<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL for SVMs in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167643#M38404</link>
    <description>&lt;P&gt;"depending on requirements" is the correct terminology to use...unfortunately.&lt;/P&gt;&lt;P&gt;You need a valid SSL cluster level cert to establish&amp;nbsp; OCUM/ActiveIQ UM connectivity.&amp;nbsp; Prob the same for SC/VSC/grafana......&lt;/P&gt;&lt;P&gt;I have seen env's with cluster level SSL certs and no SVM level SSL certs, running fine with no issues.&lt;/P&gt;&lt;P&gt;When NetApp introduces SVM System Manager GUI access you'll prob need valid SSL certs for the SVM&lt;/P&gt;&lt;P&gt;I recently had to add a valid SSL cert to the SVM because Varonis FPolicy required it.&lt;/P&gt;&lt;P&gt;I usually replace the SSL cert at deployment time with a longer expiring one (3650 days) to avoid having to deal with it again before the system is replaced/headswapped/etc. (See them here: security certificate show -type server)&lt;/P&gt;&lt;P&gt;Sound to me like you have no need for the SVM level SSL cert. Basic operations have no need for it in my experience.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jun 2021 05:09:29 GMT</pubDate>
    <dc:creator>Sig</dc:creator>
    <dc:date>2021-06-10T05:09:29Z</dc:date>
    <item>
      <title>SSL for SVMs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167115#M38273</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;would somebody please know the answer to this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When issuing security ssl show, I see value Server Enabled as true for the cluster, a CIFS SVM (only used for LDAP authentication to the cluster, setup suggested by NetApp technicians) and a FC SVM. The FC SVM doesn't have any IP interface, so I think it's invalid completely. The CIFS SVM is accessible on HTTPS, but I don't think we use it for anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what is this for? Do the SVMs need to have a certificate and SSL enabled at all?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Karel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:23:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167115#M38273</guid>
      <dc:creator>KarelBP</dc:creator>
      <dc:date>2025-06-04T10:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSL for SVMs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167186#M38289</link>
      <description>&lt;P&gt;SSL is the recommended authentication method for ONTAP cluster mode.&lt;/P&gt;&lt;P&gt;If you are accessing an svm for management purpose or data access ...etc, authentication is required.&lt;/P&gt;&lt;P&gt;That is why by default SSL service "Sever Enabled" is true for all svms.&lt;/P&gt;&lt;P&gt;For any users or application to access data on the CIFS or FC SVM, they need to authenticate.&lt;/P&gt;&lt;P&gt;For logging in to the cluster as an admin or user you need to authenticate and that is done through the cluster(admin) SVM.&lt;/P&gt;&lt;P&gt;In your case, the CIFS SVM is used for LDAP authentication which is correct and the SSL service is needed to be enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So yes, the SVMs need certs(it can be the default Self-Signed or third party CA-signed) and SSL service enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that answers your question &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 19:56:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167186#M38289</guid>
      <dc:creator>AlainTansi</dc:creator>
      <dc:date>2021-05-27T19:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSL for SVMs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167195#M38290</link>
      <description>&lt;DIV id="page-history-top-section" class="special-history-header-container"&gt;
&lt;DIV class="mt-section"&gt;
&lt;P&gt;&lt;SPAN&gt;This command displays the configuration of encrypted HTTP (SSL) for Vservers in the cluster. Depending on the requirements of the individual node's or cluster's web services (displayed by the&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref nopagenum" title="Display the current configuration of web services" href="https://docs.netapp.com/ontap-9/topic/com.netapp.doc.dot-cm-cmpr-970/vserver__services__web__show.html" shape="rect" target="_blank"&gt;&lt;SPAN class="keyword cmdname"&gt;&lt;SPAN&gt;vserver services web&amp;nbsp;show&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;command), this encryption might or might not be used. If the Vserver does not have a certificate associated with it,&amp;nbsp;SSL&amp;nbsp;will not be available.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="mt-style-conditional style-wrap" title="Procedure"&gt;
&lt;DIV id="page-history-top-section" class="special-history-header-container"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 28 May 2021 01:21:09 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167195#M38290</guid>
      <dc:creator>Mjizzini</dc:creator>
      <dc:date>2021-05-28T01:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL for SVMs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167203#M38293</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thanks for your explanation, but I'm a bit lost here. Probably more than a bit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We don't authenticate directly to the SVM, have no need for it. The cluster management page, which existed and was accessible before we created the SVM from GUI, is on a different IP address and that's the only service we ever want to talk to. Therefore I don't see why this SVM should even have a certificate and publish its web service into the network, when all I need it for is to talk to the domain controllers as client, not as a server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Karel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 14:17:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167203#M38293</guid>
      <dc:creator>KarelBP</dc:creator>
      <dc:date>2021-05-28T14:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSL for SVMs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167204#M38294</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thanks. When you write "depending on the requirements", that's the part where I cannot tell what exactly the requirements are. I know for sure I'd like to turn off everything we don't necessarily need and limit number of findings in vulnerability scanner. This is a 2-node cluster which only serves disks over fiber-channel, needs authentication with Active Directory to management GUI or SSH console and it should have REST API accessible to be able to read out events. Nothing else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Karel&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 14:30:28 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167204#M38294</guid>
      <dc:creator>KarelBP</dc:creator>
      <dc:date>2021-05-28T14:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL for SVMs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167643#M38404</link>
      <description>&lt;P&gt;"depending on requirements" is the correct terminology to use...unfortunately.&lt;/P&gt;&lt;P&gt;You need a valid SSL cluster level cert to establish&amp;nbsp; OCUM/ActiveIQ UM connectivity.&amp;nbsp; Prob the same for SC/VSC/grafana......&lt;/P&gt;&lt;P&gt;I have seen env's with cluster level SSL certs and no SVM level SSL certs, running fine with no issues.&lt;/P&gt;&lt;P&gt;When NetApp introduces SVM System Manager GUI access you'll prob need valid SSL certs for the SVM&lt;/P&gt;&lt;P&gt;I recently had to add a valid SSL cert to the SVM because Varonis FPolicy required it.&lt;/P&gt;&lt;P&gt;I usually replace the SSL cert at deployment time with a longer expiring one (3650 days) to avoid having to deal with it again before the system is replaced/headswapped/etc. (See them here: security certificate show -type server)&lt;/P&gt;&lt;P&gt;Sound to me like you have no need for the SVM level SSL cert. Basic operations have no need for it in my experience.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 05:09:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SSL-for-SVMs/m-p/167643#M38404</guid>
      <dc:creator>Sig</dc:creator>
      <dc:date>2021-06-10T05:09:29Z</dc:date>
    </item>
  </channel>
</rss>

