With Lion, Problems Accessing Shared NTFS Folders with SMB://

We are testing a local login script that we created for our Macintosh users on Lion. It has worked fine on all OS X versions prior to 10.7. Listed below is the script that we are using. When we run the script, it now mounts a folder called "home" instead of "username" and throws an error stating that "The folder can't be opened because you don't have permissions to see its contents." I have referenced the following Apple document and it was not helpful in resolving the issue.
The following is the share path that we are trying to mount to in the script:
/home/username
and the following NTFS permissions have been provided to the respectively listed directories.
/home -- All users can Read attributes, Read extended attributes, Read permissions
/home/username -- All users have full control of this folder
Here is the script that we place in /usr/local/sbin:
#!/bin/bash
clear
username="$(whoami)"
IP="$(dig $HOSTNAME +short)"
VOLUMES="/Volumes/Workarea /Volumes/$username"
for volume in $VOLUMES ; do
    [ -d $volume ] && umount -f $volume
done
if [ "$username" != "adminuser" ] && [ "$username" != "setupuser" ]; then
    osascript -e "try" -e "mount volume \"smb://domain.com/Workarea\"" -e "end try"
    osascript -e "try" -e "mount volume \"smb://domain.com/home/"$username\" -e "end try"
fi
killall -u $username Terminal
I am not sure what additional NTFS permissions need to be provided or if we have something that we need to edit in our script since Apple changed some of the SAMBA items in Lion.

Cross posted to here in case there is some additional ideas that come from a different community of Apple folks.

Similar Messages

  • Problems accessing windows share folders with iMac joined to the domain

    Hi,
    Following the Apple Seminar (http://seminars.apple.com/seminarsonline/addamac/apple/index.html?s=300) I've joined an iMac (10.6.2) to a Windows Domain successfully and I can login with my windows account.
    The problem arises when I try to mount a share folder. Mac ask me if I want to access as a guest or as a registered user, and it's really weird since the folder belongs to the windows user. It seems like Mac doesn't use the login account to access the share folders...
    Regards,

    Hi,
    I'm trying to use the Connect to Server > smb://ipaddressoftheserver (smb://192.168.100.1/implementaciones) but it ask me for the authentication again....
    It seems there is a problem with Snow Leopard and AD with .local domains. I've trying this solution:
    http://www.edugeek.net/forums/mac/43879-snow-leopard-ad-integration-woes.html#po st549033
    Regards,

  • [ETL]Could you please help with a problem accessing UML stereotype attributes ?

    Hi all,
    Could you please help with a problem accessing UML stereotype attributes and their values ?
    Here is the description :
    -I created a UML model with Papyrus tool and I applied MARTE profile to this UML model.
    -Then, I applied <<PaStep>> stereotype to an AcceptEventAction ( which is one of the element that I created in this model ), and set the extOpDemand property of the stereotype to 2.7 with Papyrus.
    -Now In the ETL file, I can find the stereotype property of extOpDemand as follows :
    s.attribute.selectOne(a|a.name="extOpDemand") , where s is a variable of type Stereotype.
    -However I can't access the value 2.7 of the extOpDemand attribute of the <<PaStep>> Stereotype. How do I do that ?
    Please help
    Thank you

    Hi Dimitris,
    Thank you , a minimal example is provided now.
    Version of the Epsilon that I am using is : ( Epsilon Core 1.2.0.201408251031 org.eclipse.epsilon.core.feature.feature.group Eclipse.org)
    Instructions for reproducing the problem :
    1-Run the uml2etl.etl transformation with the supplied launch configuration.
    2-Open lqn.model.
    There are two folders inside MinimalExample folder, the one which is called MinimalExample has 4 files, model.uml , lqn.model, uml2lqn.etl and MinimalExampleTransformation.launch.
    The other folder which is LQN has four files. (.project),LQN.emf,LQN.ecore and untitled.model which is an example model conforming to the LQN metamodel to see how the model looks like.
    Thank you
    Mana

  • Firefox 22 -30 Slowly open uploads of Shared Windows Folders with Russian symbol

    Starting with version Firefox 22-30 , slowly open uploads of Shared Windows Folders with Russian symbol. In version Firefox 20 and older, open uploads without freeze in Shared Windows Folders with Russian symbol.Win7/Xp/Vista/Win2008.
    Demonstration problem video 1. Firefox 22 Freeze open uploads of Shared Windows Folders with Russian symbol. + Process Monitor
    http://youtu.be/jXBQ6OmKyeE
    Demonstration problem video 2. Firefox 20 NO Freeze open uploads of Shared Windows Folders with Russian symbol. Firefox 30 Freeze open uploads of Shared Windows Folders with Russian symbol + Process Monitor
    http://youtu.be/DHVRjFmDa8c

    Nightly good version 2013-03-27 (No freeze)
    Nightly bad version 2013-03-28(Freeze open uploads of Shared Windows Folders with Russian symbol)
    Nihgtly bad version 2014-06-29 (Freeze open uploads of Shared Windows Folders with Russian symbol)
    http://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=178a4a770bb1&tochange=962f5293f87f

  • TS4001 Anybody having problems accessing Adwords Exspress login with Safari ?

    Anybody having problems accessing Adwords Exspress login with Safari ?

