<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Snapcreator as a mechanism for delegating data protection operations in Data Protection</title>
    <link>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/57002#M3301</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="j-post-author "&gt;&amp;nbsp; &lt;STRONG&gt; &lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" href="https://community.netapp.com/people/magnus.nyvall" id="jive-525791839796084732677" target="_blank"&gt;magnus.nyvall&lt;/A&gt;&amp;nbsp; &lt;/STRONG&gt;&amp;nbsp; Dec 7, 2011 4:01 AM&amp;nbsp;&amp;nbsp; &lt;SPAN class="font-color-meta-light j-thread-replyto"&gt; (&lt;A _jive_internal="true" class="font-color-meta-light localScroll" href="https://community.netapp.com/message/69332#68417" title="Go to message" target="_blank"&gt;in response to rmharwood&lt;/A&gt;) &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;What are the minimum rights for the OM user if you use USE_PROXY=Y?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have only tested "Global Full Control"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to do two things to use DFM Proxy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) create user with global full control&lt;/P&gt;&lt;P&gt;2) Add storage system login credentials, this is where you configure what user ther DFM server will use when communicating with storage&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which of them can i remove and still have all SC functionality?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like I said we only tested "Global Full Control" but the following should be a minimum&lt;/P&gt;&lt;P&gt;DFM.BackupManager.Backup, DFM.BackupManager.Read, DFM.BackupManager.Restore, DFM.Console.Execute, DFM.Core.AccessCheck, DFM.Core.Control, DFM.Core.Delegate, DFM.Database.Read, DFM.Database.Write, DFM.DataSet.Create,&amp;nbsp; DFM.DataSet.Write, DFM.Event.Read, DFM.Event.Write, DFM.Mirror.PolicyControl, DFM.Mirror.Read,&amp;nbsp; DFM.Policy.Delete, DFM.Policy.Read, DFM.Policy.Write,DFM.Schedule.Read&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might even be able to get it to work with just&lt;/P&gt;&lt;P&gt;DFM.Console.Execute,DFM.DataSet.Create,&amp;nbsp; DFM.DataSet.Write, DFM.Event.Read, DFM.Event.Write&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Dec 2011 16:35:21 GMT</pubDate>
    <dc:creator>ktenzer</dc:creator>
    <dc:date>2011-12-13T16:35:21Z</dc:date>
    <item>
      <title>Snapcreator as a mechanism for delegating data protection operations</title>
      <link>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/56979#M3296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Been looking at the SC (3.4.0) framework for a week or so. I am wondering if it is considered to be a useful platform for delegating control of filer operations (snapshots, clones, snapmirror and snapvault updates). Right now I have a handful of users that have to run such operations and as such they have accounts on various filers with the minimum privileges needed to perform such operations. However, the filer RBAC controls are far too wide and I can't limit these operations to particular volumes, for example. I like the idea of using our DFM server to set up a proxy by which all commands go through but I have to provide a simple interface so that snapshots and clones (et cetera) may be run from shell scripts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my research it would appear that a SC server would be required for each platform that needs to initiate such operations. Am I correct in this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It also appears that you cannot configure DFM proxy via the GUI because it insists on a filer's credentials being entered. I have not tried CLI configuration as yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else used this mechanism to delegate control in this manner or am I really trying to use the wrong tool here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any insight or advice would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:40:51 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/56979#M3296</guid>
      <dc:creator>rmharwood</dc:creator>
      <dc:date>2025-06-05T06:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Snapcreator as a mechanism for delegating data protection operations</title>
