2011-04-26 07:37 AM
I want to set up all details for cifs vfilers from a script non-interactive.
The Filerview vFiler wizard asks for the root password, and creates the root user.
The root user is also created if you run the "passwd" command interactivly in the vfiler
I thougth that the Set-NaVfilerPassword Cmdlet was designed for this, but it just returns
without creating the root user.
How can this be done? I need a working root user for other setup needs.
2011-04-26 11:06 AM
You are correct, the Set-NaVfilerPassword cmdlet should set the password for the vfiler root user. I have a few questions:
- What version of Data ONTAP are you using?
- Are you creating the vfiler using the New-NaVfiler cmdlet? If not, how are you creating the vfiler?
- Are you using any other Set-NaVfiler* cmdlets in your process? If so, which ones?
***Edit (with a little more information)***
This is a known issue with ONTAP where the API that Set-NaVfilerPassword uses does not update the password if the root user already exists. There is no short-term resolution plan. You can workaround this by connecting directly to the vfiler and using Set-NaUserPassword.
2011-04-27 01:35 AM
I have tested with Toolkit 1.3 against 22.214.171.124 and 8.0.1P3 (and also earlier releases) with the same result,
no root user.
$naCred = (get-credential root)
Connect-NaController fas2040a -credential $naCred
New-NaVol -name testvf_root -aggregate aggr0 -size 100m
New-NaVol -name testvf_vol1 -aggregate aggr0 -size 100m
Set-NaQtree /vol/testvf_vol1 -SecurityStyle "ntfs"
New-NaVfiler testvf -addresses 10.1.1.100 -storage /vol/testvf_root,/vol/testvf_vol1
Set-NaVfilerPassword testvf secret1234
Set-NaVfilerProtocol testvf -DisallowProtocols nfs,iscsi,rsh
Invoke-NaSsh vfiler run testvf secureadmin setup -q ssh 768 512 768
$ipb = New-Object NetApp.Ontapi.Filer.Vfiler73.IpbindingInfo
$ipb.Interface = "e0a"
$ipb.Ipaddress = "10.1.1.100"
$ipb.Netmask = "255.255.255.0"
Set-NaVfilerAddress testvf -IpBindingInfo $ipb
Set-NaVfilerDns testvf -DnsDomain test.local -DnsServerAddresses 10.1.1.50
2011-04-27 08:02 AM
Thank you for the sample script. With that, I was able to reproduce the behavior you are describing. The Set-NaVfilerPassword cmdlet makes use of the vfiler-setup API, which allows us to set up several properties of the vfiler (Set-NaVfilerAddress, Set-NaVfilerAdminHost, Set-NaVfilerDns, and Set-NaVfilerNis also make use of vfiler-setup). In order for the vfiler-setup API to create the root account, the IP bindings must be passed along in the same API call. This is not currently how the Set-NaVfilerPassword cmdlet works, so the root account is not created.
The good news is, the forthcoming toolkit 1.4 includes a cmdlet Invoke-NaSystemApi which allows you to send raw API requests to Data ONTAP. I've copied a sample script below that I have used to successfully create a vfiler with a root account.
Because of the issue I mentioned in my previous post, it is recommended that any subsequent password changes are accomplished by connecting directly to the vfiler and using Set-NaUserPassword.
I hope that helps,
2011-04-28 03:00 AM
Invoke-NaSystemApi is a great addition to the kit.
Does this mean that it is not possible to do this with PowerShell only before tollkit 1.4 is out?
(any estimates on when 1.4 will be out?)
2011-04-28 09:11 AM
Hi, Sjalla. We weren't aware that ONTAP's vfiler-setup API had this bug you identified, so thanks for pointing it out. Steven's suggestion should work with Toolkit 1.4, due "soon". You might also try his suggestion of connecting directly to the vfiler and issuing Set-NaUserPassword. I've also captured an enhancement request to add a vfiler setup cmdlet to a future release that would let you more fully configure a vfiler in one call.