<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP cache TTL in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123508#M26469</link>
    <description>&lt;P&gt;Hello Friend,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I work for NetApp doing ONTAP9 architecture and migration planning.&amp;nbsp; The short answer is:&amp;nbsp; Some people adjust the cache values, and it depends on how it will affect your environment based on LDAP server health/load, LDAP structure, NFS load, latency, etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before adjusting it down, I'd say ensure your LDAP infrastructure and latency between the storage controller to LDAP is very good.&amp;nbsp;&amp;nbsp;Read up&amp;nbsp;on&amp;nbsp;LDAP server best practices on pg 40 of&amp;nbsp;the Name Services Best Practices guide:&amp;nbsp; &lt;A href="http://www.netapp.com/us/media/tr-4379.pdf" target="_blank"&gt;http://www.netapp.com/us/media/tr-4379.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pgs 53 through 55 detail all the default and recommended cache values, there is also the generic&amp;nbsp;point of contacting support before&amp;nbsp;endeavoring to adjust the&amp;nbsp;TTL.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this helped out or answered your question, be sure to hit the Kudos / Mark as Answered&amp;nbsp;button &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hadrian Baron&lt;/P&gt;&lt;P&gt;Practice Architect&lt;/P&gt;</description>
    <pubDate>Thu, 22 Sep 2016 17:16:12 GMT</pubDate>
    <dc:creator>hadrian</dc:creator>
    <dc:date>2016-09-22T17:16:12Z</dc:date>
    <item>
      <title>LDAP cache TTL</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123506#M26468</link>
      <description>&lt;P&gt;Hello all!&amp;nbsp;That's a question for those of you that have configured&amp;nbsp;your C-Mode filer with LDAP authentication. The default value for the LDAP cache is 86400sec which means 24h:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;::*&amp;gt; diag secd cache show-config -node NodeA -cache-name ldap-username-to-creds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current Entries: 0&lt;BR /&gt;Max Entries: 512&lt;BR /&gt;Entry Lifetime: 86400&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wondering if anybody has tweaked this setting to be less than 24h, preferably something like 15min. If yes, was there any unexpected behaviour by the filer or is everything good? FYI, The filer I manage is an AFF8080 with CDOT 8.3.2P5. Thanks in advance for any response.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2016 16:22:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123506#M26468</guid>
      <dc:creator>gpallis</dc:creator>
      <dc:date>2016-09-22T16:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP cache TTL</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123508#M26469</link>
      <description>&lt;P&gt;Hello Friend,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I work for NetApp doing ONTAP9 architecture and migration planning.&amp;nbsp; The short answer is:&amp;nbsp; Some people adjust the cache values, and it depends on how it will affect your environment based on LDAP server health/load, LDAP structure, NFS load, latency, etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before adjusting it down, I'd say ensure your LDAP infrastructure and latency between the storage controller to LDAP is very good.&amp;nbsp;&amp;nbsp;Read up&amp;nbsp;on&amp;nbsp;LDAP server best practices on pg 40 of&amp;nbsp;the Name Services Best Practices guide:&amp;nbsp; &lt;A href="http://www.netapp.com/us/media/tr-4379.pdf" target="_blank"&gt;http://www.netapp.com/us/media/tr-4379.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pgs 53 through 55 detail all the default and recommended cache values, there is also the generic&amp;nbsp;point of contacting support before&amp;nbsp;endeavoring to adjust the&amp;nbsp;TTL.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this helped out or answered your question, be sure to hit the Kudos / Mark as Answered&amp;nbsp;button &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hadrian Baron&lt;/P&gt;&lt;P&gt;Practice Architect&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2016 17:16:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123508#M26469</guid>
      <dc:creator>hadrian</dc:creator>
      <dc:date>2016-09-22T17:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP cache TTL</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123532#M26473</link>
      <description>&lt;P&gt;So, I wrote the mentioned TR as well as TR-4073.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hadrian is right - it's very much an "it depends" scenario.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep in mind the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- When you increase the cache lifetime, that means we store stuff longer. Storing stuff longer = faster lookups, but less accurate because it's not "up to the minute."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- When you decrease the cache lifetime, we flush more often, which means more accurate and up to date info, but more processing on the cluster nodes and the secd process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also keep in mind that there are caches at the node level aside from secd that store credentials. These are also covered in TR-4379.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2016 15:20:00 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123532#M26473</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2016-09-23T15:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP cache TTL</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123582#M26483</link>