    Hi jhankins,
    There was a problem yesterday for a brief half an hour to 1 hour, please let us know if you are still facing that issue.
    -Ankit

  • I can't print using airprint from my iPhone 4.  Everything with the phone and the printer and router are up to date.  I can print from my iPad 2 with no problems.  What's wrong with the iPhone 4?

    I can't print using airprint from my iPhone 4.  Everything with the phone and the printer and router are up to date.  I can print from my iPad 2 with no problems.  What's wrong with the iPhone 4?

    I just wanted to leave a note that it's working now. I'm not sure if it was the latest iTunes update that got it working or that i decided to start a new library instead of using the one i had backed up on Windows 8 (it didn't occur to me to check using the old library when i re-installed iTunes). But if anyone is having this problem, it might be worth trying again with a new installation of iTunes to see if the latest update works for you, and if not, try using a fresh library instead of a backup (by fresh library i mean discard your old library completely and start a new library, not just restore as new iPhone, a whole new library).

  • Problem accessing shared folders with SMB from a Windows machine

    When I reboot my Macmini, I cant access the shared folders from any Windows machine. On the Windows machine, I'm being prompted for my password, but event re-entering my password does help to get access.
    The workaround I found is to go to the MacOSX System Preferences, Sharing, File Sharing, Options, and to uncheck and re-check the checkbox Share file and folders using SMB (Windows). Then I can access again the shared forders from a Windows machine and I'm not re-prompted for my password.
    This is quite trooblesome to do that everytime I reboot my Mac. Is anybody experiencing the same pb? Any idea to fix it?
    Also, since Lion, I'm experiencing some connection interruption, especially when copying big files from my Mac to a Windows machine.

    Yes that is basically the only workaround for this problem. By chance do you have a SSD installed in the Mini?
    I had this problem on my MBP when I had a SSD installed. Problem goes away with the original drive or a Seagate XT series drive.
    If you don't have a SSD installed the only other option is to Wipe the drive and reinstall and test (Make a TM backup first so you can restore if the problem continues with the clean Re-Install).
    JosoSG wrote:
    When I reboot my Macmini, I cant access the shared folders from any Windows machine. On the Windows machine, I'm being prompted for my password, but event re-entering my password does help to get access.
    The workaround I found is to go to the MacOSX System Preferences, Sharing, File Sharing, Options, and to uncheck and re-check the checkbox Share file and folders using SMB (Windows). Then I can access again the shared forders from a Windows machine and I'm not re-prompted for my password.
    This is quite trooblesome to do that everytime I reboot my Mac. Is anybody experiencing the same pb? Any idea to fix it?
    Also, since Lion, I'm experiencing some connection interruption, especially when copying big files from my Mac to a Windows machine.

  • Sharing two folders with the same name

    Hi all.
    I have two folders with the same name and I would like to be able to share these under different share names. Problem is, this doesn't seem to be possible.
    For instance, try doing this in File Sharing under Server Preferences:
    * Click +, add /Data/Media
    * Edit permissions on "Media" to permit guest access
    * Click +, add /Volumes/Drobo/Media
    * Edit permissions on "Media" (make sure you click the right one!) to permit guess access.
    This appears on the surface to work, but what it has actually done is to delete the share for /Data/Media. If you exit the File Sharing pane and go back into it again, it will be gone.
    Server Admin has the ability to rename a share's name from AFP,SMB,FTP,etc. but this doesn't appear to help either -- I tried adding the second media first, renaming its shared name to Media2 over in Server Admin, and then adding the first. Server Preferences just deletes the second one.
    Such a basic thing as being able to rename the share from Server Preferences would appear to be enough to get around this, but since Apple didn't make it possible, I have no idea how to proceed.
    Does anyone else have this working, and how did you do it?

    The best way to solve this, would be make sure you use database paraneter GLOBAL_NAME, to change your database from lets say orcl1 to orcl1.mycorpdomain.com, by this you can make sure each database actualy has a different name. Your other database then could be named orcl1.example.com.
    When chaning the display name in EM you might face other issues later on when for instance trying to run a restore using EM for one of these databases.
    Regards
    Rob
    http://oemgc.wordpress.com

  • Login freezes on iMac with Lion after screen sharing with another mac.

    I have an iMac 27" Late 2009 2.8Ghz Intel Core i7 upgraded with Lion 10.7 (11A511).  I have screen sharing enabled on this computer, and I accessed the computer with a 15" MacBook Pro also running Lion of the same version. The screen sharing work.  However, when I exited screen sharing on my MacBook, and attempt to login again on the iMac, the login is stuck after entering the password.
    Is anybody else have similar issues?

    I am having this problem as well. On a late 2009 MPB. I can login to the guest account with no problem and I can also create a new user, but I cant access any of my filevaulted files. This happened after Silverlight caused Safari and everything else to freeze and I had to hard reboot, It's almost like lion is trying to reopen those apps when logging back in and it can't. I reinstalled Lion and repaired disks and disk permissions from the recovery hd. Anyone else??

  • Problem:Accessing the file system with servlets ???

