<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NFSv4 ACLs on RHEL? in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19848#M4652</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I still can't get ACL's to work with domain users (both the Filer and the Linux client have access to the same LDAP/AD directory).&amp;nbsp; I get the "Failed setxattr operation" error.&amp;nbsp; Anyone doing this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Nov 2012 15:43:31 GMT</pubDate>
    <dc:creator>JOSHBAIRD</dc:creator>
    <dc:date>2012-11-26T15:43:31Z</dc:date>
    <item>
      <title>NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19838#M4649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm having trouble using NFSv4 ACL's on RHEL6 from an exported volume with NFSv4+ACLs enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the client:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;filer:/vol/vol4/share on /mnt/eportal type nfs4 (rw,rsize=65536,wsize=65536,hard,intr,proto=tcp,timeo=600,retrans=3,sec=sys,acl)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is my understanding that I must use "nfs4_setfacl" on RHEL, because the POSIX enabled "setfacl" command does not work for NFSv4 ACLs.&amp;nbsp; Whenever I try to use nfs4_setfacl to configure an ACL on a file/directory on the exported filesystem, I get the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;$ nfs4_setfacl -a A::jbaird@:rwatTnNcCy hi&lt;/P&gt;&lt;P&gt;Failed setxattr operation: Invalid argument&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The documentation on this matter is very sparse, and I can't really find much.&amp;nbsp; Can anyone offer some assistance?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:14:51 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19838#M4649</guid>
      <dc:creator>JOSHBAIRD</dc:creator>
      <dc:date>2025-06-05T06:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19844#M4651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, this appears to be because the user that I am trying to configure the ACL with is a local user on the Linux system which is NOT on the Filer (in /etc/passwd, LDAP or NIS).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 15:13:32 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19844#M4651</guid>
      <dc:creator>JOSHBAIRD</dc:creator>
      <dc:date>2012-11-26T15:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19848#M4652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I still can't get ACL's to work with domain users (both the Filer and the Linux client have access to the same LDAP/AD directory).&amp;nbsp; I get the "Failed setxattr operation" error.&amp;nbsp; Anyone doing this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2012 15:43:31 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19848#M4652</guid>
      <dc:creator>JOSHBAIRD</dc:creator>
      <dc:date>2012-11-26T15:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19853#M4653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I know this is, like, 5 months after you wanted an answer, but in case you're still trying to get this to work, the issue is with the command syntax.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You did not specify your NFSv4 domain after your username.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run the command like you ran it, I get the same issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# nfs4_setfacl -a A::ldapuser@:rwatTnNcCy file&lt;/P&gt;&lt;P&gt;Failed setxattr operation: Invalid argument&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run it with an nfsv4 domain specified, it works fine:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;# nfs4_setfacl -a A::&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:ldapuser@parisiwin2k3.netapp.com" target="_blank"&gt;ldapuser@parisiwin2k3.netapp.com&lt;/A&gt;&lt;SPAN&gt;:rwatTnNcCy newkrb5 --test&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;## Test mode only - the resulting ACL for "/vfileralias/newkrb5":&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A::&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:ldapuser@parisiwin2k3.netapp.com" target="_blank"&gt;ldapuser@parisiwin2k3.netapp.com&lt;/A&gt;&lt;SPAN&gt;:rwatTnNcCy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;A::OWNER@:rwatTnNcCy&lt;/P&gt;&lt;P&gt;D::OWNER@:x&lt;/P&gt;&lt;P&gt;A:g:GROUP@:rtncy&lt;/P&gt;&lt;P&gt;D:g:GROUP@:waxTC&lt;/P&gt;&lt;P&gt;A::EVERYONE@:rtncy&lt;/P&gt;&lt;P&gt;D::EVERYONE@:waxTC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 19:42:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19853#M4653</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2013-03-12T19:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19856#M4654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Parisi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have still the same problem - with the same syntax as in your example.