<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible to use Hashicorp Vault ssh plugin for One Time Password generation with ONTAP? in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Is-it-possible-to-use-Hashicorp-Vault-ssh-plugin-for-One-Time-Password/m-p/167402#M38360</link>
    <description>&lt;P&gt;We are looking at the possibility to use Hashicorp vault manage ONTAP local account access and auditing.&lt;BR /&gt;&lt;BR /&gt;One method Vault offers is an SSH Secrets Engine that can generate a one time password when an authorized user requests it. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;more info on Vault OTP configuration can be found here:&lt;BR /&gt;&lt;A href="https://learn.hashicorp.com/tutorials/vault/ssh-otp" target="_blank"&gt;https://learn.hashicorp.com/tutorials/vault/ssh-otp&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Essentially this method requires downloading a vault-ssh-helper executable and storing it in the usr/local/bin location on the host that you want Vault to manage ssh secrets for. &amp;nbsp; Some modifications of the /etc/pam.d/ssh and /etc/ssh/sshd_config files to &amp;nbsp;leverage the vault ssh helper is also required.&lt;BR /&gt;&lt;BR /&gt;Before digging too much deeper into this approach, is this something that would be possible with ONTAP? &amp;nbsp;And would it be a supported configuration?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 10:22:56 GMT</pubDate>
    <dc:creator>JonathanAlexander</dc:creator>
    <dc:date>2025-06-04T10:22:56Z</dc:date>
    <item>
      <title>Is it possible to use Hashicorp Vault ssh plugin for One Time Password generation with ONTAP?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Is-it-possible-to-use-Hashicorp-Vault-ssh-plugin-for-One-Time-Password/m-p/167402#M38360</link>
      <description>&lt;P&gt;We are looking at the possibility to use Hashicorp vault manage ONTAP local account access and auditing.&lt;BR /&gt;&lt;BR /&gt;One method Vault offers is an SSH Secrets Engine that can generate a one time password when an authorized user requests it. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;more info on Vault OTP configuration can be found here:&lt;BR /&gt;&lt;A href="https://learn.hashicorp.com/tutorials/vault/ssh-otp" target="_blank"&gt;https://learn.hashicorp.com/tutorials/vault/ssh-otp&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Essentially this method requires downloading a vault-ssh-helper executable and storing it in the usr/local/bin location on the host that you want Vault to manage ssh secrets for. &amp;nbsp; Some modifications of the /etc/pam.d/ssh and /etc/ssh/sshd_config files to &amp;nbsp;leverage the vault ssh helper is also required.&lt;BR /&gt;&lt;BR /&gt;Before digging too much deeper into this approach, is this something that would be possible with ONTAP? &amp;nbsp;And would it be a supported configuration?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:22:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Is-it-possible-to-use-Hashicorp-Vault-ssh-plugin-for-One-Time-Password/m-p/167402#M38360</guid>
      <dc:creator>JonathanAlexander</dc:creator>
      <dc:date>2025-06-04T10:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use Hashicorp Vault ssh plugin for One Time Password generation with ONTAP?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Is-it-possible-to-use-Hashicorp-Vault-ssh-plugin-for-One-Time-Password/m-p/167439#M38375</link>
      <description>&lt;P&gt;There's support for KMIP looks like. I don't think modifying SSH config works like that, so I would talk to the account team and see about what is needed to get a supported configuration. I don't think it's impossible, but definitely the account team can reach out to internal resources to get confirmation or a fPVR if needed.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 14:55:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Is-it-possible-to-use-Hashicorp-Vault-ssh-plugin-for-One-Time-Password/m-p/167439#M38375</guid>
      <dc:creator>paul_stejskal</dc:creator>
      <dc:date>2021-06-07T14:55:54Z</dc:date>
    </item>
  </channel>
</rss>

