macOS Mojave with server 5.7.1file sharing Group permissions problem :-(

hi

i have macOS Mojave with server 5.7.1 on Mac pro(Late 2013).

I'm running an updated server for the latest version.

To my question I did not find an answer through Google ...


I do several tests before moving the server to work.

The test on the server is performed from several computers, mainly from operating system 10.12.


I set up 3 users (A + B + C) and 2 groups (E + F) to check permissions Unfortunately permissions do not work properly.

And there seems to be a problem with the ACL and the permissions do not pass automatically.

The entrance was examined in two situations: AFP + SMB.


for example:

When User A logs on to the server and builds a folder / file, checking permissions on the file from the server is saved to User A and not to the Group Name (Group E).

Group: wheel - Permission: read only

All: everyone - permission: read only.


When user B enters the server and builds a folder / file, checking permissions on the file from the server is saved to user name B and not to the group name (group E).

Group: wheel - Permission: read only

All: everyone - permission: read only.



Arrange permissions through: System Prepernces / File Sharing and manual permissions changes: Apple Premissions to Enclosed Items.

Everything works out ... until the next user change.


I would be happy for help an experienced server user


Best regards

Benny

MacBook Air, macOS Sierra (10.12.6), Macintosh Plus,PB 400Hhz black, PB 867, iMac G3, OSX Server5

Posted on Oct 8, 2018 9:18 AM

Reply
Question marked as Top-ranking reply

Posted on Jan 15, 2019 7:35 PM

Hey guys I found this related information from high sierra server that helped me and it appears to work for keeping inherited permissions.


Firstly enable ACL permissions for SMB shares with the following command.



Sharing modification via terminal to engage ACLs



sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.smb.server AclsEnabled -bool YES


Then set up inheritance permissions on the parent holder with the following command. This should recursively go through your share and apply the relevant permissions.



sudo chmod -R +a "group:REPLACE_WITH_YOURGROUP_NAME:allow readattr,writeattr,readextattr,writeextattr,readsecurity,list,search,add_file,add_subdirectory,delete_child,file_inherit,directory_inherit" REPLACE_WITH_PATH_TO_PARENT_SHARED_FOLDER

118 replies

Mar 30, 2019 12:40 PM in response to andrefromflorianopolis

Saying Apple's focus is no longer on server because everyone is going to the cloud seems speculative to me. Just had a post deleted for that kind of speculation. Guess it's all in what you say.


Half of my client base could never use the "cloud" for anything but administrative work and some basic media sharing. That's not speculation, but fact. I've been running Apple servers since AppleShare IP. The Apple base was always media and content creators in my region. Big files.


Freenas doesn't seem to have a problem using Unix as a file server OS. Provides a good OS alternative to MacOS and cheaper hardware. The current version of Freenas will run as far back as a 2009 Mac mini. That's a current OS on that old mini.

May 17, 2019 10:36 AM in response to Benny2g

Hi


I had exactly the same problem. And it was solved by typing the command lines described above. Thanks to all of you on this forum. However I have another issue: everytime I update a shared file, a directory is created. So I let you imagine how many directories I have after a full week...


For example I use everyday an excel file which is called Freelance.xlsx and when I edit it then save it, a folder called Freelance.xlsx.sb-9063f676-Gk1NBI is created (the letters after .xlsx change everytime). Inside this folder I can find a small file without extension. Name is E1A23200, weight is 59ko. (Name change everytime also). It's like a temporary folder but it never disappear.


Any idea about this problem? Does someone know how to avoid the folder creation or at least hide automatically those new folders?


Thanks again for you help guys,



May 17, 2019 12:23 PM in response to zygoatt

This is an Office issue. I had some success with fiddling with the Autosave options and switching from AFP to SMB (even though I would prefer to use AFP for a number of reasons).