&lt;/P&gt;&lt;P&gt;# nfs4_setfacl -a A::&lt;A class="jive-link-email-small" href="mailto:ldapuser@parisiwin2k3.netapp.com" target="_blank"&gt;ldapuser@parisiwin2k3.netapp.com&lt;/A&gt;:rwatTnNcCy newkrb5 &lt;SPAN style="text-decoration: underline;"&gt;--test&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with the parameter --test - at the end of the command - everything looks ok !&lt;/P&gt;&lt;P&gt;but without the --test parameter we get still the same problem&lt;/P&gt;&lt;P&gt;# nfs4_setfacl -a A::&lt;A class="jive-link-email-small" href="mailto:ldapuser@parisiwin2k3.netapp.com" target="_blank"&gt;ldapuser@parisiwin2k3.netapp.com&lt;/A&gt;:rwatTnNcCy newkrb5 &lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; Failed setxattr operation: Invalid argument&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have used our own user and domain name!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas ?&lt;/P&gt;&lt;P&gt;thanks a lot &lt;/P&gt;&lt;P&gt;christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 14:59:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19856#M4654</guid>
      <dc:creator>ccie5863</dc:creator>
      <dc:date>2013-08-08T14:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19861#M4655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post the output from your commands? And then tail the last 100 lines of /var/log/messages on the client?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 15:05:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19861#M4655</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2013-08-08T15:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19865#M4656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Parisi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see here our commands and the outputs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;root@pslab-deb1:~# mount&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.99.4.153:/vol/nfsv4 on /mnt/b2 type nfs4 (rw,relatime,vers=4,rsize=65536,wsize=65536,namlen=255,hard,proto=tcp,port=0,timeo=600,retrans=2,sec=sys,clientaddr=10.99.191.41,minorversion=0,local_lock=none,addr=10.99.4.153)&lt;/P&gt;&lt;P&gt;root@pslab-deb1:~#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;root@pslab-deb1:~# nfs4_getfacl /mnt/b2&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rw&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rw&lt;/P&gt;&lt;P&gt;A::OWNER@:rwaDxtTnNcCy&lt;/P&gt;&lt;P&gt;D::OWNER@:&lt;/P&gt;&lt;P&gt;A:g:GROUP@:rwaDxtTnNcCy&lt;/P&gt;&lt;P&gt;D:g:GROUP@:&lt;/P&gt;&lt;P&gt;A::EVERYONE@:rwaDxtTnNcCy&lt;/P&gt;&lt;P&gt;D::EVERYONE@:&lt;/P&gt;&lt;P&gt;root@pslab-deb1:~#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;root@pslab-deb1:~# cd /mnt/b2/&lt;/P&gt;&lt;P&gt;root@pslab-deb1:/mnt/b2# nfs4_setfacl -a A::peter@pslab.nfs:rwatTnNcCy /mnt/b2 test --test&lt;/P&gt;&lt;OL&gt;&lt;OL&gt;&lt;LI level="2" type="ol"&gt;&lt;P&gt;Test mode only - the resulting ACL for "/mnt/b2":&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;A::peter@pslab.nfs:rwatTnNcCy&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rw&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rw&lt;/P&gt;&lt;P&gt;A::OWNER@:rwaDxtTnNcCy&lt;/P&gt;&lt;P&gt;D::OWNER@:&lt;/P&gt;&lt;P&gt;A:g:GROUP@:rwaDxtTnNcCy&lt;/P&gt;&lt;P&gt;D:g:GROUP@:&lt;/P&gt;&lt;P&gt;A::EVERYONE@:rwaDxtTnNcCy&lt;/P&gt;&lt;P&gt;D::EVERYONE@:&lt;/P&gt;&lt;OL&gt;&lt;OL&gt;&lt;LI level="2" type="ol"&gt;&lt;P&gt;Test mode only - the resulting ACL for "/mnt/b2/test":&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;A::peter@pslab.nfs:rwatTnNcCy&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rw&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rwatTnNcCy&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rwatTnNcCy&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rwatTnNcCy&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rwatTnNcCy&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rwatTnNcCy&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rwatTnNcCy&lt;/P&gt;&lt;P&gt;A::root@pslab.nfs:rw&lt;/P&gt;&lt;P&gt;A::OWNER@:rwatTnNcCy&lt;/P&gt;&lt;P&gt;D::OWNER@:x&lt;/P&gt;&lt;P&gt;A:g:GROUP@:rtncy&lt;/P&gt;&lt;P&gt;D:g:GROUP@:waxTC&lt;/P&gt;&lt;P&gt;A::EVERYONE@:rtncy&lt;/P&gt;&lt;P&gt;D::EVERYONE@:waxTC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;root@pslab-deb1:/mnt/b2# nfs4_setfacl -a A::peter@pslab.nfs:rwatTnNcCy /mnt/b2 test&lt;/P&gt;&lt;P&gt;Failed setxattr operation: Invalid