<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Admin Authentication using Windows DC in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153257#M34233</link>
    <description>&lt;P&gt;Now that I think of it, which schema are you using?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Go ahead and open a case as this seems like it isn't working right. That way we can have proper tracking. You can reference this thread and I'll check on it once open.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Dec 2019 15:03:14 GMT</pubDate>
    <dc:creator>paul_stejskal</dc:creator>
    <dc:date>2019-12-26T15:03:14Z</dc:date>
    <item>
      <title>Admin Authentication using Windows DC</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153250#M34227</link>
      <description>&lt;P&gt;I have a very simple thing, that I have spend hours on trying to fix.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Setting a Windows DC as LDAP server and using this for administrative logins. It seems impossible. So I really need some help here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Set a LDAP client config with binding username and pw. Not sure what to pick in minimum authentication, but tried them all (anon, simple, sasl)&lt;/P&gt;
&lt;P&gt;2) Set the LDAP config for my SVM (cluster)&lt;/P&gt;
&lt;P&gt;3) Created a user with secure login create and the nsswitch (for remote lookups) - ssh, http and ontapi&lt;/P&gt;
&lt;P&gt;4) Added the ldap source in ns-switch&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have full visibility to both a '12R2 and a 19 DC, but non of them lets me perform the LDAP lookup. If I test the ldap from other applications it looks fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;diag secd authentication translate has been used to test and it tells me LDAP is unavaible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3] Source: LDAP unavailable. Ignoring and trying next&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Funny thing is that the connection is up according to vserver services ldap check:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;LDAP Status: up&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LDAP Status Details: Successfully connected to LDAP server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I must be overlooking something basic. Do I need to do anything on the Windows server to make it work? I also tried all the different schemas in LDAP client with no luck.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see the bind account is logging on the domain controller.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I really the first guy to want external authentication. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Desperate for advise. Been stuck for to long.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 11:23:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153250#M34227</guid>
      <dc:creator>AllanHedegaard</dc:creator>
      <dc:date>2025-06-04T11:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Authentication using Windows DC</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153251#M34228</link>
      <description>&lt;P&gt;Need more details. Do you have a case open or a serial # so I can look with a fresh ASUP ready to go?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2019 15:08:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153251#M34228</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2019-12-25T15:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Authentication using Windows DC</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153252#M34229</link>
      <description>&lt;P&gt;Dear Paul,&lt;/P&gt;
&lt;P&gt;I was surprised to see your message.&amp;nbsp; Not sure if my service contract covers this kind of configuration issue? Most likely it is my own lack of competence, and knowledge about ldap, that is the problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2019 15:20:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153252#M34229</guid>
      <dc:creator>AllanHedegaard</dc:creator>
      <dc:date>2019-12-25T15:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Authentication using Windows DC</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153253#M34230</link>
      <description>&lt;P&gt;It's borderline Support/PS. Technically it's a new setup, but it's probably something simple. Let me know when you have that serial # or case # and I can look at ASUPs.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Dec 2019 15:31:16 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153253#M34230</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2019-12-25T15:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Authentication using Windows DC</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153254#M34231</link>
      <description>&lt;P&gt;Not really much to go on, but this is where I am stuck. I can see the bind user is logging on to my DC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tried&amp;nbsp;configuring the UID value in ADSIEDIT for the particular user, but it seems no make no difference. Looks more like a general&amp;nbsp;LDAP connectivity issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CDOT02::diag secd trace*&amp;gt; diag secd authentication show-creds -vserver CDOT02 -unix-user-name&amp;nbsp; domain.com\user&lt;/P&gt;
&lt;P&gt;Vserver: CDOT02 (internal ID: XXXX)&lt;/P&gt;
&lt;P&gt;Error: Acquire UNIX credentials procedure failed&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; 1 ms] Hostname found in Name Service Cache&lt;BR /&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1] Resolved LDAP servers: 10.0.0.10. Vserver: -1&lt;BR /&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1] Failed to initiate Kerberos authentication. Trying NTLM.&lt;BR /&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5] LDAP search for the "uid, uidNumber, gidNumber,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unixUserPassword, name, unixHomeDirectory, loginShell"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; attribute(s) within base&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "CN=Users,DC=DOMAIN,DC=COM" (scope: 2) using&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; filter "(&amp;amp;(objectClass=User)(uid=domain.com\user))" fail&lt;BR /&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5]&amp;nbsp;&amp;nbsp; Additional info:&lt;BR /&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6] Source: LDAP unavailable. Ignoring and trying next&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; available source for user-name:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domain.com\user&lt;BR /&gt;&amp;nbsp; [&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6] Entry for user-name: domain.com\user not&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; found in the current source: FILES. Entry for user-name:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domain.com\user not found in any of the&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; available sources&lt;BR /&gt;**[&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6] FAILURE: Unable to retrieve UID for UNIX user&lt;BR /&gt;**&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domain.com\user&lt;/P&gt;
&lt;P&gt;Error: command failed: Failed to resolve user name to a UNIX ID. Reason: "SecD Error: libc returned a transient error.&amp;nbsp; Please look at the journal for detail".&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2019 12:39:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153254#M34231</guid>
      <dc:creator>AllanHedegaard</dc:creator>
      <dc:date>2019-12-26T12:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Authentication using Windows DC</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153255#M34232</link>
      <description>&lt;P&gt;Tried enabling LDAP debugging on my Windows Domain controller. I am only able to see the bind entered/exited.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Internal event: Function ldap_bind entered.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No function ldap_search are logged. So to me it looks like the Ontap is never making the query. &lt;img id="smileyindifferent" class="emoticon emoticon-smileyindifferent" src="https://community.netapp.com/i/smilies/16x16_smiley-indifferent.png" alt="Smiley Indifferent" title="Smiley Indifferent" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2019 13:00:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153255#M34232</guid>
      <dc:creator>AllanHedegaard</dc:creator>
      <dc:date>2019-12-26T13:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Authentication using Windows DC</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153257#M34233</link>
      <description>&lt;P&gt;Now that I think of it, which schema are you using?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Go ahead and open a case as this seems like it isn't working right. That way we can have proper tracking. You can reference this thread and I'll check on it once open.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2019 15:03:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153257#M34233</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2019-12-26T15:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: Admin Authentication using Windows DC</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153589#M34356</link>
      <description>&lt;P&gt;If i understand you correctly, you're trying to get AD-integrated access to the Netapp Management GUI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If so, i used this as a guide to get my netapp (running 9.6) working where i could log in with an Active Directory user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://red8.com/knowledge-base/netapp-ontap-active-directory-authentication/" target="_blank"&gt;https://red8.com/knowledge-base/netapp-ontap-active-directory-authentication/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 09:46:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Admin-Authentication-using-Windows-DC/m-p/153589#M34356</guid>
      <dc:creator>RandomStorage</dc:creator>
      <dc:date>2020-01-17T09:46:34Z</dc:date>
    </item>
  </channel>
</rss>