    Hi...
    I have a strange problem with my servlets that run on Win2000 with Apache and 2 Tomcat instances.
    I cannot open files through servlets whereas exactly the same code lines work in local standalone java programm.
    It seems to be somehting like a rights problem...but I dont know what to do.
    thanks for any help
    here are my configuration files for Apache and Tomcat:
    Apache: *******************************************************
    ### Section 1: Global Environment
    ServerRoot "D:/Webserver_and_Applications/Apache2"
    PidFile logs/httpd.pid
    Timeout 300
    KeepAlive On
    MaxKeepAliveRequests 100
    KeepAliveTimeout 15
    <IfModule mpm_winnt.c>
    ThreadsPerChild 250
    MaxRequestsPerChild 0
    </IfModule>
    Listen 80
    LoadModule jk_module modules/mod_jk.dll
    JkWorkersFile conf/workers.properties
    JkLogFile logs/mod_jk.log
    JkLogLevel info
    LoadModule access_module modules/mod_access.so
    LoadModule actions_module modules/mod_actions.so
    LoadModule alias_module modules/mod_alias.so
    LoadModule asis_module modules/mod_asis.so
    LoadModule auth_module modules/mod_auth.so
    LoadModule autoindex_module modules/mod_autoindex.so
    LoadModule cgi_module modules/mod_cgi.so
    LoadModule dir_module modules/mod_dir.so
    LoadModule env_module modules/mod_env.so
    LoadModule imap_module modules/mod_imap.so
    LoadModule include_module modules/mod_include.so
    LoadModule isapi_module modules/mod_isapi.so
    LoadModule log_config_module modules/mod_log_config.so
    LoadModule mime_module modules/mod_mime.so
    LoadModule negotiation_module modules/mod_negotiation.so
    LoadModule setenvif_module modules/mod_setenvif.so
    LoadModule userdir_module modules/mod_userdir.so
    ### Section 2: 'Main' server configuration
    ServerAdmin [email protected]
    ServerName www.testnet.com:80
    UseCanonicalName Off
    DocumentRoot "D:/Webserver_and_Applications/root"
    JkMount /*.jsp loadbalancer
    JkMount /servlet/* loadbalancer
    <Directory />
    Options FollowSymLinks
    AllowOverride None
    </Directory>
    <Directory "D:/Webserver_and_Applications/root">
    Order allow,deny
    Allow from all
    </Directory>
    UserDir "My Documents/My Website"
    DirectoryIndex index.html index.html.var
    AccessFileName .htaccess
    <Files ~ "^\.ht">
    Order allow,deny
    Deny from all
    </Files>
    TypesConfig conf/mime.types
    DefaultType text/plain
    <IfModule mod_mime_magic.c>
    MIMEMagicFile conf/magic
    </IfModule>
    HostnameLookups Off
    ErrorLog logs/error.log
    LogLevel warn
    LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
    LogFormat "%h %l %u %t \"%r\" %>s %b" common
    LogFormat "%{Referer}i -> %U" referer
    LogFormat "%{User-agent}i" agent
    CustomLog logs/access.log common
    ServerTokens Full
    ServerSignature On
    Alias /icons/ "D:/Webserver_and_Applications/Apache2/icons/"
    <Directory "D:/Webserver_and_Applications/Apache2/icons">
    Options Indexes MultiViews
    AllowOverride None
    Order allow,deny
    Allow from all
    </Directory>
    Alias /manual "D:/Webserver_and_Applications/Apache2/manual"
    <Directory "D:/Webserver_and_Applications/Apache2/manual">
    Options Indexes FollowSymLinks MultiViews IncludesNoExec
    AddOutputFilter Includes html
    AllowOverride None
    Order allow,deny
    Allow from all
    </Directory>
    ScriptAlias /cgi-bin/ "d:/webserver_and_applications/root/cgi-bin/"
    <Directory "D:/Webserver_and_Applications/root/cgi-bin/">
    AllowOverride None
    Options Indexes FollowSymLinks MultiViews
    Order allow,deny
    Allow from all
    </Directory>
    IndexOptions FancyIndexing VersionSort
    AddIconByEncoding (CMP,/icons/compressed.gif) x-compress x-gzip
    AddIconByType (TXT,/icons/text.gif) text/*
    AddIconByType (IMG,/icons/image2.gif) image/*
    AddIconByType (SND,/icons/sound2.gif) audio/*
    AddIconByType (VID,/icons/movie.gif) video/*
    AddIcon /icons/binary.gif .bin .exe
    AddIcon /icons/binhex.gif .hqx
    AddIcon /icons/tar.gif .tar
