Setup Mac Server

Hello,
I have been ask to administer a Macintosh server, and while I do know Macs pretty well, I think I may be in over my head on this one.
The Server is a PowerMac G4 running Mac OS Server 10.2.8. I know it’s old but that’s what I have to work with. I think for what we need it should be enough.
I’ll try to explain the present Server setup (as it was when I began working here 3 years ago).
I work for a collection of medical research labs, each with a P.I. (primary investigator) and lab members. The way it was setup before I arrived is, each lab had an account, everyone in the lab would sign on to the Server using the same Laboratory account name & password. Each member could move files in and out at will. Everyone in the lab had access to everyone else’s files.
Now they want to give each person their own account. They want the P.I. to have access to all lab members data, but lab members to only have access to their own files. No more exchanging files between lab members.
The only thing I can come up with is to give each person an account, then make each lab member also a group, except the P.I., they would only have a personal account since no one else needs access to their data.
I then add the newly created lab member groups to the P.I.’s account so they can access their lab members data. This also isolates the lab members from each other.
I setup a share point for each account to their respective folder on the Server. In the share point the Owner and the group would be the same, this allows the P.I. to have access to the files (because I added each members Group to the P.I. account) as well as the actual owner.
I know this way will work because I tried it with the smallest Lab (P.I. + 4 members) we have.
But that was only 5 people. The 6 labs I need to setup would total around 80 accounts, plus a Group created for everyone minus the 6 P.I.’s. I would end up with over 70 groups!
Even now with only 6 accounts (one for each Lab)on the server I run into permission problem. About once a week I have someone calling me saying they are being denied access to a file someone else placed on the Server. I can go to the server and fix permissions easily using the Workgroup Manager. But, with 80 accounts I’m afraid this will become a permissions nightmare. Not to mention the Lab members come & go frequently, meaning I will be deleting and adding new account all the time.
Is there a better, easier or less complicated way to do this?
Thank you
Example:
*Johnson Lab: Primary Investigator -Dr. Eric Johnson*
* Lab Members- Robert, Mike, Alice & Steven*
*1)Dr. Johnson needs access to his own files in his personal folder, as well as all folders and files within of each Johnson Lab member.*
*2)Lab members should have access to their own folder & files only.*
If you have read this far you’re a Saint.
Thank you

Hello Lucid7,
If I were you I would draw your needs in the simplest schema possible. I would use layers for distinguishing services from permissions from user and groups and so on. You demands aren't exotic or impossible but sound rather cluttered and are the cause of user request.
The schema might provide you some additional insights, gaps and additional requirements. Bottom line things you didn't think of.
Also you might want to invest some time in studying:
+ document management system (e.g. http://www.alfresco.com)
+ update to a more recent server version as ACL have more options and are becoming more mature each server iteration (if cost is an issue, look at eBay) (10.2?)
+ inherent grouping (10.2?)

Similar Messages

  • Setup Lion Server for use in Small Office of Windows & Mac Clients

    I've purchased a Mac Mini Server with Lion Server installed to be used in my small office of less than 10 people.
    The primary goal of this server is to used for File Sharing, bother locally, and remotely.
    In the process of setting up Lion Server I have come across a couple things that I am confused about.
    The first is Open Directory.
    It is my understanding that this is not a necessary setup for the number of users in my office, however I set it up anyway as it appeared to be something that would be useful in the future.
    I have come across information that states Lion Server will not be accessible for Windows users connected via Open Directory. Thus my inclination is to disable the service, and set up my users as local users.
    My question is, for local and remote File Sharing, is there any benefit to using Open Directory?
    The second has to do with Remote Access.
    I am familiar with the notion of a VPN, but I need some clarification as to my remote access options.
    When I go to setup my Server's hostname, I am presented with three options. 1) Host name for local network, 2) Host name for private network, and 3) Host name for Internet.
    I have a domain name for my company's website, so I set up a subdomain (server.mycompany.com), asked my ISP for a Static WAN IP, and pointed thesubdomain to said IP using my DNS. Thus this appears to be option number 3; to allow users to connect to my server from the local network, as well as the Internet.
    My question is, how does this differ from a VPN both in setup, as well as method with which users will access the server? Is there a benefit to one over the other? I would Google this to find an answer, but I can't seem to find a name for what this setup is called.
    I very much appreciate any help you can provide.
    Thanks.

