Re: Office 2008 Files: Read Only, POSIX, ACLs Frustration!



Thanks Bill for the info. In the morning I'll post the ACL list from the
server. However I do have some questions regarding your setup:

What do you mean by <any group>? A local group? An AD group? Or am I
supposed to fill in that blank with the group that I want to manage, for
example:

Mac HD:Sales Dept

Owner: LocalAdminAcct
Group: admin (ie the local admin group)
Everyone: None

ACLs:
Full Control: LocalAdminAcct (same as what's shown above in POSIX)
Read/Write: MYDOMAIN\Sales
Read/Write: MYDOMAIN\Domain Admins
Read Only: MYDOMAIN\Interns

I know this sounds like a simple question that I am asking you about (ie
setting permissions for a folder).. but I have just been going nuts regarding
this Read Only thing that only appears in Office 2008, which is why I'm
trying to dig a bit deeper to find out if the cause isn't simple POSIX and
ACL permissions, but instead something dastardly that Office 2008 is trying
to do.

However your statement that:

The reason I have this setup is because no network user or group with
network users in it should *ever* have Full Control (Ownership) of any
files or folders or permissions problems will be prevalent for non-owners.

DEFINITELY intrigues me because that is not a standard I have been following
with diagnosing this problem, so I'm going to give that a try when I get to
work in the morning. I have been a Full Control kinda tester with network
account access instead of a Read/Write tester so far.


"William Smith [MVP]" wrote:

Decker 12 wrote:

I wish to lock down this folder, so I set POSIX permissions to Owner:
Decker12, Read/Write, Group: Sales, Read/Write, Everyone: None.

This is what I do for my server permissions (recreating from memory at
home):

Owner: <a local account on the server>
Group: <a local group on the server>
Everyone: None

ACLs:
Full Control: <same local account on the server>
Read/Write: <any group>
Read/Write: <any group>
Read only: <any group>
Read only: <any group>
Read only: Everyone from directory service, not local (if needed)

ACLs should always override standard permissions.

The reason I have this setup is because no network user or group with
network users in it should *ever* have Full Control (Ownership) of any
files or folders or permissions problems will be prevalent for non-owners.

How are your permissions set? To illustrate your setup you can take a
screen shot and post it on <http://www.imageshack.us/> for free and
without creating an account.


--

bill

Entourage Help Page <http://entourage.mvps.org/>
Entourage Help Blog <http://blog.entourage.mvps.org/>
YouTalk <http://nine.pairlist.net/mailman/listinfo/youtalk>
Twitter: follow <http://twitter.com/meck>

.



Relevant Pages

  • Re: Domain Users Cant Print to Networked Printer
    ... You might want to just set up a printer server and install it on your clients ... that way so you can control the permissions. ... remove the user from Domain Admins, that user can no longer print. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Need help with setting security permissions for IE hosted dll
    ... How to run a user control assembly hosted on an Internet Information Server ... permissions than would normally be granted to the zone the assembly belongs ...
    (microsoft.public.dotnet.security)
  • Re: win2k / win2k3 adminpak issue
    ... of the parent. ... To control this behavior see ... Microsoft MVP Windows Server - Active Directory ... > with incorrect permissions on the newly created home directory (in my ...
    (microsoft.public.win2000.active_directory)
  • Re: New User Not in GAL, Recipient Policy Not Applied
    ... Run setup /forestprep and setup /domainprep on the server to re-configure ... Exchange schema. ... Reboot the SBS server. ... looking at the permissions the Exchange Enterprise Servers ...
    (microsoft.public.windows.server.sbs)
  • Re: Permissions on a home directory
    ... jonathanr wrote: ... > users home directories live was rebuilt to 2003 Server. ... Don't give users full control - modify is enough. ... > Permissions the user is reflected as having all the permissions ...
    (microsoft.public.win2000.security)