ALERT! The community will be read-only starting on April 19, 8am Pacific as the migration begins. Read more for important details.
ALERT! The community will be read-only starting on April 19, 8am Pacific as the migration begins.Read more for important details.
Absent Member.
Absent Member.

OES linux "rights" command, [Public] user and Windows woes

Hey all,

I've been trying to figure out a solution for this, and although I thought I figured it out, it ends up I can't seem to figure it out. Hear me out.

We run an automated ZCM imaging system, and part of that is the ability to have any user authenticate on successful image using the Novell client. Once this is done, the first login should start installing a series of bundles/applications.

As MS Office 2010 is a rather large install, I keep the files/folders stored on a NSS volume, aptly named:

//oesserver/media/nss/APPS/MICROSOFT/MS Office 2010 SP2 - Admin Install

I would like ALL users to have access to this directory but since we run on a weird container layout, and our licensing permits for a rather large number of installs, I wanted to give the [Public] user read+filescan rights to each server's /media/nss/APPS/MICROSOFT/MS Office 2010 SP2/ directory, so regardless of where you are mapping with any user, that user would then have access to said folder.

If I use either the iManager plugin or directly using the Novell client method of applying [Public] as a trustee, it works, and the client can see the folder.

I have over 30 servers that each have the identical path, so in my sleuthing I found the OES command to perform: rights

So I performed the following command:

rights -f "/media/nss/APPS/MICROSOFT/MS Office 2010 SP2 - Admin Install" -r rf trustee [Public]

If I then show the results, there are successful:

rights show

The problem, however, is that within Windows, from any login, when I right-click the folder and check the trustees, I do not see that user in the list, and in return, that user has no access to the directory.

If I then run my command to remove the rights from the OES server:

rights -f /media/nss/APPS/MICROSOFT/MS\ Office\ 2010\ SP2\ -\ Admin\ Install/ -r none delete [Public]

And then run a "rights show" again, the Public user is removed correctly.

What I can't seem to figure out is why the command will allow me to set trustee rights to [Public], that "rights show" will validate that the rights are currently assigned, but from a Windows perspective I have no access to that directory.

I have done a "rights show" on the drive when assigning the rights from the Novell client and/or iManager, and there is NO difference in how "rights show" see the [Public] user listed.

Has anyone else ever seen this?

If I specify a user in my tree, it works correctly on both ends.

rights -f "/media/nss/APPS/MICROSOFT/MS Office 2010 SP2 - Admin Install" -r rf trustee username.ou.o.tree_name

rights show will then show me the appropriate trustee, and the user can see the path in Windows.

This restriction seems limited to the [Public] user, but I have no idea how to do this properly.

I'd like to avoid doing it by hand, because I want the ability to script all my changes and remotely and efficiently.

Any advice?

Labels (2)
3 Replies
Absent Member.
Absent Member.

I recall a problem with the rights command on Linux, not sure if it has been fixed. Is your server fully patched?

As a workaround, can you grant rights to the tree? This way any logged in user would have access to the folder.


Novell Knowledge Associate
Please don't send me support related e-mail unless I ask you to do so.
Absent Member.
Absent Member.

First, check if the trustee_database.xml are in /media/nss/APPS/._NETWARE/

To resolve any matter synchronize the NSS metadata with the trustee database (used by NCP); run the following command:
ncpcon nss resync=VOLUME_NAME

Finally, verify the attributes are correct in the trustee_database.xml file.

Check TID 7001930 (

I hope this help
Fleet Admiral
Fleet Admiral

On 16/06/2014 18:34, Uwe Buckesfeld wrote:

> I recall a problem with the rights command on Linux, not sure if it has been fixed. Is your server fully patched?

Are you thinking of TID 7014932? That's an issue with OES11 SP2 which is
fixed by installing the April 2014 OES11SP2 Hot Patch for NCL.


Novell Knowledge Partner

If you find this post helpful and are logged into the web interface,
please show your appreciation and click on the star below. Thanks.
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.