<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Role Permission for Halting Only does not working - CDOT in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Role-Permission-for-Halting-Only-does-not-working-CDOT/m-p/124192#M26676</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to create an user with the following role permission:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;netappcdot823::&amp;gt; security login role show -vserver netappcdot823 -role operators&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;VServer &amp;nbsp; &amp;nbsp; &amp;nbsp; Role Name Command/Directory Query Access Level&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;netappcdot823 operators DEFAULT &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; none&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;netappcdot823 operators system node halt &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;all&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The objective&amp;nbsp;is to create an user with the halt capability only, and&amp;nbsp;no more permissions if possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I login with that user and issue a "system node halt" command, it seems there is a lack of other permissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;netappcdot823::&amp;gt; system node halt&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Warning: Are you sure you want to halt node "netappcdot823-01"? {y|n}: y&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Error: not authorized for that command&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Note: I'm&amp;nbsp;doing this on Ontap Simulator 8.2.3 CDOT.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Changing the "DEFAULT" access level to "all" works, but this is not desired because all other commands are also allowed (acts like an admin user).&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Any idea?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Thanks!&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 18:38:39 GMT</pubDate>
    <dc:creator>luiz_silva</dc:creator>
    <dc:date>2025-06-04T18:38:39Z</dc:date>
    <item>
      <title>Role Permission for Halting Only does not working - CDOT</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Role-Permission-for-Halting-Only-does-not-working-CDOT/m-p/124192#M26676</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to create an user with the following role permission:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;netappcdot823::&amp;gt; security login role show -vserver netappcdot823 -role operators&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;VServer &amp;nbsp; &amp;nbsp; &amp;nbsp; Role Name Command/Directory Query Access Level&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;netappcdot823 operators DEFAULT &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; none&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;netappcdot823 operators system node halt &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;all&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The objective&amp;nbsp;is to create an user with the halt capability only, and&amp;nbsp;no more permissions if possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I login with that user and issue a "system node halt" command, it seems there is a lack of other permissions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;netappcdot823::&amp;gt; system node halt&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Warning: Are you sure you want to halt node "netappcdot823-01"? {y|n}: y&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Error: not authorized for that command&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Note: I'm&amp;nbsp;doing this on Ontap Simulator 8.2.3 CDOT.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Changing the "DEFAULT" access level to "all" works, but this is not desired because all other commands are also allowed (acts like an admin user).&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Any idea?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Thanks!&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 18:38:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Role-Permission-for-Halting-Only-does-not-working-CDOT/m-p/124192#M26676</guid>
      <dc:creator>luiz_silva</dc:creator>
      <dc:date>2025-06-04T18:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Role Permission for Halting Only does not working - CDOT</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Role-Permission-for-Halting-Only-does-not-working-CDOT/m-p/124236#M26682</link>
      <description>&lt;P&gt;Halting a node is supposed to be an administrative task, and often disruptive to the cluster too. It involves migrating LIFs, initiating takeover, ARLs, making changes to cluster quorum, RDB changes and perhaps affecting the resiliency of the cluster too. Why do you want to give the permission to a non-administrator to shutdown a node?I think &amp;nbsp;that is way beyond any logic. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2016 06:41:37 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Role-Permission-for-Halting-Only-does-not-working-CDOT/m-p/124236#M26682</guid>
      <dc:creator>georgevj</dc:creator>
      <dc:date>2016-10-17T06:41:37Z</dc:date>
    </item>
  </channel>
</rss>

