<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Login over SSH -  missing required capability in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Login-over-SSH-missing-required-capability/m-p/99703#M20264</link>
    <description>&lt;P&gt;It is the same - looks like it doesn't even recognize password. I am 100% sure password entered was correct, because I changed it with 'passwd' 10s before:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[xxx: sshd_2:info]: Failed password for splunkuser from xxxxxxxxxxx&amp;nbsp;port 60446ssh2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And when we have login with key, we got:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[xxx:useradminx.unauthorized.user:warning]: User 'splunkuser' denied access - missing required capability: 'login-ssh'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jan 2015 13:41:05 GMT</pubDate>
    <dc:creator>rozle_palcar</dc:creator>
    <dc:date>2015-01-23T13:41:05Z</dc:date>
    <item>
      <title>Login over SSH -  missing required capability</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Login-over-SSH-missing-required-capability/m-p/99551#M20232</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On one of our systems (FAS2040, DOT 8.1.3) we started to get errors about missing 'login-ssh' capability. Even if we create new user with administrative privileges we can't connect over SSH. Only&amp;nbsp;'root' and 'administrator' users are capable of connecting to system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is overview of one of users with which we have problems:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;User:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Name: splunkuser&lt;BR /&gt;Info:&lt;BR /&gt;Rid: 131081&lt;BR /&gt;Groups: Administrators&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Group:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Name: Administrators&lt;BR /&gt;Info: Members can fully administer the filer&lt;BR /&gt;Rid: 544&lt;BR /&gt;Roles: root,admin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Roles:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Name:&amp;nbsp;&amp;nbsp;&amp;nbsp; admin&lt;BR /&gt;Info:&amp;nbsp;&amp;nbsp;&amp;nbsp; Default role for administrator privileges.&lt;BR /&gt;Allowed Capabilities: login-*,cli-*,api-*,security-*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what could be problem? I tried to manually add 'login-ssh' role to this and other users, but it is the same. I also tried creating new user, but we hit same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On partner node there is the same configuration of users, groups and roles and everything is working ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Rozle&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2015 14:42:20 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Login-over-SSH-missing-required-capability/m-p/99551#M20232</guid>
      <dc:creator>rozle_palcar</dc:creator>
      <dc:date>2015-01-21T14:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Login over SSH -  missing required capability</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Login-over-SSH-missing-required-capability/m-p/99702#M20263</link>
      <description>&lt;P&gt;First, login directly to the filer and then try SSH from the unix host.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2015 13:29:55 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Login-over-SSH-missing-required-capability/m-p/99702#M20263</guid>
      <dc:creator>MOHIT_FUJITSU</dc:creator>
      <dc:date>2015-01-23T13:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Login over SSH -  missing required capability</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Login-over-SSH-missing-required-capability/m-p/99703#M20264</link>
      <description>&lt;P&gt;It is the same - looks like it doesn't even recognize password. I am 100% sure password entered was correct, because I changed it with 'passwd' 10s before:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[xxx: sshd_2:info]: Failed password for splunkuser from xxxxxxxxxxx&amp;nbsp;port 60446ssh2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And when we have login with key, we got:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[xxx:useradminx.unauthorized.user:warning]: User 'splunkuser' denied access - missing required capability: 'login-ssh'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2015 13:41:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Login-over-SSH-missing-required-capability/m-p/99703#M20264</guid>
      <dc:creator>rozle_palcar</dc:creator>
      <dc:date>2015-01-23T13:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: Login over SSH -  missing required capability</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Login-over-SSH-missing-required-capability/m-p/99719#M20269</link>
      <description>&lt;P&gt;Your splunkuser role is messed up...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to follow the splunk document for the app for splunk to make sure that you give it the rights perms for the app to work properly.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2015 15:33:10 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Login-over-SSH-missing-required-capability/m-p/99719#M20269</guid>
      <dc:creator>JGPSHNTAP</dc:creator>
      <dc:date>2015-01-23T15:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: Login over SSH -  missing required capability</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Login-over-SSH-missing-required-capability/m-p/135758#M29847</link>
      <description>&lt;P&gt;Noticed the same issue for me too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User created in administrator group&amp;nbsp;couldn't login while it can on the partner node without issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upon all comparisions, noticed this change in options for 'security.admin.authentication'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not working :&amp;nbsp;security.admin.authentication nsswitch&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;working one : security.admin.authentication internal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;changed this option to internal and could see user loggin in without any issues and resolves the problem.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 21:23:09 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Login-over-SSH-missing-required-capability/m-p/135758#M29847</guid>
      <dc:creator>Vidhs</dc:creator>
      <dc:date>2017-11-02T21:23:09Z</dc:date>
    </item>
  </channel>
</rss>

