ACLs work more reliably than the Posix 'inherit' permissions option does.
That said....
A user of this forum put together an excellent guide to ACLs. Here's the link:
http://discussions.apple.com/thread.jspa?messageID=648307&#648307
Jeff

Similar Messages

  • How can I set-up my mac mini server to be a central file server for my windows boxes (they don't see the mac on the network), and how do I set-up a central iTunes server so that all my devices sync to the mac mini?

    I am looking for step by step instructions to configure my mac mini server to support the following:
    1. Central itunes server for all my devices (ipad, ipod, iphone, etc.)
    2. Central file server so that my windows devices can save and retrieve data from the central system (the mac does not show up in the network for the windows systems - all running windows XP or 7)
    Thanks,
    Keith

    You will need to enable file sharing in System Preferences
    as well as setting up sharing and permissions for the
    directories that you want shared.  You may also want to
    setup a non-administrative user or allow limited guest
    access.  The user would require entering a user name and
    password to make the connection, but would allow remotes
    to change files, if set up tat way.
    As for serving iTunes media, better to post in the iTunes forum.

  • Setting up a TC as a file server. PLEASE HELP

    I am desparately trying to set up my TC as a file server through a 2wire, ATT Uverse Gateway. Can anyone walk me through it? I need it to remotely access my medical records while at numerous Dr's that I see for my Cancer treatments. Any help would be gratefully accepted.

    You will not find this an easy setup to achieve.. the TC is not accessible remotely with BTMM unless it is the main router in the network.. and this is not possible when the Uverse is installed as the main router.
    The other method is to open AFP to outside access.. read the Tesserax methods here.
    AirPort Disk - Remote Access (3 Methods)
    The last method can be adjusted for using any brand router.. you do not need to port translate.. simply open port 548 to TC bridged behind the Uverse. It must be static IP so set that on the Uverse. And you will likely need to use ddns which is also built into the uverse.
    Good luck with the treatment.. I had a bone marrow transplant for Lymphoma 20years ago.. still alive.

  • Easiest, cheapest way to create a central file server

    Can anyone recommend the easiest and cheapest way to create a file server.
    I want to share files between four networked Macs.
    I don't want to have to use OSX Server as it seem like overkill - I only need to share some files.
    Back in OS9 days, I used to use a spare Mac with multiple users set up. But how do I do it in OSX.
    Can I just set up the four users onto a Mac and put all the files in the Shared folder? Are there any permissions issues in doing this?
    Is there a way to connect directly to the shared folder of one Mac from one of the others?
    Is there a way to connect automatically on login?

    sharepoints is your answer. It allows you to setup any folder or volume as a sharepoint. it allows you to create users and groups in the same way as the workgroup manger of osx server does.
    Can I just set up the four users onto a Mac and put all the files in the Shared folder? Are there any permissions issues in doing this?
    yes there are permissions involved.
    have read through a thread whereby I posted a brief explanation of the users and groups relationships in OSX.
    Topic: local network - passwords - permissions

  • MacPro as central file server with usb tape backup

    Good Day,
    Couple of questions. Here is what they want to do. Small office, graphics design, 5 people at the moment, currently they backup to cds/dvds which takes too much time and effort.
    What they want
    Have a central networked location to store there files / projects. Easy backups.
    So I was thinking of the following.
    MacPro with 2x TB Drives Mirrored to have redundancy on the machine, many not even need to do it. just a suggestion.
    Usb External Tape Drive - > backs up data daily
    Now the questions that I have for this setup
    1) Would just the 10.5 Leopard client work fine or would have to go to Leopard Server?
    2) Cant remember if still can do a software raid on the client side without needed the dedicated mac pro raid card.
    3) Any recommendations on external usb tape drives that would work with the mac. I can get the software without any problems. Thinking about EMC Retrospect 8.0 for mac

    I think you mixed - or I misled. There are some nice dual drive cases from FirmTek that are really nice, use drive sleds.
    http://eshop.macsales.com/item/Firmtek/SATA2SEN2E/
    (even if you don't use something like this for your project, they are best quiet solid enclosure. The 5-drive + Sonnet E4P combo for RAID storage)
    I used tape, but that was 20+ yrs ago dating back to the 70's.
    HP plus Windows Home Server has a great hardware and software combination.
    A picture - and some of the Amazon reviewers...
    HP EX485 MediaSmart Home Server
    http://www.amazon.com/HP-EX485-MediaSmart-Home-Server/dp/B001OI2ZG4/
    - designed more for streaming and sharing rich media as well as backup server.
    Retrospect... use to be a good name, not so sure now.
    I am pretty much opposed to USB storage myself.