      <link>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/56984#M3297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Richard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes SC can initiate all APIs through DFM proxy which means users would need access to the scServer or run their own scServer. This is limitted however to things Snap Creator does which I think was clear by your statment. So you cant just send any API or CLI command to DFM server through Snap Creator.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for support in GUI, you are correct in 3.4 it is only supported through CLI. In 3.5 which releases on Jan 12 2012 it will also be fully supported in GUI. We also added RBAC capabilities in SC itself for those who want to control things more granular so that combo + DFM proxy makes an interesting use case &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.netapp.com/5.0.1/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2011 18:31:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/56984#M3297</guid>
      <dc:creator>ktenzer</dc:creator>
      <dc:date>2011-11-29T18:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Snapcreator as a mechanism for delegating data protection operations</title>
      <link>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/56988#M3298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply. If I ever get it working well then perhaps I will document it for everyone's benefit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Dec 2011 20:35:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/56988#M3298</guid>
      <dc:creator>rmharwood</dc:creator>
      <dc:date>2011-12-02T20:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: Snapcreator as a mechanism for delegating data protection operations</title>
      <link>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/56993#M3299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What are the minimum rights for the OM user if you use USE_PROXY=Y?&lt;/P&gt;&lt;P&gt;Cant seem to find any document on that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created one with all of these like a GolbalSnapcreator user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess i can trial end error my way but i am lazy. &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.netapp.com/5.0.1/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which of them can i remove and still have all SC functionality?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DFM.Alarm.Delete, DFM.Alarm.Read, DFM.Alarm.Write, DFM.BackupManager.Backup, DFM.BackupManager.Failover, DFM.BackupManager.Read, DFM.BackupManager.Restore, DFM.ConfigManagement.Delete, DFM.ConfigManagement.Read, DFM.ConfigManagement.Write, DFM.Console.Execute, DFM.Core.AccessCheck, DFM.Core.Control, DFM.Core.Delegate, DFM.Database.Delete, DFM.Database.Read, DFM.Database.Write, DFM.DataSet.Create, DFM.DataSet.Delete, DFM.DataSet.Write, DFM.Event.Read, DFM.Event.Write, DFM.Mirror.PolicyControl, DFM.Mirror.Read, DFM.PerfThreshTemplate.Read, DFM.PerfThreshTemplate.Write, DFM.PerfView.Delete, DFM.PerfView.RealTimeRead, DFM.PerfView.Write, DFM.Policy.Delete, DFM.Policy.Read, DFM.Policy.Write, DFM.Quota.FullControl, DFM.Report.Delete, DFM.Report.Read, DFM.Report.Write, DFM.Resource.Control, DFM.ResourcePool.Provision, DFM.SAN.FullControl, DFM.Schedule.Delete, DFM.Schedule.Read, DFM.Schedule.Write, DFM.SRM.Read, DFM.StorageService.Attach, DFM.StorageService.Delete, DFM.StorageService.Detach, DFM.StorageService.Read, DFM.StorageService.Write, SD.Config.Delete, SD.Config.Read, SD.Config.Write, SD.Snapshot.Clone, SD.Snapshot.Delete, SD.Snapshot.DestroyUnrestrictedClone, SD.Snapshot.DisruptBaseline, SD.Snapshot.Read, SD.Snapshot.Restore, SD.Snapshot.UnrestrictedClone, SD.Snapshot.Write, SD.Storage.Delete, SD.Storage.Read, SD.Storage.Write&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 12:01:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/56993#M3299</guid>
      <dc:creator>magnus_nyvall</dc:creator>
      <dc:date>2011-12-07T12:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Snapcreator as a mechanism for delegating data protection operations</title>
