<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to grant admin access to a CDOT cluster via an Active Directory group in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/136027#M29931</link>
    <description>&lt;P&gt;Thnaks for this post, it worked for us!&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2017 17:15:06 GMT</pubDate>
    <dc:creator>ARUP-Labs</dc:creator>
    <dc:date>2017-11-15T17:15:06Z</dc:date>
    <item>
      <title>How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/25168#M5918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a new 4 node CDOT cluster that we are building out at this time. This is the first on our company as the rest are all running 7-mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I add execute the following commands on our new CDOT cluster, I am able to successfully login via putty or system manager:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;security login create -vserver vs1 -username DOMAIN\username -application ontapi -authmethod domain -role admin&lt;BR /&gt;security login create -vserver vs1 -username DOMAIN\username -application ssh -authmethod domain -role admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I need to provision security access via AD groups as we have a ot of admins that need access. &lt;/P&gt;&lt;P&gt;If I use the following commands to provision security, the commands are accepted by ONTAP but AD credential sets will not grant access to putty or system manager.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;security login create -vserver vs1 -username "DOMAIN\AD Group" -application ontapi -authmethod domain -role admin&lt;BR /&gt;security login create -vserver vs1 -username "DOMAIN\AD Group" -application ssh -authmethod domain -role admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please provide comments if you have ideas on next steps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2014 13:10:45 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/25168#M5918</guid>
      <dc:creator>89sigo</dc:creator>
      <dc:date>2014-08-07T13:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/25173#M5920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have the exact same issue here. Really tough from a management perspective to have to set manually add and remove user admin accounts on the cluster.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2014 17:50:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/25173#M5920</guid>
      <dc:creator>SMINATHA22</dc:creator>
      <dc:date>2014-08-12T17:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/25177#M5921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AD security group is not supported, only AD domain user could be used starting DOT 8.1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;From the Release Notes:&lt;/SPAN&gt;&lt;/P&gt;&lt;H1 class="title topictitle1"&gt;&lt;/H1&gt;&lt;P&gt;&lt;EM&gt;Starting with Data ONTAP 8.1.1, you can enable Active Directory (AD) domain users to access the cluster (admin Vserver) by setting up an authentication tunnel through a CIFS-enabled Vserver. You must also create cluster user accounts for the domain users.&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 12:17:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/25177#M5921</guid>
      <dc:creator>jbastogne</dc:creator>
      <dc:date>2014-08-13T12:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/108073#M22368</link>
      <description>&lt;P&gt;I have done it in 8.3 please see below for the steps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the steps to grant access after you have CIFS setup in your SVM (This portion has to be done before the below steps will allow access)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;my-fas8060&amp;gt; security login domain-tunnel create -vserver (nameofSVM)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;(gives SSH &amp;nbsp;login)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN&gt;my-fas8060&amp;gt; &lt;/SPAN&gt;&lt;EM&gt;security login create -vserver (nameofSVM) -username domain\group name -application ssh -authmethod domain -role admin&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;(gives GUI login)&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;my-fas8060&amp;gt; security login create -vserver (nameofSVM) -username domain\group name -application http -authmethod domain -role admin&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;&lt;SPAN&gt;my-fas8060&amp;gt; &lt;/SPAN&gt;security login create -vserver (nameofSVM) -username domain\group name -application ontapi -authmethod domain -role admin&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2015 19:14:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/108073#M22368</guid>
      <dc:creator>DaleS</dc:creator>
      <dc:date>2015-08-03T19:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/108090#M22373</link>
      <description>&lt;P&gt;What credentials are used to log in? You cannot set group password, cannot you?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2015 07:02:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/108090#M22373</guid>
      <dc:creator>aborzenkov</dc:creator>
      <dc:date>2015-08-04T07:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/108149#M22394</link>
      <description>&lt;P&gt;8.3 adds support for domain groups over ssh and ontap (not the gui though)&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2015 21:02:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/108149#M22394</guid>
      <dc:creator>scottgelb</dc:creator>
      <dc:date>2015-08-04T21:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/108430#M22438</link>
      <description>&lt;P&gt;If the group name has a space in it, the quotes around it should work, yes? &amp;nbsp;Example: &amp;nbsp;"DOMAIN\Domain Admins"&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2015 21:01:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/108430#M22438</guid>
      <dc:creator>ilonak</dc:creator>
      <dc:date>2015-08-10T21:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/112706#M23885</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In 8.2.3P4, I found that you have to first create the domain-tunnel SVM, then create the user for the cluster name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;my-fas8060&amp;gt; security login domain-tunnel create -vserver (nameofDomainTunnelSVM)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;(gives SSH &amp;nbsp;login)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN&gt;my-fas8060&amp;gt; &lt;/SPAN&gt;&lt;EM&gt;security login create -vserver (nameofCluster) -username domain\group name -application ssh -authmethod domain -role admin&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;(gives GUI login)&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;my-fas8060&amp;gt; security login create -vserver (nameofCluster) -username domain\group name -application http -authmethod domain -role admin&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;&lt;SPAN&gt;my-fas8060&amp;gt; &lt;/SPAN&gt;security login create -vserver (nameofCluster) -username domain\group name -application ontapi -authmethod domain -role admin&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is how it worked for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Jack&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 19:53:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/112706#M23885</guid>
      <dc:creator>JROBERTS6670</dc:creator>
      <dc:date>2015-11-18T19:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/112719#M23888</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer&amp;nbsp;&lt;A href="https://kb.netapp.com/support/index?page=content&amp;amp;id=1013901" target="_blank"&gt;https://kb.netapp.com/support/index?page=content&amp;amp;id=1013901&lt;/A&gt; for the procedure.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 03:04:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/112719#M23888</guid>
      <dc:creator>Sahana</dc:creator>
      <dc:date>2015-11-19T03:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/123864#M26553</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to set the configuration that you have mentioned, but how do you login once it is set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is login id "Domain\username" or "Domain\group\username"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 21:16:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/123864#M26553</guid>
      <dc:creator>rpulikool</dc:creator>
      <dc:date>2016-10-05T21:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/132984#M29032</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-900%2Fsecurity__login__create.html" target="_blank"&gt;http://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-900%2Fsecurity__login__create.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example ONTAP 9:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cluster1::&amp;gt; security login create -user-or-group-name DOMAIN\adgroup -application ssh -authentication-method domain -role readonly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;login as Domain\username&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2017 14:38:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/132984#M29032</guid>
      <dc:creator>piosos</dc:creator>
      <dc:date>2017-07-21T14:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to grant admin access to a CDOT cluster via an Active Directory group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/136027#M29931</link>
      <description>&lt;P&gt;Thnaks for this post, it worked for us!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 17:15:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/How-to-grant-admin-access-to-a-CDOT-cluster-via-an-Active-Directory-group/m-p/136027#M29931</guid>
      <dc:creator>ARUP-Labs</dc:creator>
      <dc:date>2017-11-15T17:15:06Z</dc:date>
    </item>
  </channel>
</rss>

