Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
The OS that shagged me
fiquebem
I'm working on an upgrade from TS 5.5 to 6.5 on Windows 2003 EE for a couple of weeks now. It's been a struggle, as I come from the UNIX world. For example, changing the permissions has been too much for me to tackle in the short time I was given. We wanted to use TS Groups but, after much chagrin, found out that, until TS 6.7, we can't use "setaccess" with TS Groups (in the Submit filter). See below what someone from Interwoven Support told me.
S.
------------------------------------
I have talked to our engineers and it turned to be a bug in TeamSite server. A bug #61459 has been filed and I have linked your case to it.
Here is the bug description:
On Windows, if setaccess to a non-os group (teamsite group) in submit.cfg, it is actually set to the globalgroup. So nobody in the group other than the owner can access the file.
The fix for the bug has been rolled into TS6.7. Can you workaround this issue without using setaccess in submit.cfg until TS6.7 release?
------------------------------------
Find more posts tagged with
Comments
Migrateduser
Yes, well, it's not an easy life to work on a Windows platform, but what is your specific question?
Current Environments:
(1,2) TS 6.5 on W2K3
(3) Vignette V7 Portal on Solaris 9
fiquebem
We've migrated from TS 5.5 to 6.5 alright, but my boss wants me to fix the "permissions" now. Isn't that scary? It's such a drag, especially on Windows and the bug related to the TS Groups. On UNIX, logging in as root, one can navigate through and change all the directories from the command prompt. But on Windows, even an Administrator can have trouble. On Windows, in addition to user and group ownership, there are ACLs that may not apply to the owners at all.
Here's what I think I'll need to do:
1. Use iwchgroup to change the group of a workarea to a TS Group
2. Use Windows Explorer to change the owner of each file/directory in the workarea to myself (I am a Master and have Administrator access), so I can run the command below in the workarea
3. CACLS /t /g EVERYONE:f (set the ACL of each item so that EVERYONE has full access)
Hopefully there will be adequate security. Hopefully TS will use the workarea-sharing group to allow access to group members only.
Any suggestions are welcome.
Thanks,
S.
Migrateduser
I'll try to look at easier ways to do this, but do you have the 2003 EE resource kit (I think that's what it's called, anyway)? IMHO, it's Microsoft's way of saying, "Sorry we're not UNIX, but here are some tools to make life a bit less painful." Seriously, there are some decent tools in there and I believe there are a few things that would help with mass-changing of file ownership/permissions.
Dave
Current Environments:
(1,2) TS 6.5 on W2K3
(3) Vignette V7 Portal on Solaris 9
Gregg Faus
For mass changing of ACL's I would recommend the resource kit command:
SubInAcl
. If you are looking for an even more robust product, check out the sourceforge project SetAcl (
http://setacl.sourceforge.net
). This product is extremely power and isn't prone to the bug in XCACLS/CACLS where you cannot properly set inheriting permissions.
fiquebem
Thanks for lending a hand!
Here’s what I did for each workarea:
1. Created a distinct TS group for the workarea
2. Used the TS iwchgroup command to change the group of the workarea to the TS Group that’s supposed to share it
3. Added my Windows Administrator/TS Master userid to the almight TeamSite Web Preview group. Without that, I couldn't even navigate under the workarea (without the TS GUI).
4. As you suggested, used the “subinacl” command to give ownership of all files/directories in the workarea to my userid and give Everyone full access. First:
subinacl /errorlog=d:\temp\subinaclerrors.log /subdirectories * /owner=mydomain\myuserid /perm
Then:
subinacl /errorlog=d:\temp\subinaclerrors.log /subdirectories * /grant=everyone
I finally went home around 4:30 a.m. When I returned to work this morning, there were complaints -- people were not having trouble through the TS GUI, but couldn't get through to subdirectories in their workareas using Windows Explorer! Rats!
I ended up adding all users to the TeamSite Web Preview -- now everyone can get through from both Windows Explorer and ContentCenter. But there are no more workarea-related access restrictions :-(.
Looks like TS doesn't work with the Everyone group too well. In addition to the owner, do I need to set the primary group for each file/directory? What else can I do?
Sniff! Sob!
S.