Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Edit GUID for Group? ACLs from old server no good

Hi, we're trying to upgrade from an old server running OSX Server 10.4.11 to a new Mac Mini running Lion Server. Our 'hopes & dreams' were to be able to keep everything the same so we could just switch over and keep working with no interuption.


Our needs are pretty basic, with only using 6-8 local user accounts (no network accounts), 2-3 main groups, and mostly file sharing and VPN.


So I tried to setup the users and groups with the same long names, shortnames, passwords and UID/GIDs as our old server. Then for our main old shared files drive, we cloned the entire contents to our new RAID drive using SuperDuper, making sure to check 'retain ACLs'. We were 'hoping' to retain all of the ACLs so we wouldn't have to reapply them to thousands and thousands of files/folders. Even with only a couple groups and not too many ACLs, it would still be a pain.


Unfortunately, when I examing the permissions for files & folders on the new drive, instead of the group short names for the ACE's it is listing a long number which I believe is a GUID?!? (instead of the group name 'sales' it might say 'A4688EB67-6478-AADE-AA97-006545897979' for the User or Group). But the actual ACE's applied are correct, so those did in fact stay intact.


- So am I understanding correctly that setting the same GIDs for the groups was not enough, there was a hidden 'GUID' that I was not aware of that is now out-of-sync?


- If so, is there any way to edit this number for a group so that the ACLs will find the proper groups again?


- If THIS is possible, how would I find the GUIDs for the old groups in Tiger Server so I could port them over???


- Any other options other than resetting all of the ACLs from scratch???


THANKS!

Posted on Feb 27, 2013 8:30 PM

Reply
Question marked as Best reply

Posted on Feb 28, 2013 4:26 PM

Sorry, was easier than I thought. Just haven't worked on the server in a while.


If it helps anyone for whom this isn't obvious, I exported the users & groups from the Tiger server using Workgroup Manager, then imported them into our Lion Server. This brings all the proper GUIDs with it and now all of our ACLs look correct.


Note to self: somtimes the easy method actually works (with all the differences, I wouldn't have been certain the Tiger users could be imported directly in).

1 reply
Question marked as Best reply

Feb 28, 2013 4:26 PM in response to YoKenny

Sorry, was easier than I thought. Just haven't worked on the server in a while.


If it helps anyone for whom this isn't obvious, I exported the users & groups from the Tiger server using Workgroup Manager, then imported them into our Lion Server. This brings all the proper GUIDs with it and now all of our ACLs look correct.


Note to self: somtimes the easy method actually works (with all the differences, I wouldn't have been certain the Tiger users could be imported directly in).

Edit GUID for Group? ACLs from old server no good

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.