<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 7-Mode User Administration in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11339#M2606</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I noted that fact in the man pages Richard, I felt that as I was logged in as root I wouldn't have a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bondbhola, yes deleting and recreating with ...passwd.firstlogon.enable=off set works fine as expected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Apr 2013 00:54:39 GMT</pubDate>
    <dc:creator>CHRIS_K_AU</dc:creator>
    <dc:date>2013-04-23T00:54:39Z</dc:date>
    <item>
      <title>7-Mode User Administration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11316#M2596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How do you manage user accounts in 7 mode given the following scenarios: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Enable disabled user account:&lt;/STRONG&gt; &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Controller1&amp;gt; useradmin user list Test3&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Name: Test3 &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Info: &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Rid: 111111 &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Groups: Group1 &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Full Name: &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Allowed Capabilities: login-snmp &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Password min/max age in days: 1/4294967295 &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Status: disabled&lt;/STRONG&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Change user password for first login:&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;When &lt;STRONG&gt;&lt;STRONG&gt;security.passwd.firstlogin.enable&lt;/STRONG&gt; &lt;/STRONG&gt;is set to &lt;STRONG&gt;on&lt;/STRONG&gt; and using the principal of least privilege, how do you change the intial password?&amp;nbsp; Or let me ask, what is required to allow a user to change their password on first login if you are configuring SNMPv3 and only granting login-snmp?&amp;nbsp; Do they need the ability to login through SSH, if so what other capabilities are required for the user to change their password.&amp;nbsp; Let’s say the user only has login-snmp, login-ssh how would they change their password? There is no prompt when I login and I can login through SSH with the account with a status of expired. When I have these capabilities and try passwd , system log states that test needs the cli-passwd capability. If you grant that capability then that account can change any password. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Name: test &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Info: Rid: 11112 &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Groups: Group1 &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Full Name: &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Allowed Capabilities: &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Password min/max age in days: 0/4294967295 &lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Status: expired&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:34:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11316#M2596</guid>
      <dc:creator>ASUNDSTROM</dc:creator>
      <dc:date>2025-06-05T06:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: 7-Mode User Administration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11321#M2598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Since you have not gotten an answer, you may want to ask this question in the &lt;A href="https://forums.netapp.com/community/support" target="_blank"&gt;NetApp Support Community.&lt;/A&gt;&amp;nbsp; The current customers, partners and internal Subject Matter Experts are addressing technical product questions there.&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Feb 2012 19:48:31 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11321#M2598</guid>
      <dc:creator>crocker</dc:creator>
      <dc:date>2012-02-22T19:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: 7-Mode User Administration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11325#M2600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm seeking an answer to this 'problem' also. The closest workarounds I can see are the RSH syntax for passwd or setting the ...passwd.firstlogon.enable off before creating the accounts then turning it back on again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Apr 2013 04:57:20 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11325#M2600</guid>
      <dc:creator>CHRIS_K_AU</dc:creator>
      <dc:date>2013-04-22T04:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: 7-Mode User Administration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11329#M2601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to delete the test1 account and recrate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bhola Gond&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Apr 2013 12:53:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11329#M2601</guid>
      <dc:creator>bondbhola</dc:creator>
      <dc:date>2013-04-22T12:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: 7-Mode User Administration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11335#M2604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The capability cli-passwd only provides the privileges to change the password on the users own account.&lt;/P&gt;&lt;P&gt;It does not provide the ability to change the password on other users accounts.&lt;/P&gt;&lt;P&gt;In order to change the password of other users accounts you need the security context privilege of security-passwd-change-others.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Apr 2013 17:10:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11335#M2604</guid>
      <dc:creator>RichardSopp</dc:creator>
      <dc:date>2013-04-22T17:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: 7-Mode User Administration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11339#M2606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I noted that fact in the man pages Richard, I felt that as I was logged in as root I wouldn't have a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bondbhola, yes deleting and recreating with ...passwd.firstlogon.enable=off set works fine as expected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 00:54:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/7-Mode-User-Administration/m-p/11339#M2606</guid>
      <dc:creator>CHRIS_K_AU</dc:creator>
      <dc:date>2013-04-23T00:54:39Z</dc:date>
    </item>
  </channel>
</rss>