Here's a rabbit hole for you to go down:


https://social.technet.microsoft.com/Forums/ie/en-US/50d3d7fb-f9c1-49b3-86e3-f9ede62b33d0/mac-2016-word-when-saving-creates-a-folder-example-nameoffolderdocxsb98c2cb88xxxxxx?forum=Office2016forMac

May 23, 2019 1:18 PM in response to carlsb

Running macOS 10.14.4 (no Server app) on an 11,3 MBP with no OD configured, just sharing accounts. Using the internal SSD (APFS) for the OS and to host FileMaker Pro databases. An external Thunderbolt HFS+ (Journaled) RAID5 consisting of rotational 7200RPM drives hosts the file shares and backup destinations. Another external rotational drive for the security software, also hosted on the server.


This setup is working well enough that I will now start upgrading clients from 10.11/10.12. Mac Pro towers make great servers on the cheap because adding drives is easy, but now, the 6Gbps interface is showing its age. (4) drives, striped, (24 Gpbs max). So the laptop and external RAID is a great setup! Built-in screen and keyboard/trackpad, built-in battery backup/power conditioner, whatever add-on you want and with an external RAID formatted as HFS+ Journaled, you still get lots of sharing power. I'd stay away from Thunderbolt 2 RAIDs and go with USB-3 if possible. Have had issues with Thunderbolt 2 and Macs sleeping when they aren't supposed to (use Amphetamine.app to keep awake), causing drive drop offs. Drives RAID5 crazy, RAID4 is more tolerant in that situation but USB-3 is best.


Connectivity is both AFP and SMB. For clients I tend to lock in AFP because Adobe apps are problematic with SMB and Adobe doesn't officially support working off file shares (unless you are using something like Facilis) so with no support from Adobe I stick with AFP and have no issues. The server has (2) NICs, each with their own VLAN. No issues.


No issues deleting folders/modifying files.


Here's a sample share point set up in the, Sharing, System Preference. Then configured using TinkerTool System.


Permissions for the Admin group.


Permissions for the Staff group.


With all of this, folders within the share can still have custom permissions. Such as having a project folder with staff access but that folder having a nested folder that only allows access to a specific user. Just like the macOS Sierra Server days! 😎

May 24, 2019 10:14 PM in response to Kinneytr

Hi Kinney


I have a similar issue but on Mojave after I migrated from Snow Leopard using Migration Assistant. I just migrated system and Network settings and one standard user. I created the administrative user from scratch using my Apple ID. This is just on an iMac and not Mac OS Server but it really sounds the same.


The shared folders migrated but I found I could no longer edit sharing permissions nor remove shared folders in System Preferences > Sharing.


I contacted Apple Care but they seemed clueless and suggested I wipe the machine and start again from scratch which I am reluctant to do as it is a brand new computer which I spent a lot of time setting up. They say:


"When you used the migration assistant to migrate the use, you have

bought the old Open Directory to the new computer and it seems to have

issues.


Removing / replacing the Open Directory is not recommended


Erasing and reinstalling macOS clean, setting up all users manually and using Time

Machine application (definitely not any assistants) to recover just the

user data (nothing else) is recommended"


Do you think the Directory Utility steps you listed will help without creating issues elsewhere?


The only thing I need to do is reset Sharing to nothing so I can create the shared folders from scratch.


Thanks


May 29, 2019 10:54 AM in response to Benny2g

Hi just adding my voice to this ongoing debacle. I have a small production company and we share all of our files from one server. With Mojave we can no longer save files that have been opened remotely, we have to save them locally and then copy them over manually after the file has been closed (i.e. Photoshop PSD, Numbers, etc). I had this problem in the past and the fix was updating my ACLs, but now it seems I don't have the option to do that.


I do most of my rendering/editing on a custom built PC now... thinking now that I am more comfortable with Windows 10 I may just build a Windows server. Honestly never thought I'd be more into Microsoft than Apple :(

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

macOS Mojave with server 5.7.1file sharing Group permissions problem :-(

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.