  • Mounting Aperture library on file server

    It appears that Aperture has all the organizational functionality that my group has long needed, but we wondered if the library can be mounted on a centralized file server so that multiple users can simultaneously access it from their workstations.
    I read a thread entitled "One Computer, Two Users, Shared Library?" that discussed permissions, but I am interested to know if anyone has experience using Aperture by having the application on each client machine and the library on the server?
    Bill

    William,
    Thanks for the DAM software suggestions. The Extensis Portfolio Server 8 looks promising so far. However, check out the way James Pittman (on a later thread) is doing it just with Aperture by having their master photoss reside on an XRaid file server and referencing them to each user's Aperture library.
    Bill

  • Powermac G4 as media file server/storage?

    Hello everyone,
    Long time reader, first time poster.
    I currently run a 15" Pbook G4 1.67g with 2 GB of RAM and 100GB HD, hooked up to an 80GB and 250GB external FW drives. I've slowly been transferring all my DVDs and CDs to the drives, not to mention video footage and all the photos I've been taking. Right now I've got maybe 3 or 4 GB free between the 3 drives.
    I'm greedy. I want to keep going. I don't want to trim back. I have this dream of getting ALL of my music and movies onto HD storage, so I can digitally access any of my media at any time.
    I run iTunes off my Pbook to access my library (which is stored on the 250GB external), but it runs SOOO SLOOOWW. iTunes is extremely sluggish and slow to react. Batch editing files (I'm extremely anal about the tags and album art) takes FOREVER. I hate it.
    I blame the external drives. Maybe they're slow? (The 250GB FW is a Maxtor OneTouch drive).
    I do have an old Powermac G4 dual 533mhz with a nearly-dead 80GB HD in it. I was wondering if there was a simple way to load that machine up with the maximum amount of HD storage, and hook it up to the Pbook for my super-optimal-dream-media-storage solution.
    I'd prefer the cheapest and fastest (in terms of access/transfer speed) solution possible. I know I can set up the Powermac as a file server (but I don't know HOW), and I know I could set up the Powermac as a FW target drive and just plug it in (is that really optimal? Also, I have sold the monitor for it ... all I have is the keyboard and mouse.. is there a way to hook up the MacG4 to the Pbook as a monitor? and how much of a headache would it be to repeatedly connect/disconnect to the MacG4 without a monitor?)
    Anyway. I'm also open to solutions which would make the Powermac a wireless storage solution, since I live in a small apartment and love toting the Pbook around to surf and blog in bed, at the table, in the kitchen, etc.. except with my current setup I have to disconnect it from the music storage. So I can't have my Pbook in the kitchen and play wirelessly off iTunes...
    Thoughts? Comments? Suggestions? I know I'm asking like a million questions in one post, but I appreciate all the help in advance.

    Hi, jzn omg!
    Right now I've got maybe 3 or 4 GB free between the 3 drives...
    I run iTunes off my Pbook to access my library (which is stored on the 250GB external), but it runs SOOO SLOOOWW. iTunes is extremely sluggish and slow to react. Batch editing files (I'm extremely anal about the tags and album art) takes FOREVER. I hate it.
    I blame the external drives. Maybe they're slow?
    Your hard drives are severely overloaded. I try to maintain at least 10-15% or more available space on a drive, particularly on a startup drive. I'm not surprised that the applications are "beachballing" - your system hasn't been given sufficient hard drive space from which it can effectively operate. Moreover, your drive data is likely to be significantly fragmented with the system working "overtime" to constantly search for and piece together files before it can use them and execute the next command.
    Gary
    1GHz DP G4 Quicksilver 2002, 400MHz B&W rev.2 G3, Mac SE30   Mac OS X (10.4.5)   5G iPod, Epson 2200 & R300 & LW Select 360 Printers, Epson 3200 Scanner