    AddIcon /icons/world2.gif .wrl .wrl.gz .vrml .vrm .iv
    AddIcon /icons/compressed.gif .Z .z .tgz .gz .zip
    AddIcon /icons/a.gif .ps .ai .eps
    AddIcon /icons/layout.gif .html .shtml .htm .pdf
    AddIcon /icons/text.gif .txt
    AddIcon /icons/c.gif .c
    AddIcon /icons/p.gif .pl .py
    AddIcon /icons/f.gif .for
    AddIcon /icons/dvi.gif .dvi
    AddIcon /icons/uuencoded.gif .uu
    AddIcon /icons/script.gif .conf .sh .shar .csh .ksh .tcl
    AddIcon /icons/tex.gif .tex
    AddIcon /icons/bomb.gif core
    AddIcon /icons/back.gif ..
    AddIcon /icons/hand.right.gif README
    AddIcon /icons/folder.gif ^^DIRECTORY^^
    AddIcon /icons/blank.gif ^^BLANKICON^^
    DefaultIcon /icons/unknown.gif
    IndexIgnore .??* *~ *# HEADER* README* RCS CVS *,v *,t
    AddEncoding x-compress Z
    AddEncoding x-gzip gz tgz
    AddLanguage da .dk
    AddLanguage nl .nl
    AddLanguage en .en
    AddLanguage et .et
    AddLanguage fr .fr
    AddLanguage de .de
    AddLanguage he .he
    AddLanguage el .el
    AddLanguage it .it
    AddLanguage ja .ja
    AddLanguage pl .po
    AddLanguage ko .ko
    AddLanguage pt .pt
    AddLanguage nn .nn
    AddLanguage no .no
    AddLanguage pt-br .pt-br
    AddLanguage ltz .ltz
    AddLanguage ca .ca
    AddLanguage es .es
    AddLanguage sv .se
    AddLanguage cz .cz
    AddLanguage ru .ru
    AddLanguage tw .tw
    AddLanguage zh-tw .tw
    AddLanguage hr .hr
    LanguagePriority en da nl et fr de el it ja ko no pl pt pt-br ltz ca es sv tw
    ForceLanguagePriority Prefer Fallback
    AddDefaultCharset ISO-8859-1
    AddCharset ISO-8859-1 .iso8859-1 .latin1
    AddCharset ISO-8859-2 .iso8859-2 .latin2 .cen
    AddCharset ISO-8859-3 .iso8859-3 .latin3
    AddCharset ISO-8859-4 .iso8859-4 .latin4
    AddCharset ISO-8859-5 .iso8859-5 .latin5 .cyr .iso-ru
    AddCharset ISO-8859-6 .iso8859-6 .latin6 .arb
    AddCharset ISO-8859-7 .iso8859-7 .latin7 .grk
    AddCharset ISO-8859-8 .iso8859-8 .latin8 .heb
    AddCharset ISO-8859-9 .iso8859-9 .latin9 .trk
    AddCharset ISO-2022-JP .iso2022-jp .jis
    AddCharset ISO-2022-KR .iso2022-kr .kis
    AddCharset ISO-2022-CN .iso2022-cn .cis
    AddCharset Big5 .Big5 .big5
    AddCharset WINDOWS-1251 .cp-1251 .win-1251
    AddCharset CP866 .cp866
    AddCharset KOI8-r .koi8-r .koi8-ru
    AddCharset KOI8-ru .koi8-uk .ua
    AddCharset ISO-10646-UCS-2 .ucs2
    AddCharset ISO-10646-UCS-4 .ucs4
    AddCharset UTF-8 .utf8
    AddCharset GB2312 .gb2312 .gb
    AddCharset utf-7 .utf7
    AddCharset utf-8 .utf8
    AddCharset big5 .big5 .b5
    AddCharset EUC-TW .euc-tw
    AddCharset EUC-JP .euc-jp
    AddCharset EUC-KR .euc-kr
    AddCharset shift_jis .sjis
    AddType application/x-tar .tgz
    AddType image/x-icon .ico
    AddHandler type-map var
    BrowserMatch "Mozilla/2" nokeepalive
    BrowserMatch "MSIE 4\.0b2;" nokeepalive downgrade-1.0 force-response-1.0
    BrowserMatch "RealPlayer 4\.0" force-response-1.0
    BrowserMatch "Java/1\.0" force-response-1.0
    BrowserMatch "JDK/1\.0" force-response-1.0
    BrowserMatch "Microsoft Data Access Internet Publishing Provider" redirect-carefully
    BrowserMatch "^WebDrive" redirect-carefully
    BrowserMatch "^WebDAVFS/1.[012]" redirect-carefully
    <IfModule mod_ssl.c>
    Include conf/ssl.conf
    </IfModule>
    ScriptAlias /php/ "d:/webserver_and_applications/php/"
    AddType application/x-httpd-php .php
    Action application/x-httpd-php "/php/php.exe"
    Tomcat:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
    <Server port="11005" shutdown="SHUTDOWN" debug="0">
    <!-- Define the Tomcat Stand-Alone Service -->
    <Service name="Tomcat-Standalone">
    <!-- Define an AJP 1.3 Connector on port 11009 -->
    <Connector className="org.apache.ajp.tomcat4.Ajp13Connector"
    port="11009" minProcessors="5" maxProcessors="75"
    acceptCount="10" debug="0"/>
    <!-- Define the top level container in our container hierarchy -->
    <Engine jvmRoute="tomcat1" name="Standalone" defaultHost="localhost" debug="0">
    <!-- Global logger unless overridden at lower levels -->
