<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fabric Pool on remote cluster in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/450731#M43234</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I've got one cluster with AFFs and remote cluster with FAS and SATA disks. I've created Object Store Server and a bucket on FAS system and I'm trying to add it as a cloud tier on AFF cluster but it keeps showing me the error: "Cannot verify availability of the object store from node * Reason: Cannot verify the certificate given by the object store server. It is possible that the certificate has not been installed on the cluster." I've installed certificate of the vserver holding the object store server on AFF cluster, but the error is still the same - does object store server has a separate certificate? Where can I find it? I've got intercluster connectivity tested and working. I've created separate intercluster LIF in the subnet created for S3 traffic as well.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 09:41:02 GMT</pubDate>
    <dc:creator>kombayn</dc:creator>
    <dc:date>2025-06-04T09:41:02Z</dc:date>
    <item>
      <title>Fabric Pool on remote cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/450731#M43234</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I've got one cluster with AFFs and remote cluster with FAS and SATA disks. I've created Object Store Server and a bucket on FAS system and I'm trying to add it as a cloud tier on AFF cluster but it keeps showing me the error: "Cannot verify availability of the object store from node * Reason: Cannot verify the certificate given by the object store server. It is possible that the certificate has not been installed on the cluster." I've installed certificate of the vserver holding the object store server on AFF cluster, but the error is still the same - does object store server has a separate certificate? Where can I find it? I've got intercluster connectivity tested and working. I've created separate intercluster LIF in the subnet created for S3 traffic as well.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:41:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/450731#M43234</guid>
      <dc:creator>kombayn</dc:creator>
      <dc:date>2025-06-04T09:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Fabric Pool on remote cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/450800#M43247</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/82817"&gt;@kombayn&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Can you advise which version of ONTAP you are using on both clusters?&lt;/LI&gt;&lt;LI&gt;Do you require Object store certificate validation? If not this should be able to be disabled.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The certificate that you need to put on your AFF system (w/ Fabric Pool) needs to be the SSL certificate that you have installed on the FAS' SVM that is hosting the S3 buckets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Run the command "security ssl show -vserver &amp;lt;S3_SVM&amp;gt; -instance" on your FAS (ONTAP S3 Server) to show you the SSL certificate that is installed on the HTTPS interface for that SVM.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 21:51:52 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/450800#M43247</guid>
      <dc:creator>chamfer</dc:creator>
      <dc:date>2024-02-14T21:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Fabric Pool on remote cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/450820#M43258</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/109513"&gt;@chamfer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your suggestions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running 9.12.1P8 on both clusters.&lt;/P&gt;&lt;P&gt;I think certificate validation is not required as this is the "internal" object store and traffic does not pass the internet - please, correct me if I'm wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My security ssl output on FAS looks like this:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;SSL Server Authentication Enabled: true&lt;/STRONG&gt;&lt;BR /&gt;SSL Client Authentication Enabled: false&lt;BR /&gt;Online Certificate Status Protocol Validation Enabled: false&lt;BR /&gt;URI of the Default Responder for OCSP Validation:&lt;BR /&gt;Force the Use of the Default Responder URI for OCSP Validation: false&lt;BR /&gt;Timeout for OCSP Queries: 10s&lt;BR /&gt;Maximum Allowable Age for OCSP Responses (secs): unlimited&lt;BR /&gt;Maximum Allowable Time Skew for OCSP Response Validation: 5m&lt;BR /&gt;Use a NONCE within OCSP Queries: true&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Your suggestion is to disable Server Authentication?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 12:34:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/450820#M43258</guid>
      <dc:creator>kombayn</dc:creator>
      <dc:date>2024-02-15T12:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Fabric Pool on remote cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/450827#M43261</link>
      <description>&lt;P&gt;&amp;gt; I think certificate validation is not required as this is the "internal" object store and traffic does not pass the internet - please, correct me if I'm wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Certificate validation is always required if you want to make sure it's a valid certificate.&lt;/P&gt;&lt;P&gt;p27 tells you how to reject the option to validate from the client (&lt;A href="https://www.netapp.com/pdf.html?item=/media/17239-tr-4598.pdf" target="_blank" rel="noopener"&gt;https://www.netapp.com/pdf.html?item=/media/17239-tr-4598.pdf&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Launch ONTAP System Manager.&lt;BR /&gt;2. Click STORAGE.&lt;BR /&gt;3. Click Tiers.&lt;BR /&gt;4. Click Add Cloud Tier.&lt;BR /&gt;5. Select an object store provider.&lt;BR /&gt;6. Complete the text fields as required for your object store provider.&lt;BR /&gt;7. Click the Object Store Certificate button to turn it off&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if you install CA cert of the CA used to issue &amp;amp; sign the TLS cert of FAS S3 on your S3 client (AFF), then it will be validated so you won't need that step. Or you could paste the FAS S3 TLS certificate alone when adding Object Store, but without CA loaded on the AFF there's no way to know if it was signed by a valid CA.&lt;/P&gt;&lt;P&gt;Also see `-is-certificate-validation-enabled false`, that is also in the PDF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you use valid certs, create calendar reminders to renew all certs in question, or issue them with a long duration.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 16:10:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/450827#M43261</guid>
      <dc:creator>elementx</dc:creator>
      <dc:date>2024-02-15T16:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: Fabric Pool on remote cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/451038#M43303</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/82817"&gt;@kombayn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You really need to take a risk based approach and understand the risk that you have around the requirement for SSL Server Authentication, understanding that this is best practice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the S3 Object Store is internal and the risk of it being replaced with another S3 Object Store that also has the same S3 credentials is low/near impossible (this would have to be an accident or insider threat), I would then disable Server Authentication......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is no risk appetite then you should get the certificates from the Object Store onto the Array performing Fabric Pool.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 05:33:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/451038#M43303</guid>
      <dc:creator>chamfer</dc:creator>
      <dc:date>2024-02-28T05:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Fabric Pool on remote cluster</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/451068#M43309</link>
      <description>&lt;P&gt;Thanks a lot for your explanations. I wasn't able to fix the problem with certificate, but I attached cloud tier without certificate validation and (thanks to your explanations) I know it will be safe in my environment&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 12:20:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Fabric-Pool-on-remote-cluster/m-p/451068#M43309</guid>
      <dc:creator>kombayn</dc:creator>
      <dc:date>2024-02-28T12:20:11Z</dc:date>
    </item>
  </channel>
</rss>

