When do I use user group "wheel"?

Hello,
I have the following question: What exactly is the user group "wheel" for and when do I use it (instead of "admin", for example)? Background to the question is, I recently noticed that some applications needed to be updated regarding ownership and ACLs.
I had installed them while working as a non-admin user by drag and drop, authenticating as an admin user (which is short named "admin", too) when asked to identify as one. The apps were installed alright, but the ownership was set to the non-admin user, while the group was "admin". This caused some problems with BOINC, for instance, which I tried to fix by updating ownership and ACL, accordingly.
When checking other apps that were installed with Mac OS X I noticed that most belonged to "root" (aka "System") and group "wheel" instead of "admin". This lets me wonder about when to use which group.
Does anyone know about the backgrounds of this?
Thank you in advance
Jim

Regarding your original question:
"I had installed them while working as a non-admin user by drag and drop, authenticating as an admin user (which is short named "admin", too) when asked to identify as one."
Okay, a couple of things here.
First of all, for the most part, whenever you copy files in the Finder, the copied files take on the ownership of the person doing the copying (there's one exception which we'll see in the next paragraph). Since you were in a non-admin account, the Finder realized that in order to modify the /Applications/ folder, you'd need to first authenticate with an administrator name and password to obtain permission. Once permission was granted, the copied files took on the ownership of the user doing the copying (the non-admin user).
"The apps were installed alright, but the ownership was set to the non-admin user, while the group was "admin"."
Let's say you have a folder "ExampleFolder" whose owner is "root" and group is "admin". When you copy an item into the ExampleFolder, the copied item will take on the group permission value from the parent folder. That's why the item you copied had a group of "admin" (since the /Applications/ folder's group is "admin").
"When checking other apps that were installed with Mac OS X I noticed that most belonged to "root" (aka "System") and group "wheel" instead of "admin"."
Hmm, as far as I can tell, that's not true. Almost all of the applications in the /Applications/ folder will be drwxrwxr-x, root-owned, and group of "admin". Note that there is a display bug in the Ownership & Permissions section of the Finder's Inspector-style Info window in Tiger. The values shown in the pop up menus for owner and group do not update dynamically as you change your selection. Instead, they continue to show the owner and group of the original item on which you first opened the Inspector panel. So, for example, if you selected the /System/ folder, which has an owner of root and group of wheel, and then opened the Inspector window, any subsequent items you selected (such as applications in the /Applications/ folder) would still appear to have a group of "wheel". (The regular style Finder Get Info windows are fine).
Hope this helps.....
Dual 2.7 GHz PowerPC G5 w/ 2.5 GB RAM   Mac OS X (10.4.3)  

Similar Messages

  • AE 5.2: Using user groups as a dropdown function

    Hi All
    We would like to use the user group functionality on CUP but the client does not have the same user groups across all systems.
    Our suggestion is that they have all user groups defined across all the systems.
    Is there a way that we could accomodate the client as per the current set-up where not all user groups are defined on all systems?
    Any assistance on this matter will be appreciated.

    Hi,
    I'm not sure of all the complexities around this but we had a similar problem where the user respository we used could not be connected using LDAP.
    The solution that was implemented was to create an ADAM (Active Directory Application Mode) directory, which is connected to the user repository - ADAM is then connected the UME for AE as the LDAP server.
    Probably not the most elegant solution, but we have been using this in  PRD environment for a couple of months now without any performance issues.
    Unfortunately I don't have all the details to guide you through all the config that was required, but perhaps you could investigate this as an alternative solution.
    Regards

  • Afaria User Group

    Hi
    I'm using User Groups in Afaria based in AD group.
    I have just one problem, I don't able to see devices list when I use user group?
    What can be happening?
    Regards,
    Lucas Araujo

    You're right.
    USER groups are not shown in the link window so you can't tell if a specific policy is linked to a given device/user pair. It will be but the UI doesn't show it.
    It's a pain to debug :-(
    BR
    Peter

  • Authority check - in terms of User Group

    Hi all,
    I need restrict the usage of a finnance report by order of users.the report has order grup as an input, only certain order groups should be viewed by certain users. in authority check can do the checking by using user groups instead of individual used.i.e create separate object for seperate order group and for each order group can i check against user group instead of individual users. kindly help.
    thanks.

    hi,
    Authorizationcheck can be done  for:
    1.Transactions
    2.ABAP programs
    in abap programs use the below code as reference for authorization check
    AUTHORITY-CHECK OBJECT  0.
        MESSAGE e184(sabapdocu) WITH text-010.
      ENDIF.
    rewards points if useful.
    regards
    sandhya