    <Logger className="org.apache.catalina.logger.FileLogger"
    prefix="catalina_log." suffix=".txt"
    timestamp="true"/>
    <!-- Because this Realm is here, an instance will be shared globally -->
    <Realm className="org.apache.catalina.realm.MemoryRealm" />
    <!-- Define the default virtual host -->
    <Host name="localhost" debug="0" appBase="webapps" unpackWARs="true">
    <Valve className="org.apache.catalina.valves.AccessLogValve"
    directory="logs" prefix="localhost_access_log." suffix=".txt"
    pattern="common"/>
    <Logger className="org.apache.catalina.logger.FileLogger"
    directory="logs" prefix="localhost_log." suffix=".txt"
         timestamp="true"/>
    <!-- Tomcat Root Context -->
    <Context path="" docBase="d:/webserver_and_applications/root" debug="0"/>
    <!-- Tomcat Manager Context -->
    <Context path="/manager" docBase="manager"
    debug="0" privileged="true"/>
    <Context path="/examples" docBase="examples" debug="0"
    reloadable="true" crossContext="true">
    <Logger className="org.apache.catalina.logger.FileLogger"
    prefix="localhost_examples_log." suffix=".txt"
         timestamp="true"/>
    <Ejb name="ejb/EmplRecord" type="Entity"
    home="com.wombat.empl.EmployeeRecordHome"
    remote="com.wombat.empl.EmployeeRecord"/>
    <Environment name="maxExemptions" type="java.lang.Integer"
    value="15"/>
    <Parameter name="context.param.name" value="context.param.value"
    override="false"/>
    <Resource name="jdbc/EmployeeAppDb" auth="SERVLET"
    type="javax.sql.DataSource"/>
    <ResourceParams name="jdbc/EmployeeAppDb">
    <parameter><name>user</name><value>sa</value></parameter>
    <parameter><name>password</name><value></value></parameter>
    <parameter><name>driverClassName</name>
    <value>org.hsql.jdbcDriver</value></parameter>
    <parameter><name>driverName</name>
    <value>jdbc:HypersonicSQL:database</value></parameter>
    </ResourceParams>
    <Resource name="mail/Session" auth="Container"
    type="javax.mail.Session"/>
    <ResourceParams name="mail/Session">
    <parameter>
    <name>mail.smtp.host</name>
    <value>localhost</value>
    </parameter>
    </ResourceParams>
    </Context>
    </Host>
    </Engine>
    </Service>
    <!-- Define an Apache-Connector Service -->
    <Service name="Tomcat-Apache">
    <Engine className="org.apache.catalina.connector.warp.WarpEngine"
    name="Apache" debug="0">
    <Logger className="org.apache.catalina.logger.FileLogger"
    prefix="apache_log." suffix=".txt"
    timestamp="true"/>
    </Engine>
    </Service>
    </Server>
    *** and here is my workers.properties : *******************************
    # workers.properties
    # In Unix, we use forward slashes:
    ps=/
    # list the workers by name
    worker.list=tomcat1, tomcat2, loadbalancer
    # First tomcat server
    worker.tomcat1.port=11009
    worker.tomcat1.host=localhost
    worker.tomcat1.type=ajp13
    # Specify the size of the open connection cache.
    #worker.tomcat1.cachesize
    # Specifies the load balance factor when used with
    # a load balancing worker.
    # Note:
    # ----> lbfactor must be > 0
    # ----> Low lbfactor means less work done by the worker.
    worker.tomcat1.lbfactor=100
    # Second tomcat server
    worker.tomcat2.port=12009
    worker.tomcat2.host=localhost
    worker.tomcat2.type=ajp13
    # Specify the size of the open connection cache.
    #worker.tomcat2.cachesize
    # Specifies the load balance factor when used with
    # a load balancing worker.
    # Note:
    # ----> lbfactor must be > 0
    # ----> Low lbfactor means less work done by the worker.
    worker.tomcat2.lbfactor=100
    # Load Balancer worker
    # The loadbalancer (type lb) worker performs weighted round-robin
    # load balancing with sticky sessions.
    # Note:
    # ----> If a worker dies, the load balancer will check its state
    # once in a while. Until then all work is redirected to peer
    # worker.
    worker.loadbalancer.type=lb
    worker.loadbalancer.balanced_workers=tomcat1, tomcat2
    # END workers.properties
    thanks again

