Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
ACLs are hard!

Adbot
ADBOT LOVES YOU

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Shaggar posted:

the way permissions work is correct because each item needs a security descriptor otherwise the client has to compute it from parent descriptors every time.

also sounds like you've got a bad setup or something cause I've never had a problem w/ ntfs or file shares. Also wrt the home directories you are doing it really wrong somehow. you've got a shared drive and each folder is somehow flagged as a my documents link (which is a special link) instead of being a regular folder. Ive never seen user homes implemented in a way that would do what you're seeing.

i'm p sure the documents and other "special" shell folders are just defined by the contents of the desktop.ini file within, still. it's not a special folder attribute or anything, just data read from a file within the container

so yeah, you could cause that by having some idiotic folder redirection setting that put everyone's "document" folders in the same place, rather than the bog standard of giving each profile a subfolder based on the username

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

online friend posted:

it sucks, actually.

yeah it gobbles a large one, and yet it's better than all the alternatives

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

error1 posted:

The idiotic folder redirection is built right into AD, actually


It's the established standard since forever, both because lots of software doesn't support UNC so you need to map the path as a drive letter, and if generally want users to see as little as possible of the world outside of their little box of user data.

The site specific fuckup might be to redirect My Documents directly to the user folder via GPO instead of a Documents subdirectory but it seems like a very common annoyance. The best part is that it didn't appear on windows 2003, but the new behaviour has been the same since Vista, and still exists in Windows 10 / Server 2016 afaik. I haven't bothered looking into it too much, I just use a different utility than explorer.exe to browse those user directories.

lmao. what's it like back in 2004? you know there's going to be a black president in four years? crazy right?

but seriously, that thing in ad is legacy as hell, you don't use that for a user profile or shell folders unless you want poo poo to break. you use folder redirection via gpo to map the profile folder to a unc path or if you have RDS/VDI use user profile disks like shaggs said

aslong as you don't override the defaults and push everyone's documents folder into the same location what was described simply doesn't happen and windows handles the appropriate folder ACLs on its own

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i don't know what the hell you're using that doesn't support unc paths but functions properly on windows 7, but it probably sucks

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

Shaggar posted:

Linux users: "you cant, like, own data man. security is bad!"

literally RMS.txt

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
lmao nice

how does that show up for used space on the volume?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
yeah, they're still a popular hiding place for malware, since you can execute code from them too. for a while in the xp days av scanners wouldn't check for alternate streams

Adbot
ADBOT LOVES YOU

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
wait, so you want to worsen performance during the most common use case to improve it for occasional admin tasks?

how frequently are you touching acls anyway? everything should be defined with security groups, you're not fiddling with permissions for individual accounts

  • Locked thread