argument&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your Background:&lt;/P&gt;&lt;P&gt;The nfs storage is a netapp FAS – Data Ontap 7.3.7&lt;/P&gt;&lt;P&gt;swsbnap3&amp;gt; options nfs.v4&lt;/P&gt;&lt;P&gt;nfs.v4.acl.enable            on&lt;/P&gt;&lt;P&gt;nfs.v4.enable                on&lt;/P&gt;&lt;P&gt;nfs.v4.id.allow_numerics     on&lt;/P&gt;&lt;P&gt;nfs.v4.id.domain             pslab.nfs&lt;/P&gt;&lt;P&gt;nfs.v4.read_delegation       off&lt;/P&gt;&lt;P&gt;nfs.v4.write_delegation      off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nfs : domain pslab.nfs&lt;/P&gt;&lt;P&gt;Active Directory : pslab.local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the /var/log/messages file is empty&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can provide a teamviewer session to the onlinesystems&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 15:29:16 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19865#M4656</guid>
      <dc:creator>ccie5863</dc:creator>
      <dc:date>2013-08-08T15:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19869#M4658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using LDAP on the AD server? Is AD the NFSv4 ID mapping domain?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's LDAP, can you run:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# getent passwd peter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you restart rpcidmapd service and retry?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anything show up in the filer messages?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you get a packet trace on the client of the failed ACL set?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 15:55:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19869#M4658</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2013-08-08T15:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19873#M4660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Parisi&lt;/P&gt;&lt;P&gt;I am Out oft the Office now and will be back tomorrow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will Provide all the Infos for you.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 16:04:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19873#M4660</guid>
      <dc:creator>ccie5863</dc:creator>
      <dc:date>2013-08-08T16:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19879#M4662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;today I changed the Name of my NFS Domain from PSLAB.NFS to PSLAB.LOCAL. So DNS, AD and NFS are using the same Name. Then I installed a Debian 6, because in Debian 7 are some Bugs with rpc.imapd.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;It seems Idmapd on Debian is rpc.idmapd. There is no init.d script for the service. I think the only way to start and stop is "start-stop-daemon --start --oknodo --quiet --exec /usr/sbin/rpc.idmapd" and "start-stop-daemon --stop --oknodo --quiet --exec /usr/sbin/rpc.idmapd". &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;But with "rpc.idmap -f -vvvvv" I can see that it is running now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your questions: I have no ldap connection from my debian host. I'm usin krb5. "kinit peter" shows no errors after I entered the Password and with kpasswd i can change the pass of my AD Users. &lt;/P&gt;&lt;P&gt;I can't see anything about my error in the Logfiles. Not on the Debian Host and not on my Filer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are some of my config files and console outputs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;swsbnap3&amp;gt; options nfs.v4&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;nfs.v4.acl.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;/P&gt;&lt;P&gt;nfs.v4.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;/P&gt;&lt;P&gt;nfs.v4.id.allow_numerics&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;/P&gt;&lt;P&gt;nfs.v4.id.domain&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PSLAB.LOCAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;---- I changed this today&lt;/P&gt;&lt;P&gt;nfs.v4.read_delegation&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;/P&gt;&lt;P&gt;nfs.v4.write_delegation&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;swsbnap3&amp;gt; rdfile /etc/exports&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;/vol/nfsv4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -sec=krb5:sys,rw,root=10.99.191.43&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;swsbnap3&amp;gt; rdfile /etc/nsswitch.