      <description>&lt;P&gt;Hello. Apologies for the late response. Yeah, what you explain makes absolute sense and it's what one would expect. I just wanted to see how other fellow sys admins manage this situation when users are added and removed into AD/LDAP groups in a kind of a frequent basis and what their experiences were in case they reduced the LDAP related caches TTL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The latency between the filer and the AD servers is extremelly low as they all run in a 10Gb LAN. Plus the CPU utilisation is very low (less than 10% average as far as I can see from the current and historical data in our monitoring system).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The two documents you mentioned are awesome.&amp;nbsp;Thanks for sharing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 14:17:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123582#M26483</guid>
      <dc:creator>gpallis</dc:creator>
      <dc:date>2016-09-26T14:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP cache TTL</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123668#M26498</link>
      <description>&lt;P&gt;Hello again! I modified the following secd cache TTLs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;ldap-userid-to-creds&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;ldap-username-to-creds&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;down to 20'. But&amp;nbsp;this change doesn't seem to be reflected when adding a user to an AD group after that time. The user gets a permission denied when trying to access a share via NFS (CIFS is fine).&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;I 've read again paragraph 5.10 from&amp;nbsp;&lt;SPAN&gt;TR-4379 which explains all the different caches, but couldn't identify what I am doing wrong. Is there anything that I am missing here? Thank you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 19:46:52 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123668#M26498</guid>
      <dc:creator>gpallis</dc:creator>
      <dc:date>2016-09-28T19:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP cache TTL</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123677#M26499</link>
      <description>&lt;P&gt;Likely the nblade/NAS layer cache. Clear that manually and it should work fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;page 52 of TR-4379&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2016 23:42:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123677#M26499</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2016-09-28T23:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP cache TTL</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123952#M26583</link>
      <description>&lt;P&gt;Hello. It took me a while to get back, but I had NetApp's support to help with this. So, I still can't understand if this was necessary, but we additionaly tweaked the value of these caches:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ldap-username-to-info-batch&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;username-to-info&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(By the way, any idea what these two do? didn't quite get it plus&amp;nbsp;didn't find any other documentation other that what is mentioned here)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What definetly helped was changing the value for the TTL of the positive cached credentials for the NFS server. The default here is yet again 24h.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://library.netapp.com/ecmdocs/ECMP12454943/html/GUID-FAF76B58-BB2B-4A3F-9AB4-2FFB7F96F6C8.html" target="_blank"&gt;https://library.netapp.com/ecmdocs/ECMP12454943/html/GUID-FAF76B58-BB2B-4A3F-9AB4-2FFB7F96F6C8.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;::&amp;gt; set adv
::&amp;gt; vserver nfs modify -vserver vserver_name &lt;STRONG&gt;-cached-cred-positive-ttl&lt;/STRONG&gt; time_to_live&lt;/PRE&gt;&lt;P&gt;All good now. Thanks for the help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 15:40:28 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/123952#M26583</guid>
      <dc:creator>gpallis</dc:creator>
      <dc:date>2016-10-07T15:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP cache TTL</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/146117#M32446</link>
      <description>&lt;P&gt;After a couple of years this needs some updating. For those that do not know, ONTAP 9.3 and later introduce a change with regards to group caching in the form of the new &lt;SPAN&gt;Global Nameservice Caching functionality . The associated command is&amp;nbsp;&lt;/SPAN&gt;"&lt;SPAN&gt;name-service cache group-membership". For more information you can look the following KB:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1074594" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1074594&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 11:45:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/LDAP-cache-TTL/m-p/146117#M32446</guid>
      <dc:creator>gpallis</dc:creator>
      <dc:date>2019-01-23T11:45:34Z</dc:date>
    </item>
  </channel>
</rss>