  • Conditions based on user groups

    Hi,
    I am already using the authorization i dont want to make any changes.
    I want to restrict the column using user group.
    If my user group is admin or unique then display the item and if the user group helpdesk or test then dont display.
    I am using condition: PL/SQL Function Returning boolean
    declare
    begin
    return apex_util.current_user_in_group(p_group_name=>'admin');
    end;
    It is working fine for only admin group. If i need to display the column to either admin or uniqueuser group ,Then please could you advise the expression for that.
    Regards
    Harinder

    Hello Harinder,
    What about
    return apex_util.current_user_in_group(p_group_name=>'admin') or apex_util.current_user_in_group(p_group_name=>'yourOtherGroup');
    Greetings,
    Roel
    http://roelhartman.blogspot.com/
    You can reward this reply by marking it as either Helpful or Correct ;-)

  • EasyDMS - How to create user groups?

    Hi,
    we are using ERP2005 and EasyDMS SP08(Unicode). We like to use user groups from the authorization tab to implement authorizations on folders and document.
    We can create a user group in EasyDMS, but if we assign this to a document it is said that the user group doesn't exist.
    I have assumed that we have to create the user groups in tcode EASYDMS_CUS before but that doesn't work either.
    Has anybody an idea?
    Regards,

    Hi Oliver,
    please implement SAP note 1037891. This note is necessary to avoid the '...doesn't exist' message.
    Best regards,
    Christoph

  • How can we restrict the other user to add their user id's to the user group created in SQ03?

    Hello All,
    How can we restrict the other user to add their user id's to the user group created in SQ03?
    When we enter the user group name and click on "Assign users and Infosets" button in the attached pic "User Group" .
    I was able to enter my user id in other user groups. How to Grey out the other rows in the attached pic "User Group 1".

    How strange I answered (or at least helped) this very same question earlier today. Here the link to my previous answer then:
    http://scn.sap.com/thread/3536135

  • User= Group= SubGroup= Role: Now working when this link is used

    Hai,
    We are using EP 5.0 with LDAP 7.6 When a user id created it is attached to a group and the group is attached to a role. I introduced a nested group in this link as userid is attached to group, group is attached to sub group and subgroup is attached to role. When i did like this and login to the portal system the roles are not seen in the portal.
    Below are the things which i did,
    When a user id(Ex : MYTEST1) is created it is attached to a group(Ex : ESS_GE) by the below code.
           String group = "ESS_GE";
           String groupdn = "cn=" + group.toUpperCase() + "," + groupsRoot;
           String userdn = "cn=" + userid.toUpperCase() + "," + peopleRoot;
          // modifications for group and user
          LDAPModification[]  modGroup = new LDAPModification[2];
          LDAPModification[]  modUser  = new LDAPModification[2];
       // Add modifications to modUser
       LDAPAttribute membership = new LDAPAttribute("groupMembership", groupdn);
       modUser[0] = new LDAPModification( LDAPModification.ADD, membership);
       LDAPAttribute security = new LDAPAttribute("securityEquals", groupdn);
       modUser[1] = new LDAPModification( LDAPModification.ADD, security);
        // Add modifications to modGroup
        LDAPAttribute member = new LDAPAttribute("uniqueMember", userdn);
        modGroup[0] = new LDAPModification( LDAPModification.ADD, member);
        LDAPAttribute equivalent = new LDAPAttribute("equivalentToMe", userdn);
        modGroup[1] = new LDAPModification( LDAPModification.ADD, equivalent);
       // Modify the user's attributes
       lc.modify( userdn, modUser);
       // Modify the user's group attributes
        lc.modify( groupdn, modGroup);
    Group is attached to a role(EP_GE_USER_ROLE).  So the link is User =>Group=>Role which is MYTEST1=>ESS_GE=>EP_GE_USER_ROLE. This linke is working perfectly
    I introduced a nested group and changed the link as User=>Group=>Sub_Group=>Role  which is MYTEST1=>ESS_GE=>ESS_GE_ONLINE=>EP_GE_USER_ROLE.
    After this when I login with the user id MYTEST1 the Roles which are attached to ESS_GE_ONLINE is not shown. Any idea why the roles which are attached to group ESS_GE_ONLINE is not transferred to ESS_GE group. Should I have to add any other LDAP attributes apart from the one which are coded below.
      String group1 = "ESS_GE";
      String group2 = "ESS_GE_ONLINE";
      String groupdn1 = "cn=" + group1.toUpperCase() + "," + groupsRoot;
      String groupdn2 = "cn=" + group2.toUpperCase() + "," + groupsRoot;
      //Add ESS_GE_ONLINE group to ESS_GE group
      LDAPAttribute membership1 = new LDAPAttribute("uniqueMember", groupdn2);
      modGroup1[0] = new LDAPModification( LDAPModification.ADD, membership1);
      LDAPAttribute security1 = new LDAPAttribute("equivalentToMe", groupdn2);
      modGroup1[1] = new LDAPModification( LDAPModification.ADD, security1);
      //Add ESS_GE group to ESS_GE_ONLINE group
      LDAPAttribute membership2 = new LDAPAttribute("uniqueMember", groupdn1);
      modGroup2[0] = new LDAPModification( LDAPModification.ADD, membership2);
      LDAPAttribute security2 = new LDAPAttribute("equivalentToMe", groupdn1);
      modGroup2[1] = new LDAPModification( LDAPModification.ADD, security2);
      lc.modify( groupdn1, modGroup1);
      lc.modify( groupdn2, modGroup2); 
    Thanks & Regards,
    H.K.Hayath Basha.