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;hosts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; files&amp;nbsp; dns&amp;nbsp;&amp;nbsp; nis&lt;/P&gt;&lt;P&gt;passwd:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; files&amp;nbsp; ldap&lt;/P&gt;&lt;P&gt;netgroup:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; files&amp;nbsp; nis&lt;/P&gt;&lt;P&gt;group:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; files&amp;nbsp; ldap&lt;/P&gt;&lt;P&gt;shadow:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; files&amp;nbsp; ldap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;swsbnap3&amp;gt; cifs testdc&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Using Established configuration&lt;/P&gt;&lt;P&gt;Current Mode of NBT is B Mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Netbios scope ""&lt;/P&gt;&lt;P&gt;Registered names...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SWSBNAP3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt; 0&amp;gt; Broadcast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SWSBNAP3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt; 3&amp;gt; Broadcast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SWSBNAP3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;20&amp;gt; Broadcast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PSLAB&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt; 0&amp;gt; Broadcast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Testing all Primary Domain Controllers&lt;/P&gt;&lt;P&gt;found 1 unique addresses&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;found PDC PSLAB-DC1 at 10.99.191.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Testing all Domain Controllers&lt;/P&gt;&lt;P&gt;found 1 unique addresses&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;found DC PSLAB-DC1 at 10.99.191.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;root@pslab-deb3:~# klist&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Ticket cache: FILE:/tmp/krb5cc_0&lt;/P&gt;&lt;P&gt;Default principal: peter@PSLAB.LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Valid starting&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Expires&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service principal&lt;/P&gt;&lt;P&gt;08/09/13 17:14:34&amp;nbsp; 08/09/13 23:54:34&amp;nbsp; krbtgt/PSLAB.LOCAL@PSLAB.LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;root@pslab-deb3:~# cat /etc/idmapd.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[General]&lt;/P&gt;&lt;P&gt;# Verbosity = 0&lt;/P&gt;&lt;P&gt;# Pipefs-Directory = /var/lib/nfs/rpc_pipefs&lt;/P&gt;&lt;P&gt;Domain = PSLAB.LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;root@pslab-deb3:~# cat /etc/nsswitch.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;passwd:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; files ldap compat&lt;/P&gt;&lt;P&gt;group:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; compat&lt;/P&gt;&lt;P&gt;shadow:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; files ldap compat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hosts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; files dns&lt;/P&gt;&lt;P&gt;networks:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; files&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;protocols:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; db files&lt;/P&gt;&lt;P&gt;services:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; db files&lt;/P&gt;&lt;P&gt;ethers:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; db files&lt;/P&gt;&lt;P&gt;rpc:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; db files&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;netgroup:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;root@pslab-deb3:~# cat /etc/krb5.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[logging]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Default = FILE:/var/log/krb5.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[libdefaults]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ticket_lifetime = 24000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; clock-skew = 300&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default_realm = PSLAB.LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[realms]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PSALB.LOCAL = {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; kdc = pslab-dc1.pslab.local:88&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; admin_server = pslab-dc1.pslab.local:464&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default_domain = pslab.local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[domain_realm]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; .pslab.local = PSLAB.LOCAL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; pslab.local = PSLAB.LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;root@pslab-deb3:~# ls -l /mnt/b2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;insgesamt 4&lt;/P&gt;&lt;P&gt;drwxr-xr-x 2 4294967294 4294967294 4096&amp;nbsp; 9. Aug 17:39 folder&lt;/P&gt;&lt;P&gt;-rw-r--r-- 1 4294967294 4294967294&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; 2. Aug 15:57 test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;root@pslab-deb3:~# mount&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;10.99.4.153:/vol/nfsv4 on /mnt/b2 type nfs4 (rw,addr=10.99.4.153,clientaddr=10.99.191.43)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your Help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 15:53:25 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19879#M4662</guid>
      <dc:creator>ccie5863</dc:creator>
      <dc:date>2013-08-09T15:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19885#M4663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With NFSv4, simply naming the domain isn't enough. You have to have one to one mapping of username@nfsv4iddomain to UID. The NFS client and NFS server both need to be able to come to the same conclusion about the name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're using no name service server (like LDAP or NIS) and are relying only on local files, then there needs to be an entry for the user on the storage's passwd file and the client's passwd file. These entries must match EXACTLY.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ID you see in ls -l means NFSv4 isn't even working at all. That resolves to nobody:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.novell.com/support/kb/doc.php?id=7005060" title="http://www.novell.com/support/kb/doc.php?id=7005060" target="_blank"&gt;http://www.novell.com/support/kb/doc.php?id=7005060&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create an entry for your username in the passwd files on the client and server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@centos64 /]# cat /etc/passwd | grep peter&lt;/P&gt;&lt;P&gt;peter:x:101:1::/:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@centos64 /]# passwd peter&lt;/P&gt;&lt;P&gt;Changing password for user peter.&lt;/P&gt;&lt;P&gt;New password:&lt;/P&gt;&lt;P&gt;BAD PASSWORD: it is based on a dictionary word&lt;/P&gt;&lt;P&gt;Retype new password:&lt;/P&gt;&lt;P&gt;passwd: all authentication tokens updated successfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@centos64 /]# mount 10.61.72.35:/vol/unix /tmp&lt;/P&gt;&lt;P&gt;[root@centos64 /]# mount | grep /tmp&lt;/P&gt;&lt;P&gt;10.61.72.35:/vol/unix on /tmp type nfs (rw,&lt;STRONG&gt;vers=4&lt;/STRONG&gt;,addr=10.61.72.35,clientaddr=10.61.179.150)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@centos64 /]# cd /tmp&lt;/P&gt;&lt;P&gt;[root@centos64 tmp]# ls -la&lt;/P&gt;&lt;P&gt;total 12&lt;/P&gt;&lt;P&gt;drwxr-xr-x.&amp;nbsp; 3 root root 4096 Aug&amp;nbsp; 5 12:27 .&lt;/P&gt;&lt;P&gt;dr-xr-xr-x. 26 root root 4096 Aug&amp;nbsp; 8 16:10 ..&lt;/P&gt;&lt;P&gt;drwxrwxrwx. 10 root root 4096 Aug&amp;nbsp; 9 09:00 .snapshot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that when I login as "peter" and write a file, it lets me write but the UID is "nobody":&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@centos64 tmp]# su peter&lt;/P&gt;&lt;P&gt;sh-4.1$ cd /tmp&lt;/P&gt;&lt;P&gt;sh-4.1$ touch file&lt;/P&gt;&lt;P&gt;sh-4.1$ ls -la | grep file&lt;/P&gt;&lt;P&gt;-rw-r--r--.&amp;nbsp; 1 nobody daemon&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 Aug&amp;nbsp; 9&amp;nbsp; 2013 file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thisis defined in idmapd.conf:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@centos64 /]# cat /etc/idmapd.conf&lt;/P&gt;&lt;P&gt;[General]&lt;/P&gt;&lt;P&gt;Domain = domain.win2k8.netapp.com&lt;/P&gt;&lt;P&gt;[Mapping]&lt;/P&gt;&lt;P&gt;Nobody-User = nobody&lt;/P&gt;&lt;P&gt;Nobody-Group = nobody&lt;/P&gt;&lt;P&gt;[Translation]&lt;/P&gt;&lt;P&gt;Method = nsswitch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The fact that the user can't map would also affect me applying NFSv4 ACLs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[root@centos64 /]# nfs4_setfacl -a A::&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:peter@domain.win2k8.netapp.com" target="_blank"&gt;peter@domain.win2k8.netapp.com&lt;/A&gt;&lt;SPAN&gt;:rwatTnNcCy /mnt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Failed setxattr operation: Invalid argument&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 options to fix this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option #1: Create an LDAP server to manage your UIDs and users (best option)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Option #2:&amp;nbsp; Add the user to the client's passwd file