I'm failing in my attempt to create a .webloc file on all users desktop that the students cannot delete. I've create a DMG in composer with the .webloc file and the permissions set to 444. I deploy the DMG through Casper with FUT and FEU (either as a policy or with Casper Remote) and the file is placed correctly in the existing users Desktops and in the User Template folder. I check the permissions of the file on a non-Admin users desktop and it shows "-r--r--r--@ 1 john.doe wheel". I login as the non-Admin user and I am able to delete the file from my desktop.
What am I missing? I'm thinking it has to do with the extended attributes denoted by the @ at the end of the permissions, but I'm not exactly sure where to go from there.
