<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are there any concerns to use &amp;quot;-rorule any, -rwrule any, -superuser none&amp;quot;? in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/160295#M36648</link>
    <description>&lt;P&gt;I had to set unix-permission to 777 on NetApp side, in order to touch a file with ownership of "nfsnobody nogroup", otherwise, it won't allow me to touch and got "permission denied".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can somebody please confirm&lt;/STRONG&gt; , do I have to set to 777? if yes, then anybody can do anything but root, that sounds not good.&lt;/P&gt;</description>
    <pubDate>Thu, 15 Oct 2020 15:00:46 GMT</pubDate>
    <dc:creator>netappmagic</dc:creator>
    <dc:date>2020-10-15T15:00:46Z</dc:date>
    <item>
      <title>Are there any concerns to use "-rorule any, -rwrule any, -superuser none"?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/159210#M36336</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Based on&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_create_a_root_squash_export_policy_rule_in_ONTAP" target="_blank" rel="noopener"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_create_a_root_squash_export_policy_rule_in_ONTAP,&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;filer::&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;vserver export-policy rule create -vserver sv1 -policyname default -clientmatch 192.168.0.0/24 -rorule any -rwrule any&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;-superuser none -anon 65534&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;filer::&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;vserver export-policy rule show -vserver sv1 -policyname default -ruleindex 8 -instance&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Vserver: sv1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Policy Name: default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Rule Index: 8&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Access Protocol: any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;List of Client Match Hostnames, IP Addresses, Netgroups, or Domains: 192.168.0.0/24&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;RO Access Rule: any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;RW Access Rule: any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;User ID To Which Anonymous Users Are Mapped: 65534&amp;nbsp; &amp;nbsp;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Superuser Security Types: none&amp;nbsp; &amp;nbsp; &amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Honor SetUID Bits in SETATTR: true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Allow Creation of Devices: true&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two questions:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Basically, this is "root_squash" option. Is this a recommended export policy/configurations?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any concerns?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2)&lt;BR /&gt;Is there any way to assign a specified user (not root) to have "root" type of access to a NFS file system under NFSv3? How?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:54:51 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/159210#M36336</guid>
      <dc:creator>netappmagic</dc:creator>
      <dc:date>2025-06-04T10:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Are there any concerns to use "-rorule any, -rwrule any, -superuser none"?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/159211#M36337</link>
      <description>&lt;P&gt;&lt;STRONG&gt;You may want to peruse this wonder Tech Report by&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/11621"&gt;@parisi&lt;/a&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.netapp.com/us/media/tr-4067.pdf" target="_blank"&gt;https://www.netapp.com/us/media/tr-4067.pdf&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 00:23:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/159211#M36337</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-09-04T00:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Are there any concerns to use "-rorule any, -rwrule any, -superuser none"?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/159222#M36341</link>
      <description>&lt;P&gt;Following Example on page 117 of this document&amp;nbsp;&lt;A href="https://www.netapp.com/us/media/tr-4067.pdf" target="_blank" rel="noopener"&gt;https://www.netapp.com/us/media/tr-4067.pdf&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;I am not able to touch any files on this NFS file system. Please find the screenshot on errors, and also the Example on page 117 excerpted below. Could you please point out what went wrong?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="netappmagic_0-1599214010467.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/10034iF546EF7CCE7E0774/image-size/medium?v=v2&amp;amp;px=400" role="button" title="netappmagic_0-1599214010467.png" alt="netappmagic_0-1599214010467.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="netappmagic_0-1599213483478.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/10032i4A79BB2C8CFC9F56/image-size/medium?v=v2&amp;amp;px=400" role="button" title="netappmagic_0-1599213483478.png" alt="netappmagic_0-1599213483478.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On my local Linux server, 65534 is corresponding to "nfsnobody" in /etc/passwd file. Could it be the cause, if yes, why could it be the cause?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 10:07:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/159222#M36341</guid>
      <dc:creator>netappmagic</dc:creator>
      <dc:date>2020-09-04T10:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Are there any concerns to use "-rorule any, -rwrule any, -superuser none"?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/159235#M36343</link>
      <description>&lt;P&gt;I have done same steps as instructed in page 117, however, I (either as root or an user) could not "touch" any files or do anything on the mounted NFS file system, got "permission denied" error.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can experts here please help me out ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2020 00:12:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/159235#M36343</guid>
      <dc:creator>netappmagic</dc:creator>
      <dc:date>2020-09-06T00:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: Are there any concerns to use "-rorule any, -rwrule any, -superuser none"?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/159236#M36344</link>
      <description>&lt;P&gt;by setting the permission to 777 on the volume, I got both Example 1 and Example 2 work on page 117. Please ignore my last two messages above. Sorry for confusing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I don't quite understand what we are trying to do here. Here, "root" is squashed to nfsnobody (65534). But, what if I also want to have the "root" to do what "root" is supposed to do on this NFS file system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What am I missing ?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2020 01:12:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/159236#M36344</guid>
      <dc:creator>netappmagic</dc:creator>
      <dc:date>2020-09-06T01:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Are there any concerns to use "-rorule any, -rwrule any, -superuser none"?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/160295#M36648</link>
      <description>&lt;P&gt;I had to set unix-permission to 777 on NetApp side, in order to touch a file with ownership of "nfsnobody nogroup", otherwise, it won't allow me to touch and got "permission denied".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can somebody please confirm&lt;/STRONG&gt; , do I have to set to 777? if yes, then anybody can do anything but root, that sounds not good.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 15:00:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Are-there-any-concerns-to-use-quot-rorule-any-rwrule-any-superuser-none-quot/m-p/160295#M36648</guid>
      <dc:creator>netappmagic</dc:creator>
      <dc:date>2020-10-15T15:00:46Z</dc:date>
    </item>
  </channel>
</rss>

