Does the "cli-cifs" privilege limit an ONTAP user to read only privileges?    I'd like to restrict a user to the ability to view cifs shares but not the ability to make any changes.   



DATA ONTAP 8.1.4P9 7-Mode




Re: cli-cifs?

no, it will allow access to the entire cifs family of commands. It is very difficult to create read-only access to the filers. They can view the shares using "computer management" on their workstation and connecting to the filer.

Re: cli-cifs?

Thank you for the response.   Then what is the difference between the following two privileges?





I thought the same thing you mentioned, but then I discovered documentation that includes the cli-cifs* privilege which I would think allows access to the entire subset of cifs commands.

Re: cli-cifs?

I'm pretty sure that if you just specify cli-cifs without the *, the user could only use "cifs" which won't give them any results.

Re: cli-cifs?

[ Edited ]

Would love to find some documentation that validates your statement.   Best I can find is the following:



"The format for this is cli-* , which means allow all the commands and subcommands. (cli-<command> just means the command and NO subcommands.) "


But then, as you mentioned, just allowing the capability to run the "cifs" command (no other arguments) should effectively do nothing except provide the help output for the cifs command.    Yet, I see in the following in the messages file when a user attempts to execute "cifs shares":


"User 'testuser' denied access - missing required capability:  'cli-cifs'"