  • Setting up permissions on the file server

    I am attempting to set up a file server with the OS X Server that came with my mac mini.
    I need to be able to set up permissions for 4 different users to be able to read and write, however with no permission to delete.
    I went to the MacMini section (on the left hand corner of the server app), then storage, and from there set up custom permissions
    I added the four users as a group.
    When I added the group to have access to the needed file, I clicked on the drop downs.
    I allowed all permissions for inheritance and reading. I selected all permissions for writting except for "delete" and "Delete subfolders and files"
    This give me a "-" sign next to write versus the check symbol (like it was shown for Read and Inheritance)
    After I set this up... I went to one of the users to test it out, it would not allow me to drop a file on the server or delete anything.
    How do I get this to work the way I want it!?!

    You can not do this with a single ACE.  Or at least I've never been able to.  This shoud resolve.
    Please make sure you test this however.  Remember that trying to overwrite is a delete and then a write.  So if you deny delete, then you can not replace a file or folder with one of the same name.  Also, renaming a file is also a delete.  You will not be able to rename.  Make sure you test this before putting into production to ensure you are getting the behavior you want.
    You have a share point named Archive.  You have a group called Archive_Users.  The Archive_Users are allowed to read and write but NOT delete data in the Archive.  Do do this, follow these steps:
    1:  Create a group called Archive_Users and place your users into the group.
    2:  Define your share point in File Sharing.
    3:  Edit to share point to add the group.  Press the + button and start typing the group name.  When it appears, set the permission to Read Write.  You permission window should have 4 entries at this point.  The everyone, the group (likely staff), and the owner (likely the server admin).  Then the one you added.  The bottom three are POSIX, the final one is an ACE.
    4:  Now, you need to get your hands dirty and create a custom ACE.  Server.app does not allow you to use the Deny rules so break out Terminal.
    5:  I will assume the Archive folder is in this path /Shares/Archive.  First get a list of the folder's ACL using:
    ls -le /Shares/Archive
    It should like like the following:
    drwxr-xr-x+ 2 carbon  wheel   68 Feb 18 22:27 Archive
    0: user:_spotlight inherited allow list,search,file_inherit,directory_inherit
    1: group:archive_users allow list,add_file,search,add_subdirectory,delete_child,readattr,writeattr,readextat tr,writeextattr,readsecurity,file_inherit,directory_inherit
    6:  Now you must add your deny rule.  Use the following command:
    chmod +a# 2 "group:archive_users deny delete,file_inherit,directory_inherit" /Shares/Archive
    The syntax here is to add (+a) an ACE at index 2 (# 2), an ACE for the group archive_users that states the group can no delete any file or folder and this is inherited all the way down.
    7:  If you have content in the folder already, be sure to propagate the permissions.
    8:  Test, test, test.
    Remember, the deny rules can have some odd effects.  As mentioned, I can think of the renaming and the overwrite as possible deterrents.
    A possible alternative is to not give everyone read write access to the Archive. It might be more sane to define two groups.  The first groups, Archive_admins, is a subset of users who are entrusted with moving data to archived status.  The second group, Archive_users, is the rest of the team and they have read only access, allowing them to pull data but not edit the archive.  This allows you to use two simple ACEs in Server.app:  Archive_admin = read/write and Archive_users = read.
    R-
    Apple Consultants Network
    Apple Professional Services
    Author "Mavericks Server – Foundation Services" :: Exclusively available in Apple's iBooks Store

  • What documentation do I need to set up a second file server?