    Hi joshman,
    no I didn't get error messages as the relevant lines for reading/writing where between try statements, but you were where right it was/is just a simple path problem.
    I expected the refering directory without using a path to be the directory where the servlet is in, but it is not !!??
    Do you know if I set this in the setclasspath.bat of tomcat ?
    *** set JAVA_ENDORSED_DIRS=%BASEDIR%\bin;%BASEDIR%\common\lib ***
    thanks again
    Huma

  • Trouble with shares and access to sub folders

    We're attempting to replicate our Netware configuration to a new MacOS 10.4.6 server. On Netware we where able to create a share that was available to all users, however the folders they saw within the share where governed by their access rights within the tree. For example, take the following structure:
    Data --+-- Folder1
    |
    +-- Folder2
    Rights for Folder1 where assigned to Group1 and rights to Folder2 to Group2. All users in Group1 and Group2 could then mount the drive and see the folders that they where a member of.
    We have attempted to replicate this on MacOS as follows:
    Data --+-- Folder1 (ACL Group1 = Read/Write)
    |
    +-- Folder2 (ACL Group2 = Read/Write)
    However, when you mount Data on Mac or Windows it says you have no access rights and won't let you dig down to Folder1 or Folder2. Is there something I'm missing?

    If all users in Group 1 and Group2 have access to
    the root Data folder then that permission will
    propogate down the tree and they will have read
    access to each of the sub folders. If folders within
    suddenly gain everyone RW access then they will be
    able to open and see the folder.
    Thanks, I've solved the problem. I needed all users to have access to the root of the 'volume' but for that not to propogate down the tree. I've found the inheritence settings and that I think has solved the problems.
    You can control this by propagating permissions
    downward from the top level folder. Do this:
    Create a group for everyone who accesses Data called
    DataGroup.
    Add DataGroup to the group list for everyone. (You
    can mass select Users and add the group to everyone
    who needs it at once.)
    Change the Unix group owner of the Data folder to
    DataGroup and set these permissions:
    Owner: admin RW, Group: DataGroup R, Everyone: None
    Open Data and set Folder1 privileges to:
    Owner: admin RW, Group: Group1 RW, Everyone: None
    and propagate these settings to the subfolders. Be
    sure to propagate Group Ownership and Group
    Permissions and Everyone permissions.
    NOTE: This is the traditional *nix way - with ACLs
    you can do this and then fine-grain the control using
    the ACL granting Group 1 Full Control and propagating
    that.
    Now set Folder2 to Group2 etc.
    This allows you access to Data (versus using staff or
    some generic Unix group but those will work too) but
    allows you to control who has access to the
    subfolders. In this case membership in DataGroup only
    grants you access to see the folders - it doesn't
    even guarantee access to any of the subfolders.
    If you want nested folders within Folder1 or Folder2
    you can do the same thing - create a folder owned by
    a specific user and set Group Read access to none and
    propagate that through the subtree. Just be aware
    that propagations that happen above that folder can
    reverse the settings. Always set large and then get
    specific. New Users are granted access to Data by
    adding DataGroup and users access to folders are
    granted or revoked by adding or removing the Group1,
    Group2 etc settings.
    I think that once you get it set how you want and try
    it you'll find that the Data folder is redundant and
    is giving you unnecessary conceptual problems. If you
    make the Folder1, Folder2 etc shares then after a
    user authenticates they will see only the folders
    they have permission to access. If I am in Group1 and
    I authenticate my selection of folders will only be
    folders accessible by Group1 - I will never even see
    Folder2. By grouping them in Data you are adding a
    layer of permissions that is probably not needed. But
    everyone has their own organizational system and
    sometimes it's easier to leave users with what their
    used to using. (I have users that still mount Users
    and navigate to their own folder even though their
    user folder shows up at the login level simply
    because that's the way they've always done it.)
    No there are good reasons to share the Data folder and not the children below. For example, if you are on Windows clients and you wish to map the share to a drive letter you will have no way of doing this if you don't have the containing folder.
    Yes, I understand with ACLs (or at least I think I
    do and have setup a system that works). The problem
    is that new folders get Everyone Read access. Which
    ruins the effective permissions for that folder. I
    need a way of making the default posix permissions
    O=RW,G=None,Everyone=None.
    We have a lot of folders to deal with Folder 1 and
    Folder 2 are only examples. We have about 15 or more
    folders with sub folders that have differing access
    rights. All this we have sorted out except the
    default POSIX permissions for new folders/files.
    You can change Umask default privilege settings but
    DON'T. Well, DON'T unless you're a *nix guru. It
    changes the default for all created files - including
    those created by the system and this can lead to
    serious problems down the road.
    I don't want a whole system default change to umask I want one that works only for people connected via AFP, you would think that would be possible. Similarly I want one for SMB access also.
    If you get this working you will see that despite the
    POSIX settings the ACLs are working. If you really
    need your Unix permissions to be set a certain way
    chuck ACLs and set "Inherit from Parent Folder" in
    AFP and SAMBA. With ACLs on the system will only do
    POSIX settings.
    In the windows world you either use POSIX or ACLs in the mac world you use a combination of both. That can be an asset but it can also be a major problem. If only you could use the inherit setting for POSIX when ACLs where enabled it would solve all these worries.
    Thanks for your time on this.
    Ian

  • Having problem accessing MacMini over network with PC's Windows 7

    Hi all,
    I have a Mac Mini with 10.6.x
    Onec in a while, especially when restart Airport Extreme for upgrade or something else (both are connected with ethernet cable cat5e) ALL PC's on the network having problem accessing Mac Mini Server while All MACs are fine and can access all folders no problem. Usually takes about 3-4 min for PC to connect to server. Then  once it is connected (it loads all folder and files in that current window on the PC) i can go from folder to folder with no delays. However if i close the window with all folders then again i have to wait for around 3 min. to load everything all over again. AFP and SMB are ON. Today i made an experiment and turned SMB off and the problem still excist with the difference that after 3-4 min delay no folders were shown.
    It seems that the PCs have hard time establishing connection with the server which is weird that Macs don't have that problem. It must be something with the setting of Mac MIni. Other wise i have no problem accessing Internet so the routher is working fine. DHCP is ON on the AP Extreme.
    I came across as i was searching for this issue and it seems that authentication - Golden triangle or whatever is called - might be the issue in the whole mess. Do you guys think that this might be the case ?
    The only way i have found out to help is to restart the Router and Server and that usually fix the problem  .
    Could you please help me figure what is going on there?
    Here is the original thread: https://discussions.apple.com/thread/3867559?tstart=0 ( i think i posted in the wrong forum )