    Well, I spoke too soon.  Lion Server is unstable, awkward and is far too limited to qualify as an Apple product. Even though there's quite a few enhancements, the omissions of technologies in the server 10.6 edition makes this "server" a no go for us.
    Even after installing mysql, I still cannot run a Joomla website on Lion server as it should be done. The wiki's a nice thing to have, but isn't a "professional grade" solution.  There's too much iOS as well.
    With that said, I think it's a shame that apple would put customers through so much frustration and disappointment by releasing such a lame product. In order for us to use Lion server, we would have to be able to run a second (totally separate) instance of Apache. It also appears that server settings are changing to the extent that services become inaccessible as the system is running.

  • Simple question; Mac Server Setup for Mail, iCal and Address Book Services.

    Hi Guys;
    I'm new to the Mac Server world and need a few questions answered.
    I have purchased a new Mac mini Server for hosting File, Web, Mail, iCal and Address Book Services.
    I’m comfortable setting up File and Web Services however I’m a bit uneasy setting up Mail, iCal and Address Book services to be access locally and remotely(via the internet).
    My current setup is;
    Internet connection (Dynamic IP) -> Router -> Mac mini Server.
    I have purchased a domain name (Thornton-net.com) from DynDns.com + a custom DNS service as I can setup my router to update my domain’s IP address automatically.
    I can access File and Web Services remotely (thortnon-net.com) perfectly without any issues via the Port Forwarding feature of the Router.
    If I setup Mail, iCal and Address Book Services -> will Mail, iCal and Address Book clients be able to access these services hosted by the server via Thornton-net.com?
    Message was edited by: Allan.Thornton

    Welcome to the forums.
    For mail services (and specifically for your outbound mail to be accepted by other mail servers) your mail server needs to have a static IP address and matching forward and reverse and MX records, or a tunnel to a static IP (with matching DNS), or you need another mail server where you have an authorized relay. Without that, your mail will be considered a spam engine, and dropped.
    Additionally, your particular tier of service with your ISP (with a static IP) will generally allow server-oriented access and server-oriented network traffic, where a residential or other tier of service (with a dynamic IP addresses) can be firewalled.
    The ISP controls the "high ground" of the network connections here, so you pretty much get to play by their rules and requirements. If they don't offer static IP, then (presuming their T&Cs permit it) you get to tunnel (via IPv6, for instance) to a tunnel broker, and receive your network traffic via that (and with matching DNS) point of presence. That could well be a tunnel for your mail at whichever your DNS provider is here, because you'll have issues with your dynamic address. (You get to sort out if they offer that.)
    Far and away the easiest approach (if you want to host this stuff yourself) is to work with the ISP. They're inherently involved in your network, and they and they alone have full control over your reverse DNS configuration.

  • Best DNS setup for public-facing Mac server with no NAT?

    What's the best way to set up the DNS server as a member of an existing domain with nameservers elsewhere for a public-facing server with no NAT?
    We own the domain myexample.com and it's name servers and zone files are on a hosted linux server with mail/web server services.
    We now have a Mac server hosted elsewhere and we want it to be a subdomain of our myexample.com i.e. macserver.myexample.com.
    We haven't enabled NAT or DHCP so the Mac server host network IP is a public IP. There is no LAN.
    When setting up the DNS server, what should the primary zone be? macserver.myexample.com, or myexample.com?
    Any advice would be great. Mr Hoffman....are you out there?

    You do need valid DNS services.  But you don't need to provide DNS on the same server.  And if you're not dealing with NAT, things can get easier.
    The easiest approach available is to not run your own DNS services here.   This assumes the OS X Server box is configured on a static IP address, but then that's something OS X Server needs/wants/ expects.
    Use the DNS provided by your domain registrar, and your ISP.    Or maybe on that Linux box, if that's publicly authoritative for the domain.
    Enter the host name and the IP address into the public DNS services that you have configured for the domain, or that you have at your registrar or ISP, or on that Linux box.
    You will need to have your ISP for the static IP configure a PTR record (reverse DNS) for the server, particularly if you're planning to run mail or related.

  • How to set a static IP address on a Mac server?

