<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows LDAP Authentication for Cluster Admin in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-LDAP-Authentication-for-Cluster-Admin/m-p/440975#M41668</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer want to use AD ldap for cluster admin login follow KB&amp;nbsp;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_configure_LDAP_Authentication_for_Cluster_(Admin)_SVM" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_configure_LDAP_Authentication_for_Cluster_(Admin)_SVM&lt;/A&gt;&amp;nbsp;but failed. Customer exist AD ldap auth Hitachi storage admin login no problem, they did not want to use CIFS tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I test KB in my simulator still failed with below setting.&lt;/P&gt;&lt;P&gt;-&amp;nbsp;schema copy AD-IDMU to AD-IDMU-lab and change groupOfUniqueNames, uniqueMember and Name Mapping windowsAccount&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_1-1673859781306.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24991iE97ADE5693D3F9F7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_1-1673859781306.png" alt="chinchillaking_1-1673859781306.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- setup ldap client as below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_0-1673859689788.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24990i888FAD0BD205D79F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_0-1673859689788.png" alt="chinchillaking_0-1673859689788.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- modify name-services as below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_2-1673859948849.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24992iF5156B7706E7B1C3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_2-1673859948849.png" alt="chinchillaking_2-1673859948849.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- t&lt;SPAN&gt;est UNIX credentials are pulled correctly from Windows AD LDAP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_3-1673860040040.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24993iB4597EDF37F547C1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_3-1673860040040.png" alt="chinchillaking_3-1673860040040.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_4-1673860115963.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24994i7D13FD970DCABBED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_4-1673860115963.png" alt="chinchillaking_4-1673860115963.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- check the ldap status no problem&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_5-1673860181330.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24995iAF99CF9BC94AC5B5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_5-1673860181330.png" alt="chinchillaking_5-1673860181330.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- security login account add in cluster&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_6-1673860237218.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24996i9062980800CF6A23/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_6-1673860237218.png" alt="chinchillaking_6-1673860237218.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;Install Identity Management for UNIX, Server for NIS and Password Synchronization&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_7-1673860449829.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24997i5D6CBD672BBBCC6B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_7-1673860449829.png" alt="chinchillaking_7-1673860449829.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_8-1673860465366.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24998iF556D829C23EF631/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_8-1673860465366.png" alt="chinchillaking_8-1673860465366.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- reset hvadmin password trigger password synchronization, the unixUserPassword update&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_9-1673860522571.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24999i0A8624AD161BD121/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_9-1673860522571.png" alt="chinchillaking_9-1673860522571.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- try login ssh display "Access denied" or system manager and display "&lt;SPAN&gt;Sign In Failed. Please verify Username and Password."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- when login with hvadmin,&amp;nbsp;wireshark display it will query ldap but event log not much info troubleshoot&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_10-1673861028053.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/25000i2DF262DBB731EABF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_10-1673861028053.png" alt="chinchillaking_10-1673861028053.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_11-1673861170335.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/25001i528E8F2CE04CE7D1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_11-1673861170335.png" alt="chinchillaking_11-1673861170335.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any advise?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 09:54:11 GMT</pubDate>
    <dc:creator>chinchillaking</dc:creator>
    <dc:date>2025-06-04T09:54:11Z</dc:date>
    <item>
      <title>Windows LDAP Authentication for Cluster Admin</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-LDAP-Authentication-for-Cluster-Admin/m-p/440975#M41668</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer want to use AD ldap for cluster admin login follow KB&amp;nbsp;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_configure_LDAP_Authentication_for_Cluster_(Admin)_SVM" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/How_to_configure_LDAP_Authentication_for_Cluster_(Admin)_SVM&lt;/A&gt;&amp;nbsp;but failed. Customer exist AD ldap auth Hitachi storage admin login no problem, they did not want to use CIFS tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I test KB in my simulator still failed with below setting.&lt;/P&gt;&lt;P&gt;-&amp;nbsp;schema copy AD-IDMU to AD-IDMU-lab and change groupOfUniqueNames, uniqueMember and Name Mapping windowsAccount&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_1-1673859781306.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24991iE97ADE5693D3F9F7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_1-1673859781306.png" alt="chinchillaking_1-1673859781306.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- setup ldap client as below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_0-1673859689788.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24990i888FAD0BD205D79F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_0-1673859689788.png" alt="chinchillaking_0-1673859689788.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- modify name-services as below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_2-1673859948849.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24992iF5156B7706E7B1C3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_2-1673859948849.png" alt="chinchillaking_2-1673859948849.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- t&lt;SPAN&gt;est UNIX credentials are pulled correctly from Windows AD LDAP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_3-1673860040040.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24993iB4597EDF37F547C1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_3-1673860040040.png" alt="chinchillaking_3-1673860040040.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_4-1673860115963.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24994i7D13FD970DCABBED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_4-1673860115963.png" alt="chinchillaking_4-1673860115963.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- check the ldap status no problem&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_5-1673860181330.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24995iAF99CF9BC94AC5B5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_5-1673860181330.png" alt="chinchillaking_5-1673860181330.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- security login account add in cluster&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_6-1673860237218.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24996i9062980800CF6A23/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_6-1673860237218.png" alt="chinchillaking_6-1673860237218.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;Install Identity Management for UNIX, Server for NIS and Password Synchronization&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_7-1673860449829.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24997i5D6CBD672BBBCC6B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_7-1673860449829.png" alt="chinchillaking_7-1673860449829.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_8-1673860465366.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24998iF556D829C23EF631/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_8-1673860465366.png" alt="chinchillaking_8-1673860465366.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- reset hvadmin password trigger password synchronization, the unixUserPassword update&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_9-1673860522571.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/24999i0A8624AD161BD121/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_9-1673860522571.png" alt="chinchillaking_9-1673860522571.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- try login ssh display "Access denied" or system manager and display "&lt;SPAN&gt;Sign In Failed. Please verify Username and Password."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- when login with hvadmin,&amp;nbsp;wireshark display it will query ldap but event log not much info troubleshoot&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_10-1673861028053.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/25000i2DF262DBB731EABF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_10-1673861028053.png" alt="chinchillaking_10-1673861028053.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chinchillaking_11-1673861170335.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/25001i528E8F2CE04CE7D1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chinchillaking_11-1673861170335.png" alt="chinchillaking_11-1673861170335.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any advise?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:54:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-LDAP-Authentication-for-Cluster-Admin/m-p/440975#M41668</guid>
      <dc:creator>chinchillaking</dc:creator>
      <dc:date>2025-06-04T09:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Windows LDAP Authentication for Cluster Admin</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Windows-LDAP-Authentication-for-Cluster-Admin/m-p/441100#M41687</link>
      <description>&lt;P&gt;I found the problem, Windows AD Schema did not allow search unixUserPassword, change below problem fixed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ADSI editior &amp;gt; select a well known naming context &amp;gt; Schema &amp;gt; OK &amp;gt; searchFlags Attribute for CN=unixUserPassword change default 128 to 0&lt;BR /&gt;right click Schema &amp;gt; Update Schema Now&lt;/P&gt;</description>
      <pubDate>Sat, 21 Jan 2023 10:01:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Windows-LDAP-Authentication-for-Cluster-Admin/m-p/441100#M41687</guid>
      <dc:creator>chinchillaking</dc:creator>
      <dc:date>2023-01-21T10:01:59Z</dc:date>
    </item>
  </channel>
</rss>

