<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ONTAP S3 Access 9.15.1P15 with AD Group in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-S3-Access-9-15-1P15-with-AD-Group/m-p/463945#M45203</link>
    <description>&lt;P&gt;I have created object-store-server on a Scaleout cluster ( Ontap 9.15.1P15). i created Buckets and can able to access with local user. Required help on AD group&amp;nbsp; &amp;nbsp;integration for the Bucket. Do we require LDAP integration for the Object_store_SVM?&lt;/P&gt;&lt;P&gt;Not able to access TR 4814 in NetApp site and is unavailable&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i try to add the ad group iam getting the bellow error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TestCluster::*&amp;gt; object-store-server bucket policy statement create -vserver testsvm -bucket adbucket -effect allow -action GetObject,PutObject,DeleteObject,ListBucket,GetBucketAcl,GetObjectAcl,ListBucketMultipartUploads,ListMultipartUploadParts,GetObjectTagging,PutObjectTagging,DeleteObjectTagging,GetBucketLocation,GetBucketVersioning,PutBucketVersioning,ListBucketVersions,GetBucketPolicy,PutBucketPolicy,DeleteBucketPolicy,PutLifecycleConfiguration,GetLifecycleConfiguration&amp;nbsp; -principal ITA/GROUP_TSA_DP&lt;BR /&gt;&amp;nbsp; (vserver object-store-server bucket policy statement create)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error: Specified user name or group name "ITA/GROUP_TSA_DP" is not valid. Valid characters for a user&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; name or group name are 0-9, A-Z, a-z, "_", "+", "=", ",", ".", "@", and "-". Valid syntax for an S3 group is&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "group/&amp;lt;group-name&amp;gt;". Valid syntax for a NAS group is "nasgroup/&amp;lt;group-name&amp;gt;".&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "ITA/GROUP_TSA_DP" is an invalid value for field "-principal &amp;lt;Object Store Principal&amp;gt;", ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;KP Karthik&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Oct 2025 00:56:35 GMT</pubDate>
    <dc:creator>KPKarthik1</dc:creator>
    <dc:date>2025-10-30T00:56:35Z</dc:date>
    <item>
      <title>ONTAP S3 Access 9.15.1P15 with AD Group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-S3-Access-9-15-1P15-with-AD-Group/m-p/463945#M45203</link>
      <description>&lt;P&gt;I have created object-store-server on a Scaleout cluster ( Ontap 9.15.1P15). i created Buckets and can able to access with local user. Required help on AD group&amp;nbsp; &amp;nbsp;integration for the Bucket. Do we require LDAP integration for the Object_store_SVM?&lt;/P&gt;&lt;P&gt;Not able to access TR 4814 in NetApp site and is unavailable&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i try to add the ad group iam getting the bellow error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TestCluster::*&amp;gt; object-store-server bucket policy statement create -vserver testsvm -bucket adbucket -effect allow -action GetObject,PutObject,DeleteObject,ListBucket,GetBucketAcl,GetObjectAcl,ListBucketMultipartUploads,ListMultipartUploadParts,GetObjectTagging,PutObjectTagging,DeleteObjectTagging,GetBucketLocation,GetBucketVersioning,PutBucketVersioning,ListBucketVersions,GetBucketPolicy,PutBucketPolicy,DeleteBucketPolicy,PutLifecycleConfiguration,GetLifecycleConfiguration&amp;nbsp; -principal ITA/GROUP_TSA_DP&lt;BR /&gt;&amp;nbsp; (vserver object-store-server bucket policy statement create)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error: Specified user name or group name "ITA/GROUP_TSA_DP" is not valid. Valid characters for a user&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; name or group name are 0-9, A-Z, a-z, "_", "+", "=", ",", ".", "@", and "-". Valid syntax for an S3 group is&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "group/&amp;lt;group-name&amp;gt;". Valid syntax for a NAS group is "nasgroup/&amp;lt;group-name&amp;gt;".&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "ITA/GROUP_TSA_DP" is an invalid value for field "-principal &amp;lt;Object Store Principal&amp;gt;", ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;KP Karthik&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 00:56:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-S3-Access-9-15-1P15-with-AD-Group/m-p/463945#M45203</guid>
      <dc:creator>KPKarthik1</dc:creator>
      <dc:date>2025-10-30T00:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: ONTAP S3 Access 9.15.1P15 with AD Group</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-S3-Access-9-15-1P15-with-AD-Group/m-p/464326#M45212</link>
      <description>&lt;P&gt;I added Ldap access to vserver and added domain users for the Object store vserver&lt;/P&gt;&lt;P&gt;used bellow NetApp document&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/s3-config/generate-access-keys-api.html#configure-users-for-access-key-generation" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/s3-config/generate-access-keys-api.html#configure-users-for-access-key-generation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 13:06:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/ONTAP-S3-Access-9-15-1P15-with-AD-Group/m-p/464326#M45212</guid>
      <dc:creator>KPKarthik1</dc:creator>
      <dc:date>2025-11-12T13:06:35Z</dc:date>
    </item>
  </channel>
</rss>

