<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RBAC - Clustered Data ONTAP in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/RBAC-Clustered-Data-ONTAP/m-p/109006#M22707</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to create a RBAC Rule where in user should have a full admin access on a system manager level but have a readonly access on CLI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to do the following but got that message, that same user can be a part of two different roles:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;security&amp;gt; login create -user-or-group-name rbacv1 -application http -authmethod password -role admin&lt;BR /&gt;iceage::security&amp;gt; login create -user-or-group-name rbacv1 -application ontapi -authmethod password -role admin&lt;/P&gt;&lt;P&gt;iceage::security&amp;gt; login create -user-or-group-name rbacv1 -application ssh -authmethod password -role readonly&lt;/P&gt;&lt;P&gt;Error: User "rbacv1" is already defined with role "admin". Adding a login for this user with a different role (readonly) is not supported.&lt;/P&gt;&lt;P&gt;iceage::security&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Suggestations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;,Sheel&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 23:27:47 GMT</pubDate>
    <dc:creator>sheelnidhig</dc:creator>
    <dc:date>2025-06-04T23:27:47Z</dc:date>
    <item>
      <title>RBAC - Clustered Data ONTAP</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/RBAC-Clustered-Data-ONTAP/m-p/109006#M22707</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to create a RBAC Rule where in user should have a full admin access on a system manager level but have a readonly access on CLI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to do the following but got that message, that same user can be a part of two different roles:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;security&amp;gt; login create -user-or-group-name rbacv1 -application http -authmethod password -role admin&lt;BR /&gt;iceage::security&amp;gt; login create -user-or-group-name rbacv1 -application ontapi -authmethod password -role admin&lt;/P&gt;&lt;P&gt;iceage::security&amp;gt; login create -user-or-group-name rbacv1 -application ssh -authmethod password -role readonly&lt;/P&gt;&lt;P&gt;Error: User "rbacv1" is already defined with role "admin". Adding a login for this user with a different role (readonly) is not supported.&lt;/P&gt;&lt;P&gt;iceage::security&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Suggestations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;,Sheel&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 23:27:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/RBAC-Clustered-Data-ONTAP/m-p/109006#M22707</guid>
      <dc:creator>sheelnidhig</dc:creator>
      <dc:date>2025-06-04T23:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: RBAC - Clustered Data ONTAP</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/RBAC-Clustered-Data-ONTAP/m-p/109083#M23048</link>
      <description>&lt;P&gt;Hi Sheel,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you try doing it from Oncommand System Manager itself ? As it is more easier and infact i am not a CLI fan , &amp;nbsp;Please go through KB to find more information&amp;nbsp;&lt;A href="https://kb.netapp.com/index?page=content&amp;amp;id=1013627&amp;amp;pmv=print&amp;amp;impressions=false" target="_blank"&gt;https://kb.netapp.com/index?page=content&amp;amp;id=1013627&amp;amp;pmv=print&amp;amp;impressions=false&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.netapp.com/t5/image/serverpage/image-id/3488i3FC22997541789FB/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="OCSM2.png" title="OCSM2.png" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2015 09:49:26 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/RBAC-Clustered-Data-ONTAP/m-p/109083#M23048</guid>
      <dc:creator>NAYABSK</dc:creator>
      <dc:date>2015-08-26T09:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: RBAC - Clustered Data ONTAP</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/RBAC-Clustered-Data-ONTAP/m-p/109087#M23050</link>
      <description>&lt;P&gt;Hi Sheel -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Despite the syntax of the command, which is somewhat confusing, you are mixing elements that are independent of each other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the "security login create" command you need to specify two elements at a minimum. &amp;nbsp;First is the access method (http, ssh, etc.) and second is the authentication method when a user tries access via that method. &amp;nbsp;These two elements are tied together in a pair and associated to the user, and obviously there can be multiple pairs of access/authentication created.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can optionally specify a "role" which is tied only to the user, not the combination of user and access/authentication style. &amp;nbsp;The role lists what the user can do once they get access by any of the methods allowed. &amp;nbsp;And yes, both the documentation and the command syntax aren't explicitly clear that the role is tied only to the user [ well - technically the user and the SVM ]. &amp;nbsp;For any given SVM a user can only have one role. &amp;nbsp;Once a user is granted access via authentication by any mechanism, then they get the rights identified in the single role associated to the user in that SVM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One possible way to accomplish what you want might be to allow access with different roles via both the target SVM and the cluster itself. &amp;nbsp;You could grant needed access with default role "vsadmin" at the SVM level and then access to the Cluster at a "readonly" level via other means.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on your sample commands though I see you want to do this at the cluster level, given your choice of applications. &amp;nbsp;At that level only you can't limit "capability" based on mechanism used to access the cluster. &amp;nbsp;If you think about it this makes sense. &amp;nbsp;If you given someone full access, you given them full access. &amp;nbsp;Even if you could limit to readonly access via SSH, I just do the same thing I want via a ZAPI call and totally ignore your restriction on SSH such that the restriction doesn't accomplish anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would&amp;nbsp;need to move to multiple user names to accomplish this security difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bob Greenwald&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2015 12:52:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/RBAC-Clustered-Data-ONTAP/m-p/109087#M23050</guid>
      <dc:creator>bobshouseofcards</dc:creator>
      <dc:date>2015-08-26T12:52:59Z</dc:date>
    </item>
  </channel>
</rss>