    The specified changeip -checkhostname command does not make changes to your configuration. 
    To research the command (and that's entirely your perogative), please use Google or Bing to search for previous discussions and details, or review the provided man page documentation for the command.  (Launch Terminal.app (folder Applications > Utilities) and issue the command man changeip.  You'll see something like this:
    $ man changeip
    changeip(8)               BSD System Manager's Manual              changeip(8)
    NAME
         changeip -- Change service configuration files with hard-coded IP addresses
    SYNOPSIS
         changeip [-v] [-d path] old-ip new-ip [old-hostname new-hostname]
         changeip -checkhostname
         changeip -h
    DESCRIPTION
         changeip is used to manually update configuration records when a server's IP address or hostname changed in a way that affected services were unable to properly process, for example when the server is behind a NAT device and the WAN identity changed.  ...
    Given your response and your concern, consider creating a backup of your disk.  Shut down, boot the installation DVD, and use Disk Utility (from the Utilities menu) in the second screen of the installation process to copy your disk contents to an external storage device.  (Time Machine isn't as good at getting a backup of a server as is a clean backup created while shut down.)  There are descriptions around that detail how to create this backup using Disk Utility.
    There is no DNS server implemented in the Airport Extreme.  The Airport Extreme forwards DNS requests to a DNS server elsewhere.  Few gateway devices contain DNS servers; that these devices request a DNS address tends to be confusing, too.  That address is solicited from the user for use in the DHCP server that many of the available gateway devices provide.
    There is no need for a DNS forwarder, particularly if your server is configured for your LAN.  (Adding a forwarder adds another hop into the whole translation process.  That configuration and that extra hop can be useful when the intermediate DNS server is providing specific, enhanced DNS-related functions, such as security monitoring and logging, or providing a "nanny filter" mechanism.)
    If you are running DNS services on your LAN, then your Airport Extreme DHCP server should be configured to pass out the IP address of your DNS server.
    It would appear that your local box has the default self-hosted DNS, and is not configured to serve LAN DNS (other than for itself).  That's good.  Accordingly, it'll likely be getting good DNS from itself, but will not be getting translations for other hosts on your network.  That's not so good.  When DNS responses are not available, you'll get DNS-level timeouts, and those are usually around 30 seconds each.
    Check your server logs for messages related to the failed connections, and check the Windows file service logs for any errors being generated by the file service.  The log information is most easily available from Console.app, which is a utility in Applications > Utilities folder, or from the Server Admin tool (Applications > Server folder) for DNS, and for the file server component.
    The above is probably going to read like a wall of unfamiliar jargon, so please ignore this and my previous response here, and I'll leave it to somebody else to assist you here.

  • How do I switch remote desktops with lion server screen sharing?

    When I sometimes use the Lion Server screen sharing feature to take over my iMac using my Macbook, I find that I'm not able to switch desktops on the remote computer, i.e. using the three finger swipe.
    Both are running the latest versions of Lion Server.
    Now there MUST be some way to do that right?
    Who knows?

    Hi John, perhaps I did not express myself clearly.
    My desktop iMac is set up with multiple desktops (desktop 1 for system stuff, desktop 2 for mail, messages, skype etc, desktop 3 for Safari and desktop 4 for text proessing, VM-Ware and other work).
    When I work on that machine I'm logged in as one user and use the three finger swipe left and right or the Cmd-1 thru Cmd-4 keys to switch between those desktops.
    I haven't founf how to do that from my a remotely connected MacBook Pro.
    Both of which are running Mountain Lion in the mean time. The iMac runs Mountain Lion Server and the MBP has ML Server installed as well, but nut implemented. Just to be able to use the remote screen...
    Hope this makes my question a bit mre clear...
    Gerard

  • Macbook Wireless Driver Incompatible with Dual Band Access Points & PPTP VPN with MPPE Enabled.

    Configuration:
    Local Client: Macbook Pro 8,1 (Dual boot 10.8.2 & Windows 7 x64)
    Local WLAN AP: WiFi dual band access points (I do not have admin access to)
    ISP: TWC Road Runner
    External VPN Server: Poptop PPTPD server v1.3.4 (I do have admin access to)
    Problem:
    There is a Macbook BCM4331 driver incompatibility that spans across both OS X and Windows 7 when connecting to a PPTP VPN through a local dual band access point.
    The same Macbook (booted into either OS X 10.8 or Windows 7) cannot maintain a ping/connection to the PPTP server when connected to a local dual band (2.4GHZ/5GHZ) WiFi access point.
    Macbook connects and remains connected to the PPTP server (as shown in connection status,) but no traffic will pass through VPN once the connection has "dropped" internet traffic. Flood ping to the VPN server initially replies with expected <30ms ping time. Once internet traffic is passed across VPN, ping fails and traffic stops completely.
    • Any other wifi client machines & OS using same dual band AP can connect to VPN and maintain flood ping to PPTP server and pass all traffic or even split tunnel. I've tested different computers using Windows XP, Windows 7, Android 4.1, iOS 6.0.1 etc. No problems at all.
    • Macbook can maintain flood ping and pass traffic to PPTP server when connected to a different standard 2.4GHZ access point.
    • Macbook can maintain flood ping and pass traffic to PPTP server when connected via Ethernet on same LAN as dual band AP's.
    • Macbook can maintain connection/ping by disabiling MPPE encryption on the PPTP server. Running an unencrypted VPN is not an option for me however.
    • Macbook can maintain connection/ping whenn booted into Windows 7 natively and disabling 2.4 band through Device Manager > Advanced tab > Disable bands > "Disable 802.11g/b".
    To fix this problem, I would propose that Apple allow OS X users to disable 2.4GHZ in OS X. Doing so should allow PPTP + MPPE when connected via dual band routers as it does in Windows 7. I think asking them to rewrite the driver for OS X & Windows 7 is asking too much.
    Credits:
    I have been through so many forums, reconfigured the Macbook, the PPTP server, reformatted, tested and tweaked until my eyes bled. Here is a collection of threads of others with similar problems:
    https://discussions.apple.com/thread/2778039?start=120&tstart=0
    https://discussions.apple.com/thread/3202997?start=0&tstart=0
    https://discussions.apple.com/thread/2136112?start=15&tstart=0
    http://forums.macrumors.com/showthread.php?t=196438
    https://discussions.apple.com/thread/2132652?start=0&tstart=0
    http://comments.gmane.org/gmane.network.poptop/2373
    https://discussions.apple.com/thread/1623154?start=0&tstart=0
    https://discussions.apple.com/message/12514921?messageID=12514921#12514921
    http://forums.macrumors.com/showthread.php?t=1101053
    http://forums.macrumors.com/showthread.php?t=415087
    https://discussions.apple.com/thread/1346301?start=0&tstart=0
    https://discussions.apple.com/thread/2197122?start=0&tstart=0

