<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About LDAP schema MS-AD-BIS for CIFS and NFS in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/152830#M34055</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Got curious to find out what is 'MS-AD-BIS', Looks like it is refering to RFC2307bis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ONTAP 9.0 introduced a new built-in schema template for RFC-2307bis environments, specifically with&lt;BR /&gt;Active Directory in mind. This schema is called MS-AD-BIS and should be used with Microsoft Active&lt;BR /&gt;Directory LDAP servers whenever possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Found some some reference below:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This is a new schema (AD-MS-BIS) template available in ONTAP 9 for use with RFC-2307bis schemas, please refer to links below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to configure RFC 2307bis for Windows: (ldap_schema = rfc2307bis)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1031211/loc/en_US" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1031211/loc/en_US&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1074006/loc/en_US" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1074006/loc/en_US&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://unofficialaciguide.com/2019/07/31/ldap-schemas-for-aci-administrators-rfc2307-vs-rfc2307bis/" target="_blank"&gt;https://unofficialaciguide.com/2019/07/31/ldap-schemas-for-aci-administrators-rfc2307-vs-rfc2307bis/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.cdot-famg-nfs%2FGUID-B1CCBCC8-9FF0-4270-A4F4-679BE315C58A.html" target="_blank"&gt;https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.cdot-famg-nfs%2FGUID-B1CCBCC8-9FF0-4270-A4F4-679BE315C58A.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.netapp.com/us/media/tr-3458.pdf" target="_blank"&gt;https://www.netapp.com/us/media/tr-3458.pdf&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://whyistheinternetbroken.wordpress.com/2018/08/16/securing-nfs-mounts-in-a-docker-container/" target="_blank"&gt;https://whyistheinternetbroken.wordpress.com/2018/08/16/securing-nfs-mounts-in-a-docker-container/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://blogs.msdn.microsoft.com/sfu/2010/06/21/proof-of-concept-nfs-attributes-editor/" target="_blank"&gt;https://blogs.msdn.microsoft.com/sfu/2010/06/21/proof-of-concept-nfs-attributes-editor/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Secure Unified Authentication (MS-AD-BIS) : This PDF looks useful.&lt;/STRONG&gt;&lt;BR /&gt;&lt;A href="https://www.netapp.com/us/media/tr-4073.pdf" target="_blank"&gt;https://www.netapp.com/us/media/tr-4073.pdf&lt;/A&gt; (Page:122)&lt;BR /&gt;&lt;A href="https://tools.ietf.org/html/draft-howard-rfc2307bis-02" target="_blank"&gt;https://tools.ietf.org/html/draft-howard-rfc2307bis-02&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2019 21:58:15 GMT</pubDate>
    <dc:creator>Ontapforrum</dc:creator>
    <dc:date>2019-12-05T21:58:15Z</dc:date>
    <item>
      <title>About LDAP schema MS-AD-BIS for CIFS and NFS</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/152302#M33908</link>
      <description>&lt;P&gt;I was reading that the schema MS-AD-BIS allows for nexted grouping.&amp;nbsp; However, the only place I can find the text 'ms-ad-bis' is on the NetApp site, and only referring to the schema.&amp;nbsp; There is nothing I can find at Microsoft, or indeed via a general search about how to implement it in Windows, which versions it is supported by and so on.&lt;/P&gt;
&lt;P&gt;Has any a clue where to find more information?&lt;/P&gt;
&lt;P&gt;Hint:&amp;nbsp; The ONTAP developers must know something about it, since they have included it in the LDAP client schema list.&lt;/P&gt;
&lt;P&gt;TasP&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 20:10:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/152302#M33908</guid>
      <dc:creator>Tas</dc:creator>
      <dc:date>2019-11-13T20:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: About LDAP schema MS-AD-BIS for CIFS and NFS</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/152830#M34055</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Got curious to find out what is 'MS-AD-BIS', Looks like it is refering to RFC2307bis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ONTAP 9.0 introduced a new built-in schema template for RFC-2307bis environments, specifically with&lt;BR /&gt;Active Directory in mind. This schema is called MS-AD-BIS and should be used with Microsoft Active&lt;BR /&gt;Directory LDAP servers whenever possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Found some some reference below:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This is a new schema (AD-MS-BIS) template available in ONTAP 9 for use with RFC-2307bis schemas, please refer to links below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to configure RFC 2307bis for Windows: (ldap_schema = rfc2307bis)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1031211/loc/en_US" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1031211/loc/en_US&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1074006/loc/en_US" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1074006/loc/en_US&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://unofficialaciguide.com/2019/07/31/ldap-schemas-for-aci-administrators-rfc2307-vs-rfc2307bis/" target="_blank"&gt;https://unofficialaciguide.com/2019/07/31/ldap-schemas-for-aci-administrators-rfc2307-vs-rfc2307bis/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.cdot-famg-nfs%2FGUID-B1CCBCC8-9FF0-4270-A4F4-679BE315C58A.html" target="_blank"&gt;https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.cdot-famg-nfs%2FGUID-B1CCBCC8-9FF0-4270-A4F4-679BE315C58A.