    change that to the following and retest:
    Joshua Fowler wrote:
    I think you're correct. Under the Publish settings of the document, that's what "Class" points to.
    Here's the first main section of the code:
    package com.anselmbradford
      import flash.display.MovieClip;
      import flash.events.TimerEvent;
      import flash.utils.Timer;
      public class Main extends MovieClip
      * Create a new CountDown object, listen for updates and pass it the date to countdown to.
      public function Main()
      var cd:CountDown = new CountDown();
      cd.addEventListener( CountDownEvent.UPDATE , _updateDisplay );
      cd.init( new Date(2015,3,9,20,00) );
      * Update the display.
      private function _updateDisplay( evt:CountDownEvent ) : void
    Does this look correct?
    Thanks again!

  • Add user to group wheel

    How do I add a user to the wheel group?
    Or more specifically, how do I allow TextWrangler to write to /etc/hosts?
    Thanks in advance.

    Linc Davis wrote:
    Second and last try to keep you from doing real damage. Don't modify things like system groups and permissions when you don't know what you're doing. If you don't like my suggestion of editing the file in place, then do the following. I'll make this as simple as I can.
    1. In the Finder, press the key combination Shift-Command-G.
    2. A window with the title "Go to Folder" will open. In the text field, type "/etc" (without the quotes.)
    3. Press Return, or click the 'Go' button. A Finder window will open with the contents of /etc showing. Find the file you want and drag it to your Desktop. The file will be copied, not moved.
    4. Edit the copy using any editor you want. Save the changes.
    5. Open a Terminal window. Drag the following text into the window:
    sudo -i
    Press Return. Type your password when prompted. Now type:
    cat
    There's a space after the word 'cat'. Do not press Return or any other key.
    6. Drag the icon of the file you just edited from your Desktop into the Terminal window. Some text will appear automatically. Right after that text, type '> '. That's Shift-Period followed by a space.
    7. Drag the icon of the original /etc/hosts file from the Finder window into the Terminal window. Click in the Terminal window to bring it forward, then press Return.
    8. Verify that the modified hosts file does whatever you're expecting it to do. If it does, you can close the Terminal window and delete the hosts file from your Desktop. If not, revert the changes you made to the copy and repeat the above steps to revert the changes to the original.
    holy crap finally I tried this one and it works wohooo...Im so exited I can barely write...I've been trying to activate php5 for hours and it wouldn't let me because of the group wheel crap finally I try this and VOILA very nice...THNX a lot dude You really saved my day
    Message was edited by: Spideruser
    Message was edited by: Spideruser

  • How to use User Options and User-Defined Fields in DC Group function?

    Dears,
    As title, when should I use above fields?  I did not see the related information in SAPME help library.
    Thanks!

    The user options fields are just information fields you can store at the Data Collection Maintenance activity. You can think of these as extra information fields for storage purposes only.  I can't give you a use case except to say 'information fields' only.
    With regards to the User-Defined fields in DC Group - you can think of these as extra data fields to be collected.  They will appear immediately underneath the data parameter they are defined in in the DC Plug-in for the POD.  They do not have limits but are just extra pieces of data you may want to collect about the specific parameter.

  • Creating user groups using SQ03.

