<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cmode 8.3 multi-protocol in a multi-domain setup in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Cmode-8-3-multi-protocol-in-a-multi-domain-setup/m-p/99709#M20266</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have joined the 8.3 C-Mode simulator to a domain called A.DOMAIN.NET, additionally there is a LDAP binding for mapping linux accounts with AD accounts. This works perfect for accounts, which are in the same domain (a.domain.net), but unfortunately we have two separate domain forests with trusts between. The main part of the users are in different domains&amp;nbsp;(e.g. in b.domain.net or c.domain.net) in the other forest:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="23-01-2015 11-56-26.jpg" border="0" src="https://community.netapp.com/t5/image/serverpage/image-id/1901iFCB3B3B0B07C361D/image-size/large?v=mpbl-1&amp;amp;px=-1" title="23-01-2015 11-56-26.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The mapping from a b.domain.net AD user to the UID works in theory, BUT Cmode cannot list the windows group memberships, so it stops completely:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;diag secd authentication show-creds -node node1 -vserver vserver1 -win-name username1@b.domain.net&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Vserver: vserver1 (internal ID: 2)&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Error: Get user credentials procedure failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] Windows user 'EUNET\username1' mapped to UNIX user&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'username1'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] Determined UNIX id 50665 is UNIX user 'username1'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1] Connecting to LDAP (Active Directory) server&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; adserver.a.domain.net (0.0.0.0)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1] Failed to initiate Kerberos authentication. Trying NTLM.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp; 10] Connected to LDAP (Active Directory) service on&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; adserver.a.domain.net&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp; 10] Using a new connection to adserver.a.domain.net&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;**[&amp;nbsp;&amp;nbsp;&amp;nbsp; 17] FAILURE: Cannot get credentials for SID&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;**&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'S-1-5-21-329046322-854245398-839522115-1235216'. Cannot&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;**&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; determine AD domain name for 'EUNET'&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Error: command failed: Failed to get user credentials. Reason: "SecD Error: cannot find domain mapping".&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand the mapping of a UID to a Windows AD account is not working, as Cmode is expecting that the user should be in the joined domain A.DOMAIN.NET. Mapping rules are not solving this problem, as the users are in different domains and it would not solve the group membership resolving.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it has something to do with the mult-domain / trust setup - any AD/LDAP specialists knows more? Feedback would be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; regards&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jan 2015 10:23:47 GMT</pubDate>
    <dc:creator>philofiler</dc:creator>
    <dc:date>2015-01-26T10:23:47Z</dc:date>
    <item>
      <title>Cmode 8.3 multi-protocol in a multi-domain setup</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Cmode-8-3-multi-protocol-in-a-multi-domain-setup/m-p/99709#M20266</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have joined the 8.3 C-Mode simulator to a domain called A.DOMAIN.NET, additionally there is a LDAP binding for mapping linux accounts with AD accounts. This works perfect for accounts, which are in the same domain (a.domain.net), but unfortunately we have two separate domain forests with trusts between. The main part of the users are in different domains&amp;nbsp;(e.g. in b.domain.net or c.domain.net) in the other forest:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="23-01-2015 11-56-26.jpg" border="0" src="https://community.netapp.com/t5/image/serverpage/image-id/1901iFCB3B3B0B07C361D/image-size/large?v=mpbl-1&amp;amp;px=-1" title="23-01-2015 11-56-26.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The mapping from a b.domain.net AD user to the UID works in theory, BUT Cmode cannot list the windows group memberships, so it stops completely:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;diag secd authentication show-creds -node node1 -vserver vserver1 -win-name username1@b.domain.net&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Vserver: vserver1 (internal ID: 2)&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Error: Get user credentials procedure failed&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] Windows user 'EUNET\username1' mapped to UNIX user&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'username1'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0] Determined UNIX id 50665 is UNIX user 'username1'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1] Connecting to LDAP (Active Directory) server&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; adserver.a.domain.net (0.0.0.0)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1] Failed to initiate Kerberos authentication. Trying NTLM.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp; 10] Connected to LDAP (Active Directory) service on&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; adserver.a.domain.net&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp; 10] Using a new connection to adserver.a.domain.net&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;**[&amp;nbsp;&amp;nbsp;&amp;nbsp; 17] FAILURE: Cannot get credentials for SID&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;**&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'S-1-5-21-329046322-854245398-839522115-1235216'. Cannot&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;**&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; determine AD domain name for 'EUNET'&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Error: command failed: Failed to get user credentials. Reason: "SecD Error: cannot find domain mapping".&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand the mapping of a UID to a Windows AD account is not working, as Cmode is expecting that the user should be in the joined domain A.DOMAIN.NET. Mapping rules are not solving this problem, as the users are in different domains and it would not solve the group membership resolving.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it has something to do with the mult-domain / trust setup - any AD/LDAP specialists knows more? Feedback would be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; regards&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2015 10:23:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Cmode-8-3-multi-protocol-in-a-multi-domain-setup/m-p/99709#M20266</guid>
      <dc:creator>philofiler</dc:creator>
      <dc:date>2015-01-26T10:23:47Z</dc:date>
    </item>
  </channel>
</rss>