    I am setting up a New Mac server for a mail sever and have resieved the MX record and IP address from the ISP and DNS providers. Now I am trying to set up the server to be seen on the out side, or even on the network. Is this all done in the Network confiruration by maually setting the IP and Sub Mask there? I have set it all up to what I think they should be but not having any luck. When I installed the server software I told it to be a stand alone server was that wrong. I will not be running DNS or any other services on this system only Mail.
    thanks

    You should enter the IP address/netmask, etc. during the first-time-boot setup. Changing it later can be a PITA, but it sounds like you did that.
    Setting 'standalone' shouldn't be an issue since that only relates to directory services.
    It sounds like the problem is a more basic connectivity issue.
    Have you verified that you have basic IP address connectivity? Can you ping the router address provided by your ISP? Can you ping remote sites outside your network? If that's not working you're not going to get much further.

  • I'm running Snow Leopard and want to setup a server.

    Hello everyone!
    This is the situation: I have large amounts of data I want to be able to access from afar. Some friends as well. At some point we would want to share some of that data. Dropbox or similar services are not an option since space is limited and expensive. We prefer spending some money now to paying monthly... So we thought of setting up our own server. Although I'm far from being a computer specialist I proposed myself as some sort of vanguard...
    The idea would be to provide to all four of us some 5 tb for storage that should be accessible from everywhere to each one of us. (I have a small MacBook Air and would like to travel light while having access to my data at home). This "data" would mostly be small files from 500kb to 5mb, a smaller portion is about 50-100mb (mostly pdfs and scans).
    Then sharing: If we set this up and get it running there would still be the question of how to share data... Suggestions?
    I'm running a Mac Pro 3.1 on Snow Leopard. What are my options? What kind of software or whatever this is called will I need to setup a server? For several reasons I don't feel like upgrading to Lion and Mountain Lion, in fact I'm quite stubborn about this. This means (as far as i know) that I won't be able to use OS X Mountain Lion Server...
    Hardware: Any tips? We're thinking of investing some 1000 euro.
    From what I've read some OS X server would be relatively easy to setup; is there other options?
    I would be thankful for a link to good guide as well!
    Thanks to everyone in advance!

    SL Server runs the Apache Server. To access a remote server you set up would have to access it via a direct IP address, like 292.128.12.144, since you can't assign a pretty name to your broadcasting server such as www.goodstuff.com.
    That's incorrect. If you have a dynamically assigned IP address you're going to need a way to reference it whether it be Wide Area Bonjour else a dynamic DNS service… either way you're not referencing it via an IP address. If you have a static IP address then pointing a domain name or sub-domain to it is really simple.
    The biggest issue to my mind here is the upstream speed as you mentioned. Irrespective of how much storage one can cheaply attach to their server one is going to be limited to how much of that can actually trickle out of their internet connection. Moving 5TB over SATA is painful enough let alone trying to move anywhere near that over DSL or cable internet. Sure you're not going to want to transfer that all at once but that data all came from somewhere right… and all it takes to really bottleneck things is for 2 people to want something at the same time.
    Don't get me wrong as there are plenty of benefits to running your own in-house server. Deprecating via the internet access to services like Dropbox isn't really one of them though. If you're mostly on the local network to your server the sure but if not then there are better solutions.
    For what it's worth I use both OS X Server (Lion) and a web host as both provide a benefit that the other can't.

  • Help needed with Mac Server set up

    Hi
    I have purchased a mini mac server, that i want to use as a replacement for my windows home server, for basic back ups & to run a website with possible remote access.
    At the initial configuration screen where if you manually configure your connection via ethernet, after putting the desired internal ip, sub net, router and DNS, it should find my domain on the next page where the server would be named. this does not happen, ( this is where i need the help )
    I have a domain name
    fixed external ip with my it pointing to my domain name
    and a RDNS setup with my ISP
    Any help?
    you can email me directly : [email protected]
    many thanks

    If you're running NAT, well, you have some choices on how you might choose to [set up DNS services|http://labs.hoffmanlabs.com/node/1436]. Once you get that sorted, there's a link there to the set-up for the public-facing (outside your external firewall) network configuration, too.