    I have a 10.4 server that used to be my OD master...  but I'm setting up a new Mac Pro to be the master (running 10.6) but would like the old 10.4 server to handle some of the network software.  I don't mind doing a bit of reading to set this up, but I couldn't find any documentation to help me.  The File Server Administration PDF doesn't talk about a second server for AFP or how to get the second server to look up user information on a different server running as the OD Master...
    Thanks in advance for any help or direction!  (either would be great!)
    Kevin

    Hi
    Launch Directory Access (/Applications/Utilities) on your 10.4 Server, click on the LDAPv3 Plug-in and create a New Entry. Add the fully qualified domain name of your 10.6 OD Master. There's no need to provide authentication unless you're disallowing anonymous binding on your 10.6 OD Master?
    Assuming everything is as it should be regarding internal DNS Services and that the 10.4 Server is referencing the correct DNS Server, the 10.4 Server should now be reading from the OD Master's LDAP Database - essentially your Users and Groups. Launch WorkGroup Manager on the 10.4 Server and you should see those Users and Groups.
    All of the above absolutely depends on properly working and configured DNS Services. You may want to add an A Record for the 10.4 Server in whatever you've designated as your DNS Server for your private network. Presumably this will be the 10.6 Server? For SSO (Kerberos) Authentication to work properly - assuming this is what you want? All Servers and Clients must be referencing the same NTP Server.
    Assuming all has gone well with the 'join', launch Server Admin and click on the Open Directory Service. This should report its role as "Connected to a Directory Service". Now start the AFP Service. Use WorkGroup Manager to define shares and access. I would enable Access Control Lists for volumes you wish to designate shares on. Once enabled restart the 10.4 Server. Use the ACL Permissions Model rather than the POSIX one. Make sure you propagate permissions afterwards. Don't share Volumes. Share folders instead.
    You can have as many Servers as you like presenting AFP Shares to as many clients as you like. There is no restriction. Basically it's just another server offering shares. The documentation you've read does not mention multiple servers probably because - no offence intended - it's kind of obvious and fairly straightforward.
    HTH?
    Tony

  • File Server and Permissions

    We are using Coldfusion 8.  Does anyone know a way to set permissions on a file server so my users in my cfapplication are the only people that can access the files in a specific folder on that server?  I ask this because we have a lot of public folders on this server and now we want to add some private folders only accesable via people using the application.

    If what you are asking is "how can I setup a folder on my fileserver so that files that are accessed through my CF application using tags such as CFFILE are the only ones that can access it" then the answer is to 1) Change the login information for the CF services from the local system service to a domain account, being sure to give that account admin privs, 2) on the file server only give access to the domain user that you just created in step 1.
    However, if your CF app is allowing users to access that folder via mechanisms like HREF links (ie, where the account accessing the folder is not the CF account, but the user that is logged into windows running a browser), then you need to put those users in a group and give that group the sole access to the folder.
    Scenario #1 presumes that your CF app is doing some sort of authentication so that it knows who is allowed to use it to get to that folder. 
    -reed

  • Auditing file server setup issues - nfs permissions

    I have half-dozen Solaris 10 workstations requiring Solaris Auditing enabled and audit files saved. I used a spare Solaris 10 system with 2-72GB disks and formatted 2nd disk for entired 72GB. I shared out the 72GB partition on this system and modified /etc/security/audit_control on a test Solaris 10 W/S to use the shared-out partition on Audit file server as primary audit directory. Following directions in Solaris 10 Admin Gde I chmod -R 750 the mount pt using the 72GB partition before sharing out the partition. However, all client W/S's that I enable Auditing would not use the 72GB partition on file server until I went back and chmod 777 the partition and rebooting file server. Also, on any client that I have enabled Auditng to use nfs-mounted 72GB partion on file server I cannot as a non-root user issue a "df -k" command without getting error:
    df: cannot statvfs /var/audit/fmaud.1/files: Permission denied
    Is this normal or did I miss a chmod step or two in setting up Audit clients and/or Audit file server?

    The roundcube db schema needs to setup manually. See /usr/share/webapps/roundcube/INSTALL
    Also, from your /etc/webapps/postfixadmin/config.inc.php:
    $CONF['domain_path'] = 'NO';
    $CONF['domain_in_mailbox'] = 'YES';
    $CONF['maildir_name_hook'] = 'NO';
    ..which results in /var/mail/vmail/[email protected]
    From your dovecot.conf
    mail_home = /var/mail/vmail/%d/%u
    ...which results in /var/mail/vmail/domain.com/user
    That doesn't fit together.