    I am going to make a change to a already existing query 01 in the user group /SAPQUERY/AM. I am not a query expert, in fact this is the second query that I am modifing. I am reading some documentation that the first thing that I have to do is create a user group. from what I am reading, the user group will contain the users that are allowing to modify queries. Since our users do not use this tool, I am the only one that creates and modifies queries. I think I am going to create a user group and that my user-id will be the only one in the group - correct? will I create one user group and and queries that I make changes to in the future user this user group or do I create user groups based on the users group that are defined by SAP. example - If I am changing a query in /SAPQUER/AM  and in /SAPQUERY/AU - would I create 2 user groups  1 for AM and 1 for AU or would I create only 1 user group and use it for both queries.
    After this, I think I have to copy the infoset (SQ02)and the query (SQ01) to custom names (names starting with Z) and then attaching the parts to the new user group.

    Hi Timothy
    Typically you want to create user groups for functional areas or grouped reports/queries. You can enter as many users as needed into a user group and only those who have the checkbox next to their name in the user group screen will have authorization to create/modify queries in the infosets where the usergroup is assigned. If you are creating 2 usergroups with the same users and authorizations then that is redundant but if the list of users is different or the authorizations may change then it would make sense to have 2 usergroups. You should have some naming convention to follow when creating the queries but the Z prefix is not required.
    Andy

  • Problem using a group which has a space in it's DN when using LDAP Group mappings in UCS 1.4

    Hey,
    We've been implementing LDAP authentication (Active Directory) using LDAP group mapping in UCS 1.4, and we've noticed that when using a group which has a DN with a space in it (such as "UCS Admins") it wouldn't authenticate the user with the appropriate role.
    Using a DN without spaces (such as "UCSAdmins"), works just fine.
    I should mention that having a base DN with spaces works just fine as well, it's just the group mappings that doesn't work.
    I should also mention that Cisco's "Quick guide to configuring ldap for ucs 1.4" shows an example in which the group's DN doesn't include a space.
    Is there a workaround available which can make it possible using a group which has a space in it's name?
    Thanks,
    Dor

    Hey Roman,
    Thanks for your prompt reply.
    We've tried putting quotes using UCSM which is not possible at all - not for the entire entry nor for the part with spaces.
    We've also tried using CLI ("scope security/ldap/ldap-group") where you have to put quotes if you use a DN with spaces, and it still doesn't work. Furthermore, we tried adding quotes only to the part with the spaces, i.e. - CN="UCS Admins",OU=TEST,DC=TEST. It adds the entry without an error, but shows like we would use "CN=UCS Admins,OU=TEST,DC=TEST". Anyway, it doesn't work either.
    Thanks again,
    Dor

  • To use the "Users & Groups" preferences pane, System Preferences must quit and reopen.

    When I try to access some of the system preferences in Mavericks I get an error pane that states "To use the “Users & Groups” preferences pane, System Preferences must quit and reopen."
    Has anybody had this problem and if so what is the fix?

    Usually happens if you opened one that was 32-bit. Then, you need to revert back to 64-bit.

  • Using users and groups from LDAP in ADF application

    Hi there,
    I'm using WebLogic Server 10.3.5.0 and JDev 11.1.2.3.0.
    I configured my WL server to use the users and groups defined in my LDAP server (they display when I select the Users or Groups tab). So this works fine (I think).
    Now I want to use 1 group, let's call the group ApplicationGroup, and all it's users to give them access to my ADF Application.
    But I can't find proper/up-to-date info about how to do this.
    I tried 2 major things:
    1) I configured ADF Security to use Authentication and Authorization. Defined an Enterprise Role with the same name as in my WL server (so ApplicationGroup) then defined a
    Application Role with a custom name and added the Enterprise Role to it. That Application Role I gave access to all my TF's and Web Pages. When I deploy this, It just doesn't work (Migrate Users and Groups is not checked).
    2) Used the Authentication option in the ADF Security and the rest is the same as in 1). This works +-, I can login with all users so the role mapping isn't configured right I guess?
    Any help or documentation that could help me?

    Since we aren't using EM I had to find an other way. And I found it.
    In web.xml ADF Security (I suppose) automaticly adds 'valid-users'. In my weblogic.xml I added my enterprise role as a principal to 'valid-users' and this works for me.
    Thanks for the help.

  • Why do we change the user group when doing LSMW?

    Hi experts,
    I just wanted to know why do we change the user group Tcode SU3 when we are doing upload of data using LSMW?
    Thanks,
    JEss.

    As Rajesh suggested if you are uploading data for action in which infotype group is based on User Group then you need to change User group.
    Otherwise there is no need to change user group for using LSMW.
    Rgds,
    Lata

Maybe you are looking for