  • Trust relation between mac server 2.2.1 (10.8 mountain lion) and windows server 2008 r2

    i have the following settings:
    windows 2008R2 domain server.
    mac server 2.2.1
    mac client machines
    mac server machine is joined to Active Directory in windows 2008r2 without any problems.
    mac client machine is joined to mac server without any problem.
    the only problem is that i cannot log in to the mac client machine with a username from the active directory in windows 2008r2. i can log in with a created user on the mac server.
    i did a trust relation in windows 2008r2:
    Realm trust
    Transitive
    One-way incoming
    still cannot log with ad users. can anyone help me in the configurations if i missed something? i am new to mac servers and their configurations.

    does this mean that on every mac client i have to join 2 domains, the windows domain and mac domain?
    Yes
    then, why to use "workgourp manager" in mac to copy all the active directory users to mac server group? i do this to make all users available for authentication through mac serve ronly.
    Am I right? The users on your macserver are a copy of your users of the AD? It was not necessary to do that. Because all Users will listed on the Server.app on the User-Manager if you setup was correct. And this means:
    - first join your Mac (used as Server) to your Active Directory
    - second Install the Server.app. The Setup Wizard will do the rest.
    In my case, on the Usersection an the Server.app I will find "Benutzer von FAMILY-NET" that is my Active Domain.
    and if i join the mac client to windows domain for authentication, why do i need the mac server for? i need only to authenticate users in active directory on mac os x and that is only it.
    In this case - you need no Mac Server!
    Only if you want to use the Services of the Mac-Server (DNS, Wiki, Mail,...) or Manage you IOS/Mac Devices. Than it is necessary.
    sorry for my many questions, i am very new to mac os x and server.
    No problem. I lived in Mac-Worlds since 2 years. I infected with it with the purchase of my first iphone.

  • Anyone aware of a step by step guide to setup lion server?

    Anyone aware of a step by step guide to setup lion server? Looking to bin my SBS and movr to lion server but need an idiots guide to step by step setup.

    Hi Joe,
    Thanks for the info. Was also looking for a step by step guide on installtion of all the different modules, i.e. mail, profile manager, wiki for example. Maybe im just to use to windows server but the mac server just seems too simple. Maybe i am over complicating things.

  • HELP! NEW TO MAC SERVER MAIL

    Call me a dumb but I am new to our Snow Leopard Server software coming from a Windows server. I have watched tutorials at Lynda.com and went through manuals but don't understand how to set up our client mail. We are confused with the instructions because the Mac server allows you to set up "user mail" for you own company.
    We are looking to set up a bunch of e-mails for all the different domains we host on our server. These are not our personal company e-mails but our client e-mails for the different websites we are hosting for them.
    So how do we set up and configure (add new) e-mails for the different domains on our server?
    I hope I haven't been confusing and you guys understand what I am asking. Thanks!

    There are a couple of ways of handling multi-domain email. The 'right' way for you depends on several factors, including exactly how you're trying to implement mail/domains, how comfortable you are with command line vs. GUI configuration, and number of users.
    If you're just looking for a catch-all email for each domain it's probably easier setup using pure postfix virtual domains. that requires command-line configuration, though.
    Using the GUI will require that you add every user to your directory and then give them additional 'short names' that match the email address(es) in the other domains.

  • Mac-Server as Phone-central-server

    Hi there,
    Lets' start by whishing you a Happy new year and a profitable 2007.
    I would like a mac server, to work as a phone server,
    - to be connected to our multiple phone and fax lines as well VOIP,
    - working as a phone-central,
    So Phone calls are answered automatically, etc..
    and connected through to the right person logged-in withtin the network.
    (or phone = redirected, transfered to mobile when they are out-of-office)
    So users from any other mac within the network,
    are able to Phone (in/out), from their mac,
    using (be able to choose) any of the multiple Phone-Lines.
    Or Connect through to each other.
    (clicking on a list of all people logged in in the networtk)
    I am already familliar with Ph-link (http://www.ovolab.com/phlink/index.php)
    There are plenty of companies offering this for Mircosft-windows platform
    But have not found a programm that enables a mac-server into a Phone-server, as described above..
    Does any of you know a company who has such software ?
    or does anyone have experience what would be the best programm to use.
    Thanks
    Bastiaan
    Intel 1.83 Core Duo   Mac OS X (10.4.7)  
    Powerbook G4   Mac OS X (10.4.7)  
    Powerbook G4   Mac OS X (10.4.7)  
    Powerbook G4   Mac OS X (10.4.7)  

    It should be possible to alter the NAT config so it will use the ppp0 "interface" (PPPoE) instead of the en1 (?) you get on that USB interface ethernet adapter. At least used to work in Tiger/Panther.
    Export server settings in Server Admin (tried this with Leopard server Advanced setup) only exporting NAT/firewall settings. Open the exported file and exchange en1 for ppp0 save it and import it using Server Admin. The en1 interface should be on top of the lits of interfaces i Network prefpane (no router field filled in for en0).

