Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

editing files on Server 2008 messes up permissions

I've run into a problem that's a bit baffling for me.


We've got several macs in our office all running 10.7.2. All of these macs connect to a windows 2008 server over SMB.


We're not having any problems connecting to the shares and getting to files, where we are running into problems is that when one of these macs saves changes to a file, the file gets a random account added to it's ACL that isn't part of our Active Directory. It's showing up as "Account Unknown(S-1-5-88-3-448)" and it gets added regardless of who edits the file or which computer the editing is done on.


This account is set to Deny and has no priviledges whatsoever on the file and is causing other users to no longer be able to edit the file.


If I go in on a windows machine and remove the offending account from the ACL on the file, it begins working properly again.


This has only started happening since we upgraded to 10.7.


Anyone have any ideas?

iMac, Mac OS X (10.7.2)

Posted on Jan 23, 2012 2:28 PM

Reply
7 replies

Feb 25, 2015 7:55 AM in response to ghardin137

I am also having this issue. We have Macs on the latest OS joined to our Active Directory domain, and connecting to a Windows 2003 server share. When the Mac users are editing/copying files on the share or adding new files, an unknown permission S-1-5-88-3-448 gets added to the security or ACL of the shared folder. These files are for internal dev websites, and once the S-1-5-88-3-448 permission gets added you will get a log in prompt when trying to browse the page. Once you go to the server and remove the permission everything works normally again. We have been able to recreate one instance of this happening by downloading a picture from the internet and saving it directly to the file share. If we download the file locally to the mac first, and then copy it to the file share it does not seem to modify the permission list.


The Windows share has the following permissions.


Local admin group: Full Control

Domain group: Modify - The mac users are part of this group

System: Full Control


Any suggestions would be appreciated. This problem has been happening for months and is very frustrating.

editing files on Server 2008 messes up permissions

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.