<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Did Name Mapping (Kerberos to UNIX) changes between Ontap 8.3 and 9.X ? in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Did-Name-Mapping-Kerberos-to-UNIX-changes-between-Ontap-8-3-and-9-X/m-p/126021#M27178</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Thanks Justin; unfortunately &lt;/SPAN&gt;&lt;SPAN&gt;adding another (.+)\$ name mapping rule didn’t fix the issue; I will open a support case and reference what you mentioned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BTW: your (Secure Unified Authentication for NFS Kerberos, NFSv4, and LDAP in Clustered Data ONTAP) document save us lots of time setting up krb5 in our nfs environment. Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Dec 2016 21:01:24 GMT</pubDate>
    <dc:creator>MrBenjamin</dc:creator>
    <dc:date>2016-12-06T21:01:24Z</dc:date>
    <item>
      <title>Did Name Mapping (Kerberos to UNIX) changes between Ontap 8.3 and 9.X ?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Did-Name-Mapping-Kerberos-to-UNIX-changes-between-Ontap-8-3-and-9-X/m-p/125905#M27138</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are testing an upgrade to Ontap 9.0 &amp;amp; 9.1rc from Ontap 8.3;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This name mapping works in Ontap 8.3:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kerberos to UNIX:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;Pattern: (.+)\$@DOMAIN.COM Replacement: nfsuser&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This name mapping doesn't work in Ontap 9.x:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kerberos to UNIX:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;Pattern: (.+)\$@DOMAIN.COM Replacement: nfsuser&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is the error from my netapp:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;12/2/2016 15:19:23 &amp;nbsp;MYNODE &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;ERROR &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;secd.nfsAuth.problem: vserver (nfsv4) General NFS authorization problem. Error: RPC accept GSS token procedure failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;[ 24 ms] Acquired NFS service credential for logical interface 1027 (SPN='nfs/nfsv4.domain.com@DOMAIN.COM').&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;[ &amp;nbsp;&amp;nbsp;&amp;nbsp;31] GSS_S_COMPLETE: client = 'MYCOMPUTER$@DOMAIN.COM'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;[ &amp;nbsp;&amp;nbsp;&amp;nbsp;32] Trying to map SPN 'MYCOMPUTER$@DOMAIN.COM' to UNIX user 'MYCOMPUTER$' using implicit mapping&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;[ &amp;nbsp;&amp;nbsp;&amp;nbsp;37] Entry for user-name: MYCOMPUTER$ not found in the current source: FILES. Ignoring and trying next available source&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;[ &amp;nbsp;&amp;nbsp;&amp;nbsp;48] Successfully connected to ip 1.1.1.1 port 389 using TCP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;[ &amp;nbsp;3063] LDAP search for the "uid, uidNumber, gidNumber, unixUserPassword, name, unixHomeDirectory, loginShell" attribute(s) within base "dc=domain,dc=com" (scope: 2) using filter "(&amp;amp;(objectClass=User)(uid=MYCOMPUTER$))" failed with error: Timed out&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;[ &amp;nbsp;3063] &amp;nbsp;&amp;nbsp;Additional info:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;[ &amp;nbsp;3064] Source: LDAP unavailable. Entry for user-name:MYCOMPUTER$ not found in any of the available sources&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;[ &amp;nbsp;3064] Unable to map SPN 'MYCOMPUTER$@DOMAIN.COM'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;**[ &amp;nbsp;3064] FAILURE: Unable to map Kerberos NFS user 'MYCOMPUTER$@DOMAIN.COM' to appropriate UNIX user&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;[ &amp;nbsp;3065] Failed to accept the context: The routine completed successfully (minor: Unknown error). Result = 6916&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Note: this one works on the Ontap 9: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kerberos to UNIX:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;Pattern: (.+)@DOMAIN.COM Replacement: nfsuser&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Though, I do not want all the domain krb users mapped to nfsuser only MACHINESHORTNAME$@DOMAIN.COM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Additionally, my LDAP translations are working:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;diag secd authentication translate -node MYNODE -vserver NFS4 &amp;nbsp;-unix-user-name MYUSERNAME
12345&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, is there an easier way to test krb like unix ids?&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;diag secd authentication translate -node MYNODE -vserver NFS4 &amp;nbsp;-unix-user-name MYUSERNAME&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ben&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 18:07:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Did-Name-Mapping-Kerberos-to-UNIX-changes-between-Ontap-8-3-and-9-X/m-p/125905#M27138</guid>
      <dc:creator>MrBenjamin</dc:creator>
      <dc:date>2025-06-04T18:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: Did Name Mapping (Kerberos to UNIX) changes between Ontap 8.3 and 9.X ?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Did-Name-Mapping-Kerberos-to-UNIX-changes-between-Ontap-8-3-and-9-X/m-p/125969#M27161</link>
      <description>&lt;P&gt;What's probably happening here is that the name mapping is trying to use the name without the DOMAIN.COM appended. That's why it can't seem to find it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd say change the rule (or add a 2nd rule) to be (.+)\$ (without the @DOMAIN.COM portion)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It may be that the changes in 8.3.2 to support asymmetric name mappings caused this. See page 66 of TR-4073 for details of those.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.netapp.com/us/media/tr-4073.pdf" target="_blank"&gt;http://www.netapp.com/us/media/tr-4073.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd suggest opening a support case either way. If the above fixes the issue, we need to call out the default behavior in docs and file a bug.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the above doesn't work, a support case can help you get to the bottom of this and file a bug if necessary.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 15:32:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Did-Name-Mapping-Kerberos-to-UNIX-changes-between-Ontap-8-3-and-9-X/m-p/125969#M27161</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2016-12-05T15:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: Did Name Mapping (Kerberos to UNIX) changes between Ontap 8.3 and 9.X ?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Did-Name-Mapping-Kerberos-to-UNIX-changes-between-Ontap-8-3-and-9-X/m-p/126021#M27178</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks Justin; unfortunately &lt;/SPAN&gt;&lt;SPAN&gt;adding another (.+)\$ name mapping rule didn’t fix the issue; I will open a support case and reference what you mentioned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BTW: your (Secure Unified Authentication for NFS Kerberos, NFSv4, and LDAP in Clustered Data ONTAP) document save us lots of time setting up krb5 in our nfs environment. Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 21:01:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Did-Name-Mapping-Kerberos-to-UNIX-changes-between-Ontap-8-3-and-9-X/m-p/126021#M27178</guid>
      <dc:creator>MrBenjamin</dc:creator>
      <dc:date>2016-12-06T21:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: Did Name Mapping (Kerberos to UNIX) changes between Ontap 8.3 and 9.X ?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Did-Name-Mapping-Kerberos-to-UNIX-changes-between-Ontap-8-3-and-9-X/m-p/126341#M27268</link>
      <description>&lt;P&gt;for the sake for completion: this issue was address in: (&lt;SPAN&gt;1041909) and fixed in&amp;nbsp;Data ONTAP &lt;A href="https://mysupport.netapp.com/download/software/ontap/9.1RC2/" target="_blank"&gt;9.1RC2&lt;/A&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 23:30:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Did-Name-Mapping-Kerberos-to-UNIX-changes-between-Ontap-8-3-and-9-X/m-p/126341#M27268</guid>
      <dc:creator>MrBenjamin</dc:creator>
      <dc:date>2016-12-15T23:30:06Z</dc:date>
    </item>
  </channel>
</rss>