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.netapp.com/us/media/tr-3458.pdf" target="_blank"&gt;https://www.netapp.com/us/media/tr-3458.pdf&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://whyistheinternetbroken.wordpress.com/2018/08/16/securing-nfs-mounts-in-a-docker-container/" target="_blank"&gt;https://whyistheinternetbroken.wordpress.com/2018/08/16/securing-nfs-mounts-in-a-docker-container/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://blogs.msdn.microsoft.com/sfu/2010/06/21/proof-of-concept-nfs-attributes-editor/" target="_blank"&gt;https://blogs.msdn.microsoft.com/sfu/2010/06/21/proof-of-concept-nfs-attributes-editor/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Secure Unified Authentication (MS-AD-BIS) : This PDF looks useful.&lt;/STRONG&gt;&lt;BR /&gt;&lt;A href="https://www.netapp.com/us/media/tr-4073.pdf" target="_blank"&gt;https://www.netapp.com/us/media/tr-4073.pdf&lt;/A&gt; (Page:122)&lt;BR /&gt;&lt;A href="https://tools.ietf.org/html/draft-howard-rfc2307bis-02" target="_blank"&gt;https://tools.ietf.org/html/draft-howard-rfc2307bis-02&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 21:58:15 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/152830#M34055</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2019-12-05T21:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: About LDAP schema MS-AD-BIS for CIFS and NFS</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/152840#M34060</link>
      <description>&lt;P&gt;Thank you Ontapforrum:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like I have a little reading to do.&amp;nbsp; We have several flavors of LDS, including, believe it or not, Adam still running;&amp;nbsp; unfortunately we don't have an ID SME, so I'm trying to figure out how to go forward.&lt;/P&gt;
&lt;P&gt;Our aim is to manage permissions from one platform, but have them apply to both SMB and NFS (non-kerb).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Justin Parisi recommended using SMB/NTFS as the driving protocol, but I need to document the implementation, management and operation of permissions for all groups involved, i.e. Windows, AD, Help Desk, Storage, ;).&amp;nbsp; Being able to next groups in LDAP will make things alot easier.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will read, and flag this as an answer in a few days.&amp;nbsp; Hope you don't mind waiting...&lt;/P&gt;
&lt;P&gt;TasP&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 14:47:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/152840#M34060</guid>
      <dc:creator>Tas</dc:creator>
      <dc:date>2019-12-06T14:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: About LDAP schema MS-AD-BIS for CIFS and NFS</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/156685#M35415</link>
      <description>&lt;P&gt;I hope the link below provides all the information you need:&lt;/P&gt;
&lt;P&gt;&lt;A title="File sharing between NFS and CIFS" href="https://library.netapp.com/ecmdocs/ECMP1141095/html/GUID-C186238E-5AC9-427B-B19C-657F03F10E47.html" target="_blank" rel="noopener"&gt;File sharing between NFS and CIFS&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 09:31:00 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/156685#M35415</guid>
      <dc:creator>tahmad</dc:creator>
      <dc:date>2020-06-04T09:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: About LDAP schema MS-AD-BIS for CIFS and NFS</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/157899#M35895</link>
      <description>&lt;P&gt;Hi Tasp:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just wanted to know if you were able to achieve what you wanted.&lt;/P&gt;
&lt;P&gt;We have a similar requirement to map every NFS or CIFs access to a user in Active Directory.&lt;/P&gt;
&lt;P&gt;The solution proposed seems to be the one, but have not tried it yet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Abhi&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 12:48:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/157899#M35895</guid>
      <dc:creator>abhit</dc:creator>
      <dc:date>2020-07-21T12:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: About LDAP schema MS-AD-BIS for CIFS and NFS</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/158002#M35925</link>
      <description>&lt;P&gt;Abhit:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for the late reply.&amp;nbsp; I've tried using BIS, and for some reason I lose LDAP access from AD when I use it.&amp;nbsp; That doesn't mean I have done something wrong, or perhaps it is because of an option in our AD.&amp;nbsp; Unfortunately we don't have AD Identity Management SME's on site, and I don't have a lab nor the time to play with.&amp;nbsp; If you do try it and are successful, would you kindly let me know?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tas&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2020 13:50:37 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/About-LDAP-schema-MS-AD-BIS-for-CIFS-and-NFS/m-p/158002#M35925</guid>
      <dc:creator>Tas</dc:creator>
      <dc:date>2020-07-28T13:50:37Z</dc:date>
    </item>
  </channel>
</rss>

