<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Security Groups unable to login to cluster on NetApp 9.4 in Ask The Experts</title>
    <link>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146316#M348</link>
    <description>&lt;P&gt;Thanks Vijay,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as stated in my comments for Marcus it's able to display all the Groups Memberships that this particular account is part of.&lt;/P&gt;
&lt;P&gt;I've also opened a support request as well and will update the thread with the solution.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Jan 2019 07:23:06 GMT</pubDate>
    <dc:creator>SHASHIKG87</dc:creator>
    <dc:date>2019-01-31T07:23:06Z</dc:date>
    <item>
      <title>AD Security Groups unable to login to cluster on NetApp 9.4</title>
      <link>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146150#M335</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm trying to setup Active Directory access across my NetApp environment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Created a domain tunnel which had CIFS enabled&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; security login domain tunnel create -vserver&amp;nbsp;SVM101 (CIFS enabled)&lt;/P&gt;
&lt;P&gt;2. Added user name with ssh, ontapi, http&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; security login create -vserver&amp;nbsp;nas101 DOMAIN\username -application ssh -authentication-method domain&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN&gt;security login create -&lt;/SPAN&gt;vserver&lt;SPAN&gt;&amp;nbsp;nas101 DOMAIN\username -application ontapi -authentication-method domain&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; security login create -vserver&amp;nbsp;nas101 DOMAIN\username -application http -authentication-method domain&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. Now both ssh, GUI works perfectly fine for this username&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4. But when I try to add a security group this doesn't seem to work, no members of that security groups are unable to login.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;5. Added Group Nmae&amp;nbsp;with ssh, ontapi, http&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;security login create -vserver&amp;nbsp;nas101 DOMAIN\GROUP-NAME -application ssh -authentication-method domain&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;security login create -vserver&amp;nbsp;nas101 DOMAIN\GROUP-NAME -application ontapi -authentication-method domain&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;security login create -vserver&amp;nbsp;nas101 DOMAIN\GROUP-NAME -application http -authentication-method domain&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'm not sure what exactly is the problem here as individual ad accounts are working but not group accounts.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;NetApp Version&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Release 9.4.P1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any articles related&amp;nbsp;to this would be of great help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;IMP:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;services dns show -vserver&amp;nbsp;abc101(SVM)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;has proper DNS, name servers, domains defined.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ntp server show&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;has proper AD DC's configured.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Shashi&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 08:16:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146150#M335</guid>
      <dc:creator>SHASHIKG87</dc:creator>
      <dc:date>2019-01-24T08:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: AD Security Groups unable to login to cluster on NetApp 9.4</title>
      <link>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146301#M345</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you confirm the filer see the groups correctly and you input it in the same way?&lt;/P&gt;
&lt;PRE&gt;set diag; secd authentication show-creds -node NODE  -vserver  VSERVER -win-name DOMAIN\USER&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gidi&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 14:55:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146301#M345</guid>
      <dc:creator>GidonMarcus</dc:creator>
      <dc:date>2019-01-30T14:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: AD Security Groups unable to login to cluster on NetApp 9.4</title>
      <link>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146311#M346</link>
      <description>&lt;P&gt;Hi Shashi,&lt;/P&gt;
&lt;P&gt;There are few things we can check &lt;BR /&gt;1) Do not add Active Directory group accounts in ONTAP that have a common (sub)set of users&lt;BR /&gt;eg. when an Active Directory group is assigned the "admin" role and an user from that group is assigned a another role in ONTAP.&lt;/P&gt;
&lt;P&gt;2) Remove the Active Directory groups from ONTAP, and add them back with the domain identifier in upper case&lt;BR /&gt;eg. If the domain is "DOMAIN" and user is "user1", the admin account configured at ONTAP as "domain\user1"&lt;/P&gt;
&lt;P&gt;3) we can check if we are able to the user information from DC:&lt;BR /&gt;::&amp;gt; set d -c off&lt;BR /&gt;::*&amp;gt; diag secd authentication show-creds -node &amp;lt;node_hosting_lif&amp;gt; -vserver &amp;lt;svm&amp;gt; -win-name &amp;lt;domain\username&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem could be with the PAM&amp;nbsp; modeule or with the DC connections. With debug logging done in PAM and in secd along with packet traces we can find why authentication for a user from the group added to security login is failing.&lt;/P&gt;
&lt;P&gt;I would suggest to open a support ticket for further investigation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Vijay&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 03:29:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146311#M346</guid>
      <dc:creator>Vijay_ramamurthy</dc:creator>
      <dc:date>2019-01-31T03:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: AD Security Groups unable to login to cluster on NetApp 9.4</title>
      <link>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146315#M347</link>
      <description>&lt;P&gt;Thanks Marcus,&lt;/P&gt;
&lt;P&gt;I ran this command and it's able to show all windows user DOMAIN\username and list all Domain Memberships that this account is part of.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It also displayed the security group that is been used for providing ssh, ontapi and http access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: Individual AD user accounts added still works perfectly. Only Security Group accounts failing to authenticate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Shashi&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 07:21:00 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146315#M347</guid>
      <dc:creator>SHASHIKG87</dc:creator>
      <dc:date>2019-01-31T07:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: AD Security Groups unable to login to cluster on NetApp 9.4</title>
      <link>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146316#M348</link>
      <description>&lt;P&gt;Thanks Vijay,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as stated in my comments for Marcus it's able to display all the Groups Memberships that this particular account is part of.&lt;/P&gt;
&lt;P&gt;I've also opened a support request as well and will update the thread with the solution.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 07:23:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146316#M348</guid>
      <dc:creator>SHASHIKG87</dc:creator>
      <dc:date>2019-01-31T07:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: AD Security Groups unable to login to cluster on NetApp 9.4</title>
      <link>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146317#M349</link>
      <description>&lt;P&gt;Welcome Shashi.&lt;/P&gt;
&lt;P&gt;Since the show-creds command worked , SVM-&amp;gt; DC connections are fine.&lt;/P&gt;
&lt;P&gt;I would suggest to try the option 1) and 2) which i provided in my previous post and check if that resolves the issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Vijay&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 07:58:26 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Ask-The-Experts/AD-Security-Groups-unable-to-login-to-cluster-on-NetApp-9-4/m-p/146317#M349</guid>
      <dc:creator>Vijay_ramamurthy</dc:creator>
      <dc:date>2019-01-31T07:58:26Z</dc:date>
    </item>
  </channel>
</rss>