    I haven't heard anything back yet. I will update if I do.
    Being that Apple takes pride in selling their own computers and writing their own drivers & software to match, the Macbook with OS X 10.8 should be a super polished, finely tuned machine. It's aggravating when I can't do relatively simple things which I can do on any other device & OS:
    If you've read the first post, you know it's not possible to pass PPTP + MPPE on the Macbook Pro 8,1 with OS X 10.6+ or Windows 7 when connected to a dual band AP.
    OS X also imposes a 130mbps limit on the 2.4Ghz band. I have no problems connecting @ 450mbps on 2.4Ghz with Windows 7. The range is much better than 5Ghz as expected when there aren't any neighboring AP's for interference. I've also never received interference with Bluetooth devices.
    There have been a couple times where some things don't plain work right and the flexibility to fix them as an "Apple knows better than the user" policy is restricted. In most cases, perhaps Apple does know better. In this case, there is definitely a problem with the BCM4331 driver. If it "just worked" this topic wouldn't have been created.

  • Problem accessing mounted ntfs partitions

    Hi,
    I have problems accessing ntfs partitions as a non root user. The user trying to acces the partition is in usergroup wheel and has sudo acces.
    /etc/fstab looks like this:
    /dev/sda5 /media/winC ntfs defaults 0 2
    /dev/sdb1 /media/winD ntfs defaults 0 2
    It does not matter where I mount them (e.g. /home/user/media/winC), if i try cd-ing into the directory, it tells me:
    cd /medi/winC
    -bash: cd: /media/winC: Permission denied
    When i try the following, it tells me:
    sudo cd /medi/winC
    sudo: cd: command not found
    which I find a bit strange, but ok.
    Any pointers what I am doing wrong? cd-ing as root works, but i would like to acces it as a normal user too. Using the following options did not work for me:
    rw,suid,dev,exec,auto,users,async
    mount -l tells me the following when using the options stated above:
    /dev/sda5 on /media/winC type ntfs (ro,nosuid,nodev,noexec,relatime,uid=0,gid=0,fmask=0177,dmask=077,nls=utf8,errors=continue,mtf_zone_multiplier=1)
    Thanks for any pointers!

    Trilby wrote:
    You should use ntfs-3g instead of ntfs.  I'm not sure if that will solve this problem, though it might, but it will prevent others.
    As for "sudo cp" failing, that is not odd at all: `cd` is not a program, it is a shell builtin - there is no `cd` binary for sudo to execute.
    Thanks for the explanation. I will try ntfs-3g as soon as I manage to connect to the internet again.

Maybe you are looking for

  • RAM macbook pro 13" feb 2009

    I need to upgrade ram in my macbook pro 13" Feb 2009  I was told to use Newegg website but cant find the exact spec needed for this machine, any suggestions?

  • How can I report an exemption case for warranty?

    I purchsed my 27 inch Imac in Panama (I live in Colombia) and it suddenly started to sound extrange (fans) I re-started it and the weird  sound stopped, but the lower left side of the display is darker now. This happened some months ago but I just co

  • Insert row with same formatted cells

    I am a newbye with Numbers. I have created a spreadsheet with some columns and every cell formatted, such as a list or a box to check. Until now every time I have inserted a new row the system create a row with the same formattated cells, now the sys

  • Jeff Schewe - More capture sharpening examples?

    Jeff, I confess to being a bit frustrated at how difficult it is proving to be to learn how to apply optimal capture sharpening (source+content) in ACR (v. 4.4.1). Yes, I have studied Bruces sharpening book and the CS3 version of Real World Camera Ra

  • MFP Experiences?

    I'm wondering how people's experiences have been with MFP, after enabling it on the wireless controllers. How well does/did it work, has it caused any problems? (And what controller version were you running at the time?) I have Intel 2200BG and 3945A