  • Help setting up a File Server

    Hello,
    I have a few questions about setting up a file server with Mac OS X 10.5 Server.
    I have set up a sub domain name for the server to use... I just don't know how to get the dynamic IP address to contact the domain name so can ftp to the server... Mac Server is very new to me and I have know Idea on how to set it up...
    FYI we plan to run the file server on a G5 Mac Pro, With a dynamic IP.
    -Ron

    You will not find this an easy setup to achieve.. the TC is not accessible remotely with BTMM unless it is the main router in the network.. and this is not possible when the Uverse is installed as the main router.
    The other method is to open AFP to outside access.. read the Tesserax methods here.
    AirPort Disk - Remote Access (3 Methods)
    The last method can be adjusted for using any brand router.. you do not need to port translate.. simply open port 548 to TC bridged behind the Uverse. It must be static IP so set that on the Uverse. And you will likely need to use ddns which is also built into the uverse.
    Good luck with the treatment.. I had a bone marrow transplant for Lymphoma 20years ago.. still alive.

  • Setting the UNIX file permissions after writing the file to a directory

    Hi Experts,
    Can we set the UNIX file permissions after writing the file to a directory using Receiver File Adpater in SAP PI 7.1 ?
    Thanks in Advance.
    Regards,
    Jyoti

    Hi
    you can use the option "Run Operatiing system Command after File Processing" in the file adapter.
    Thanks
    Rinku Gangwani

  • When setting up permissions for application files--URGENT

    Hello All,
    when setting up permissions for application files,
    Is this following permisson appropriate?
    If application files are owned by a single owner,
    that owner should be the oracle user.
    DN

    Here is my question again.
    when setting up permission for application file, which permission is
    appropriate?
    a) If application files are owned by a sigle owner,that owner should be oracle
    user.
    b) Application files should be owned by oracle user
    c) Application files should be owned by single user.

  • I have been trying to download photos. It keeps saying can't create file, please check permissions on destination folder. Ihave made sure I have set the permissions on read and write. What am I doing wrong?

    I have been trying to download photos too my MAC. It keeps saying can't create file, please check permissions on destination folder. Ihave made sure I have set the permissions on read and write. What am I doing wrong?

    Lanakivee
    Try this it worked for me Pat Willener gave it to me off the site :
    I have not read all you wrote, so I may have missed some points. As I understand it, you installed FP 10 on IE7, but it won't play any Flash content?
    Try this
    download the FP uninstaller from http://www.adobe.com/go/tn_14157
    close all browser windows, then run the uninstaller
    download the offline ActivX installer for Internet Explorer from http://fpdownload.macromedia.com/get/flashplayer/current/install_flash_player_ax.exe
    close all browser windows, then run the installer

Maybe you are looking for

  • Send message to WebSphere MQ resource adapter - how?

    Hi, has anybody a working sample how an Weblogic EJB can write to an MQ queue via the WebSphere MQ resource adapter? http://publib.boulder.ibm.com/infocenter/wmqv6/v6r0/index.jsp?topic=/com.ibm.mq.csqzaw.doc/uj40010_.htm I took Adrian Cole's sample f

  • What are you using as a Flash replacement for 64-bit machines?

    Hi, I was reading about the vulnerabilities in Adobe's Flash and decided to remove the offending package. I opened Chromium to make sure my Flash still worked, as I understood that Chromium implemented another method for rendering Flash stuff. I was

  • Material Master upload thru RMDATIND

    Hi Friends, I came to know for uploading of MMR is easy, perfomanc eis much better thru RMDATIND rather than BDC or even BAPI_MATERIAL_SAVEDATA. Is it so ? Is it so. Where can I get the details of documentation for this. I read some where, Production

  • Conveter for DataTable that has access to DataModel row variable?

    I am trying to make a conveter that I can use in conjunction with a datatable. So I can verfify the results against a DB and do custom calculations and easily display the error message next to that row. I do already have access to an EntityManager in

  • Outgoing email alleged to be "SPAM": ominous and serious privacy implications

    I attempted to send a link to a friend, and Verizon's software prevented me from sending the message, with a message saying "....the mail server responded 5.7.1...determined to be spam." By using the old standby workaround--guile, trickery and deceit