  • How to setup vpn-server in Mountain Lion 10.8.3?

    Before I updated my mac mini server to 10.8.3 I used Server Admin to setup a vpn server. After the update Server Admin isn't supported anymore and my vpn settings are gone. Now i want to setup the server again, but have no clue what settings to enter where.
    I suppose it starts with adding two vpn-interfaces: PPTP and LT2P.
    But how further? I can't find a tutorial or manual.

    I do now :-)
    And many thank, that's the application I was looking for. My vpn is back online. Well, the mac-part. I still can't connect with a Win7 system. Connecting to a vpn-server of another company works fine, so it's something in the configuration of de Mini Server.
    The error code is 629.
    Hopefully someone can help me with this part too?

  • I just tranfer all my photo from my Mac though itune to my iPhone so I can setup Mac back to factory setting after doing I try to put my photo vac to my Mac I photo did not detect any of the photo that I had tranfer from itune it only detectPLAESE  HELP!

    I just tranfer all my photo from my Mac from itune to my Iphone so I can setup Mac back to factory setting after I don't with that, I try to put my photo back to my Mac and Iphoto did not detect any of the photo that I had tranfer from itune it only detect the one rhat i took with the Iphone PLAESE  HELP!!!!!!

    Hello Partii,
    It sounds like you may use a POP account for your email.  With a POP account, email applications like Mail and Outlook can remove emails from the server, so when another device tries to check the server for new emails, it doesn't see any. 
    You may need to adjust settings in Outlook so that the emails are not removed from the server when downloaded.  I found an article with more information:
    When using a POP email account with multiple devices, email messages may only appear on the first device that receives them. This occurs when an email client is configured to automatically remove email from the server once an email client has received it. You can configure your email client (or clients) either to keep a copy of the email on the server, remove it after a certain number of days have passed, or keep it until you move it from your Inbox.
    I recommend reviewing the full article for steps on adjusting these settings; you can find the full article here:
    Using a POP account with multiple devices
    http://support.apple.com/kb/HT3228
    Thank you for using Apple Support Communities.
    Best,
    Sheila M.

  • MAC Server & iTunes : Does MAC Server support central iTunes repositories?

    I need some help
    Problem:
    I have a family of "5" who are all MAC users - all alas have different MAC iTunes repositories. I want to create a central MAC Music repository to ease the pain on my checkbook. Three people bought Nora Jones new Album... one person pays - me
    Setup:
    Potential Server:
    BIGMAC1:
    Dual Proc Power PC G4 1.25 Mhz, 1 gb RAM
    Gig Ethernet Connectivity with 4 Terabytes of RAID storage.
    Clients:
    5 MAC's... (Mac Mini, 24" iMac (intel), 2 Mac Book Pro's (Intel), and a 12" Power PC)
    Current Setup:
    I use symbolic links from the desktops to BIGMAC Music repository.
    Mount BIGMAC1 Disk via network
    Open System preferences
    Open Accounts
    Open login items
    Drag BIGMAC1 to login items
    Open iTunes
    <Backup iTunes music directory>
    Select preferences / advanced
    Turn off “keep itunes organized” and “copy files to itunes” on all clients
    Exit
    For each user
    Delete <User>/Music/iTunes/”iTunes Music”
    ln –s /Volumes/”BigMAC1 Disk”/Music ./<User>/Music/iTunes/”iTunes Music”
    Copy any purchased music to BIGMAC1
    Open iTunes on Client
    Delete Music library in iTunes
    Select add to library
    Select /Volumes/”BigMAC1 Disk”/Music
    Once complete your all using the same repository
    Issue: If someone adds new music you have to know and add it to you your library…
    This works but every so often some family member does something that duplicates all the files in iTunes. I suspect this is something to do with consolidate music library options. "Picture Homer Simpson looking frustrated"
    Help: Is their Recommended Solution?
    The above sort of work but is not perfect and I am not a "nerd". I need to maintain my social skills and would love to know if I can just install MAC Server or something equivalent and fix this.
    In short: Does MAC Server solve this or does something else?
    Hey Apple: I would line up and buy a solution if one existed...
    1. MAC Server in basement… access to music from PC around house. Music ordered is stored on basement PC and backup automatically…
    2. The ability to add a fourth child under account (MAC limit 5 machines to one iTunes Account)
    Apple: I am not breeding until you allow me to purchase another person to the family music account…. You would stunt their childhood if this is not fixed...
    TechnoPhobe!

