<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Linux LDAP User not have the right access to  NFS volume directory with NFSv4 ACL in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Linux-LDAP-User-not-have-the-right-access-to-NFS-volume-directory-with-NFSv4-ACL/m-p/449386#M42990</link>
    <description>&lt;P&gt;After deploy the environment by "&lt;STRONG&gt;How to configure LDAP in ONTAP&amp;nbsp;&lt;/STRONG&gt;TR-4835"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1. Windows server 2019 with LDAP services&lt;/P&gt;&lt;P&gt;2. CentOS7 client use sssd and realm add to the AD Domain, and use two methods according to TR, shows below&lt;/P&gt;&lt;P data-unlink="true"&gt;[root@centos7 ~]# id u01&lt;BR /&gt;uid=2000(u01) gid=3000(Domain Users) groups=3000(Domain Users)&lt;BR /&gt;[root@centos7 ~]# id u01@gtish.loc&lt;BR /&gt;uid=1596602150(u01@GTISH.LOC) gid=1596600513(domain users@GTISH.LOC) groups=1596600513(domain users@GTISH.LOC),1596602153(all test users@GTISH.LOC)&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. From ONTAP SVM, the name services query returns correct results, shows below&lt;/P&gt;&lt;P&gt;::*&amp;gt; getxxbyyy getpwbyname -node FAS2750-01 -vserver SVM_LDAP -show-source true -use-cache false -username u01&lt;BR /&gt;(vserver services name-service getxxbyyy getpwbyname)&lt;BR /&gt;Source used for lookup: LDAP&lt;BR /&gt;pw_name: u01&lt;BR /&gt;pw_passwd:&lt;BR /&gt;pw_uid: 2000&lt;BR /&gt;pw_gid: 3000&lt;BR /&gt;pw_gecos:&lt;BR /&gt;pw_dir:&lt;BR /&gt;pw_shell: /bin/bash&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Problem&lt;/STRONG&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;The LDAP user u01@gtish.loc&amp;nbsp;cannot access the directory in the ONTAP NFS volume with NFSv4 ACL, shows below&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[u01@GTISH.LOC@centos7 ldap]$ nfs4_getfacl root&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;# file: root&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;A::OWNER@:rwaDxtTnNcCy&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;A::u01@gtish.loc:rwaDxtTnNcCy&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[u01@GTISH.LOC@djwcentos7 ldap]$ cd root/&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;bash: cd: root/: access denied&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Any things set wrong?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 09:43:19 GMT</pubDate>
    <dc:creator>DDA</dc:creator>
    <dc:date>2025-06-04T09:43:19Z</dc:date>
    <item>
      <title>Linux LDAP User not have the right access to  NFS volume directory with NFSv4 ACL</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Linux-LDAP-User-not-have-the-right-access-to-NFS-volume-directory-with-NFSv4-ACL/m-p/449386#M42990</link>
      <description>&lt;P&gt;After deploy the environment by "&lt;STRONG&gt;How to configure LDAP in ONTAP&amp;nbsp;&lt;/STRONG&gt;TR-4835"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1. Windows server 2019 with LDAP services&lt;/P&gt;&lt;P&gt;2. CentOS7 client use sssd and realm add to the AD Domain, and use two methods according to TR, shows below&lt;/P&gt;&lt;P data-unlink="true"&gt;[root@centos7 ~]# id u01&lt;BR /&gt;uid=2000(u01) gid=3000(Domain Users) groups=3000(Domain Users)&lt;BR /&gt;[root@centos7 ~]# id u01@gtish.loc&lt;BR /&gt;uid=1596602150(u01@GTISH.LOC) gid=1596600513(domain users@GTISH.LOC) groups=1596600513(domain users@GTISH.LOC),1596602153(all test users@GTISH.LOC)&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. From ONTAP SVM, the name services query returns correct results, shows below&lt;/P&gt;&lt;P&gt;::*&amp;gt; getxxbyyy getpwbyname -node FAS2750-01 -vserver SVM_LDAP -show-source true -use-cache false -username u01&lt;BR /&gt;(vserver services name-service getxxbyyy getpwbyname)&lt;BR /&gt;Source used for lookup: LDAP&lt;BR /&gt;pw_name: u01&lt;BR /&gt;pw_passwd:&lt;BR /&gt;pw_uid: 2000&lt;BR /&gt;pw_gid: 3000&lt;BR /&gt;pw_gecos:&lt;BR /&gt;pw_dir:&lt;BR /&gt;pw_shell: /bin/bash&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Problem&lt;/STRONG&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;The LDAP user u01@gtish.loc&amp;nbsp;cannot access the directory in the ONTAP NFS volume with NFSv4 ACL, shows below&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[u01@GTISH.LOC@centos7 ldap]$ nfs4_getfacl root&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;# file: root&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;A::OWNER@:rwaDxtTnNcCy&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;A::u01@gtish.loc:rwaDxtTnNcCy&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;[u01@GTISH.LOC@djwcentos7 ldap]$ cd root/&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;bash: cd: root/: access denied&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Any things set wrong?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:43:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Linux-LDAP-User-not-have-the-right-access-to-NFS-volume-directory-with-NFSv4-ACL/m-p/449386#M42990</guid>
      <dc:creator>DDA</dc:creator>
      <dc:date>2025-06-04T09:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Linux LDAP User not have the right access to  NFS volume directory with NFSv4 ACL</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Linux-LDAP-User-not-have-the-right-access-to-NFS-volume-directory-with-NFSv4-ACL/m-p/449445#M43000</link>
      <description>&lt;P&gt;Using the root user, what does "ls -la" show for that volume/the files in the volume?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your NFSv4 configuration might be wrong. If the owner shows "nobody" or "nfsnobody" then you need to fix the v4 config. TR-4067 covers it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.netapp.com/pdf.html?item=/media/10720-tr-4067.pdf" target="_blank"&gt;https://www.netapp.com/pdf.html?item=/media/10720-tr-4067.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 15:08:48 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Linux-LDAP-User-not-have-the-right-access-to-NFS-volume-directory-with-NFSv4-ACL/m-p/449445#M43000</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2023-12-04T15:08:48Z</dc:date>
    </item>
  </channel>
</rss>