      <link>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/56998#M3300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What are the minimum rights for the OM user if you use USE_PROXY=Y?&lt;/P&gt;&lt;P&gt;Cant seem to find any document on that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created one with all of these like a GolbalSnapcreator user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess i can trial end error my way but i am lazy. &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.netapp.com/5.0.1/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which of them can i remove and still have all SC functionality?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DFM.Alarm.Delete, DFM.Alarm.Read, DFM.Alarm.Write, DFM.BackupManager.Backup, DFM.BackupManager.Failover, DFM.BackupManager.Read, DFM.BackupManager.Restore, DFM.ConfigManagement.Delete, DFM.ConfigManagement.Read, DFM.ConfigManagement.Write, DFM.Console.Execute, DFM.Core.AccessCheck, DFM.Core.Control, DFM.Core.Delegate, DFM.Database.Delete, DFM.Database.Read, DFM.Database.Write, DFM.DataSet.Create, DFM.DataSet.Delete, DFM.DataSet.Write, DFM.Event.Read, DFM.Event.Write, DFM.Mirror.PolicyControl, DFM.Mirror.Read, DFM.PerfThreshTemplate.Read, DFM.PerfThreshTemplate.Write, DFM.PerfView.Delete, DFM.PerfView.RealTimeRead, DFM.PerfView.Write, DFM.Policy.Delete, DFM.Policy.Read, DFM.Policy.Write, DFM.Quota.FullControl, DFM.Report.Delete, DFM.Report.Read, DFM.Report.Write, DFM.Resource.Control, DFM.ResourcePool.Provision, DFM.SAN.FullControl, DFM.Schedule.Delete, DFM.Schedule.Read, DFM.Schedule.Write, DFM.SRM.Read, DFM.StorageService.Attach, DFM.StorageService.Delete, DFM.StorageService.Detach, DFM.StorageService.Read, DFM.StorageService.Write, SD.Config.Delete, SD.Config.Read, SD.Config.Write, SD.Snapshot.Clone, SD.Snapshot.Delete, SD.Snapshot.DestroyUnrestrictedClone, SD.Snapshot.DisruptBaseline, SD.Snapshot.Read, SD.Snapshot.Restore, SD.Snapshot.UnrestrictedClone, SD.Snapshot.Write, SD.Storage.Delete, SD.Storage.Read, SD.Storage.Write&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 12:01:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/56998#M3300</guid>
      <dc:creator>magnus_nyvall</dc:creator>
      <dc:date>2011-12-07T12:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Snapcreator as a mechanism for delegating data protection operations</title>
      <link>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/57002#M3301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="j-post-author "&gt;&amp;nbsp; &lt;STRONG&gt; &lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" href="https://community.netapp.com/people/magnus.nyvall" id="jive-525791839796084732677" target="_blank"&gt;magnus.nyvall&lt;/A&gt;&amp;nbsp; &lt;/STRONG&gt;&amp;nbsp; Dec 7, 2011 4:01 AM&amp;nbsp;&amp;nbsp; &lt;SPAN class="font-color-meta-light j-thread-replyto"&gt; (&lt;A _jive_internal="true" class="font-color-meta-light localScroll" href="https://community.netapp.com/message/69332#68417" title="Go to message" target="_blank"&gt;in response to rmharwood&lt;/A&gt;) &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;What are the minimum rights for the OM user if you use USE_PROXY=Y?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have only tested "Global Full Control"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to do two things to use DFM Proxy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) create user with global full control&lt;/P&gt;&lt;P&gt;2) Add storage system login credentials, this is where you configure what user ther DFM server will use when communicating with storage&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which of them can i remove and still have all SC functionality?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like I said we only tested "Global Full Control" but the following should be a minimum&lt;/P&gt;&lt;P&gt;DFM.BackupManager.Backup, DFM.BackupManager.Read, DFM.BackupManager.Restore, DFM.Console.Execute, DFM.Core.AccessCheck, DFM.Core.Control, DFM.Core.Delegate, DFM.Database.Read, DFM.Database.Write, DFM.DataSet.Create,&amp;nbsp; DFM.DataSet.Write, DFM.Event.Read, DFM.Event.Write, DFM.Mirror.PolicyControl, DFM.Mirror.Read,&amp;nbsp; DFM.Policy.Delete, DFM.Policy.Read, DFM.Policy.Write,DFM.Schedule.Read&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might even be able to get it to work with just&lt;/P&gt;&lt;P&gt;DFM.Console.Execute,DFM.DataSet.Create,&amp;nbsp; DFM.DataSet.Write, DFM.Event.Read, DFM.Event.Write&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Dec 2011 16:35:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Data-Protection/Snapcreator-as-a-mechanism-for-delegating-data-protection-operations/m-p/57002#M3301</guid>
      <dc:creator>ktenzer</dc:creator>
      <dc:date>2011-12-13T16:35:21Z</dc:date>
    </item>
  </channel>
</rss>