    Your solution is as good as any to let you share iTunes tracks, especially ones purchased from the iTunes store amongst multiple users on a single computer.
    If you had multiple computers, you could use the built-in sharing function of iTunes and then access them from the other computers, but the other computers would also need 'authorising' to play the protected tracks.
    However there is something else you could consider. Have all the music and protected files on one computer, share it using iTunes, and access it using the new TV box. You could have multiple TV boxes and they would not need authorising to play the protected tracks. They would also not modify your iTunes files causing the problems you have occasionally experienced.
    There are other similar approach devices like the Roku Soundbridge, Sonos ZonePlayer, SlimDevices Squeezebox but none of those support tracks purchased from the iTunes store whereas the TV does.

  • Remote-control of a Mac server from Windows

    What is the Apple recommended way to logging into a Mac Server from a Windows PC so that I can manage it? I have an iMac on my desk but that's for creating/testing images. My main PC is an HP laptop running Windows 7. I've got Real VNC setup but the number of times it just stops working and I have to reconnect is not funny. Logging in is a chore, too. 1st password to control screen, then login to server, VNC gets kicked out during screen refresh, have to enter 1st password again to get back in.
    Is there an official RDP program like Windows has for managing Windows servers?

    Hi
    +"What is the Apple recommended way to logging into a Mac Server from a Windows PC"+
    AFAIK there isn't one? Why would there be? Putting the shoe on the other foot Microsoft offers RDC for mac to control PCs. I don't see anything on the site stating it's the 'recommended' way?
    +"Is there an official RDP program like Windows has for managing Windows servers?"+
    Yes. It's called Apple Remote Desktop. You can't install it on a PC. Since 10.5 VNC Server and Client are 'built-in' for Server and Client OS as you already know. The protocol is actually VNC. RDP is Microsoft's proprietary name for it.
    I've never had problems controlling any mac (server or client) using TightVNC, RealVNC or UltraVNC - there are others you could use and experiment with? Depending on the Windows OS and network environment you may have to experiment with all three before settling on one that works consistently. Perhaps the problems you're having are due to a misconfiguration? On the mac side enable Remote Management - not Screen Sharing. Go into the VNC options and enable the "Control Screen with Password Setting". Create a password but don't make it the same as the Administrator one.
    AFAIK the logging in behaviour you describe is normal in my experience. I've not found it a chore on either a platform.
    HTH?
    Tony

Maybe you are looking for

  • Query on Enhancement Spots and Composite Enhancement spots

    Hi Group, I want to know about "Enhancement Spots and Composite Enhancement spots" and how to implement them in the system? please provide me the uses and how to implement them for our requirements? Thanks, Vishnu.

  • Why does my printer cut off the top of copies?cc=​us

    My printer cuts off the top of copies.  Is there some way to adjust the printing size at the top?

  • Is the GeForce GTX 960 worth the extra cost over the GTX 750 Ti?

    Today I acquired an eVGA GeForce 960 FTW card with 2GB of GDDR5 VRAM to test against my main PC's existing GeForce GTX 750 Ti (also with 2GB of GDDR5 VRAM). But first, here's my impetus: Despite the fact that the GTX 750 Ti was newer than my now-sold

  • Startup.dll failed with error 127

    I am using CS5 master suite but premiere pro does not work, everything else works Load Library EX startup.dll failed with error 127 the specified procedure could not be found Does anybody ever got thie error msg ? Please help...

  • Only Downloaded Half

    I just purchased a book on iTunes. It has 12 parts. After the first 7 parts downloaded it stopped and now I can't get into the music store again. How to I get the other 4 parts? I'm sure this has something to do with the erratic behavior the music st