and server/filer's passwd file (and the entry must be EXACTLY the same):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fas3170-rtp*&amp;gt; wrfile -a /etc/passwd peter::101:2:/:&lt;/P&gt;&lt;P&gt;fas3170-rtp*&amp;gt; rdfile /etc/passwd&lt;/P&gt;&lt;P&gt;root:_J9..LnoxwdFuzh81UF6:0:1::/:&lt;/P&gt;&lt;P&gt;pcuser::65534:65534::/:&lt;/P&gt;&lt;P&gt;nobody::65535:65535::/:&lt;/P&gt;&lt;P&gt;ftp::65533:65533:FTP Anonymous:/home/ftp:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;peter:x:101:1:/:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@centos64 tmp]# cat /etc/passwd | grep peter&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;peter:x:101:1::/:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@centos64 /]# umount /tmp&lt;/P&gt;&lt;P&gt;[root@centos64 /]# mount 10.61.72.35:/vol/unix /tmp&lt;/P&gt;&lt;P&gt;[root@centos64 /]# cd /tmp&lt;/P&gt;&lt;P&gt;[root@centos64 tmp]# ls -la&lt;/P&gt;&lt;P&gt;total 12&lt;/P&gt;&lt;P&gt;drwxrwxrwx.&amp;nbsp; 3 root&amp;nbsp; nobody 4096 Aug&amp;nbsp; 9 12:20 .&lt;/P&gt;&lt;P&gt;dr-xr-xr-x. 26 root&amp;nbsp; root&amp;nbsp;&amp;nbsp; 4096 Aug&amp;nbsp; 8 16:10 ..&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-rw-r--r--.&amp;nbsp; 1 peter daemon&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 Aug&amp;nbsp; 9 12:20 file&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;drwxrwxrwx. 10 root&amp;nbsp; nobody 4096 Aug&amp;nbsp; 9 09:00 .snapshot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; After this, I can apply ACLs, but only if I use the @domain:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[root@centos64 /]# nfs4_setfacl -a A::peter:rwatTnNcCy /tmp&lt;/P&gt;&lt;P&gt;Failed setxattr operation: Invalid argument&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[root@centos64 /]# nfs4_setfacl -a A::&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:peter@domain.win2k8.netapp.com" target="_blank"&gt;peter@domain.win2k8.netapp.com&lt;/A&gt;&lt;SPAN&gt;:rwatTnNcCy /tmp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[root@centos64 /]# nfs4_getfacl /tmp&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;A::&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:peter@domain.win2k8.netapp.com" target="_blank"&gt;peter@domain.win2k8.netapp.com&lt;/A&gt;&lt;SPAN&gt;:rwatTnNcCy&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A::&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:peter@domain.win2k8.netapp.com" target="_blank"&gt;peter@domain.win2k8.netapp.com&lt;/A&gt;&lt;SPAN&gt;:rw&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;A::OWNER@:rwaDxtTnNcCy&lt;/P&gt;&lt;P&gt;D::OWNER@:&lt;/P&gt;&lt;P&gt;A:g:GROUP@:rwaDxtTnNcCy&lt;/P&gt;&lt;P&gt;D:g:GROUP@:&lt;/P&gt;&lt;P&gt;A::EVERYONE@:rwaDxtTnNcCy&lt;/P&gt;&lt;P&gt;D::EVERYONE@:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Once you get NFSv4 working properly and usernames showing up in ls output, ACLs should start working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 17:04:50 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19885#M4663</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2013-08-09T17:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19891#M4664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I understand. Then I have to configure a LDAP connection to my AD on the Filer and the Linux Host?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 20:01:36 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19891#M4664</guid>
      <dc:creator>ccie5863</dc:creator>
      <dc:date>2013-08-09T20:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: NFSv4 ACLs on RHEL?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19897#M4665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, you need a name mapping service. That could be LDAP, local files or NIS. Just something that the NFSv4 domain can use to map users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LDAP would be the easiest to set up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out this TR for details on Windows AD LDAP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.netapp.com/us/system/pdf-reader.aspx?m=tr-4073.pdf&amp;amp;cc=us" title="http://www.netapp.com/us/system/pdf-reader.aspx?m=tr-4073.pdf&amp;amp;cc=us" target="_blank"&gt;http://www.netapp.com/us/system/pdf-reader.aspx?m=tr-4073.pdf&amp;amp;cc=us&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a cDOT specific TR, but the LDAP portion applies to all environments.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 20:05:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFSv4-ACLs-on-RHEL/m-p/19897#M4665</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2013-08-09T20:05:30Z</dc:date>
    </item>
  </channel>
</rss>

