<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unix to Mixed security style change in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Unix-to-Mixed-security-style-change/m-p/455883#M44112</link>
    <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you are wrong to set security to mixed, you should set it to unix or ntfs&lt;/P&gt;&lt;P&gt;You can follow the links below to determine the security you want to set&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/nfs-admin/decide-security-style-svm-flexvol-concept.html" target="_blank"&gt;Decide which security style to use on SVMs (netapp.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/nfs-admin/security-styles-their-effects-concept.html" target="_blank"&gt;Security styles and their effects (netapp.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Oct 2024 01:50:35 GMT</pubDate>
    <dc:creator>Ashun</dc:creator>
    <dc:date>2024-10-18T01:50:35Z</dc:date>
    <item>
      <title>Unix to Mixed security style change</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Unix-to-Mixed-security-style-change/m-p/453658#M43745</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created new SVM with root volume and data volumes with UNIX security style. While creating the volumes, the requirement was limited to NFS access only. Now the new requirement requires CIFS access too. I have a volume lets say volume_nfs, under that there is a qtree lets say volume_nfs_qtree. Security style for both volume and qtree is UNIX. There are no other file or folder under volume volume_nfs except volume_nfs_qtree. Currently only NFS export is configured on this volume.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I am thinking to change security style of qtree volume_nfs_qtree to mixed from UNIX and I will keep security style of volume volume_nfs unchanged.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that a right approach? I am worried what if it changes file permissions and application starts seeing issues with the file access. Please advice on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 06:37:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Unix-to-Mixed-security-style-change/m-p/453658#M43745</guid>
      <dc:creator>Pkumawat</dc:creator>
      <dc:date>2024-07-04T06:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unix to Mixed security style change</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Unix-to-Mixed-security-style-change/m-p/453660#M43746</link>
      <description>&lt;P&gt;Don’t do it. Nothing ever good comes out of using mixed mode. I call it “last one to set security wins”. And by this I mean: ONTAP only supports a single set of permissions in files/directories. Either Unix permissions or nt ACLs. Not both. I can set Unix permissions then someone can come in ABBA set an acl and restrict. Then troubleshooting security becomes a nightmare.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;set up an ldap client for the svm. Make sure your Active Directory schema includes uid, number and gidnumber.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;review the Netapp multi protocol tr&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 10:41:27 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Unix-to-Mixed-security-style-change/m-p/453660#M43746</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2024-07-04T10:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unix to Mixed security style change</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Unix-to-Mixed-security-style-change/m-p/455883#M44112</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you are wrong to set security to mixed, you should set it to unix or ntfs&lt;/P&gt;&lt;P&gt;You can follow the links below to determine the security you want to set&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/nfs-admin/decide-security-style-svm-flexvol-concept.html" target="_blank"&gt;Decide which security style to use on SVMs (netapp.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/nfs-admin/security-styles-their-effects-concept.html" target="_blank"&gt;Security styles and their effects (netapp.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 01:50:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Unix-to-Mixed-security-style-change/m-p/455883#M44112</guid>
      <dc:creator>Ashun</dc:creator>
      <dc:date>2024-10-18T01:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unix to Mixed security style change</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Unix-to-Mixed-security-style-change/m-p/455917#M44129</link>
      <description>&lt;P&gt;As all mentioned, MIXED is not needed for multiprotocol access.&amp;nbsp; &amp;nbsp;Multiprotocol access is available on any security style.&amp;nbsp; That the security style represents is the management of the permissions.&amp;nbsp; For UNIX style, NFSv3 perms (mode bits) or NFSv4 ACLs are used to secure the files.&amp;nbsp; Windows users will need to map to a unix user via AD &amp;amp; LDAP.&amp;nbsp; &amp;nbsp;For NTFS style, NTFS ACLs are used to secure the files and NFS users will need to map to a Windows user via AD &amp;amp; LDAP.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 18:14:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Unix-to-Mixed-security-style-change/m-p/455917#M44129</guid>
      <dc:creator>chris_hurley</dc:creator>
      <dc:date>2024-10-18T18:14:39Z</dc:date>
    </item>
  </channel>
</rss>

