<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S3-Bucket Key Authentication in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/S3-Bucket-Key-Authentication/m-p/450513#M10008</link>
    <description>&lt;P&gt;S3 uses its own key pairs and there's no way to "map" them to some other keys stored on ONTAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to build some client-side stuff that prompts the user to enter a password (for Active Directory, LDAP, password for encrypted Zip file, etc.) and get the S3 key pair from there or some other database, you may do that but S3 service doesn't know or care how it's done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;S3 API access must use a valid access &amp;amp; secret key. How you get it and whether you encrypt it or not is a client-side concern. There's nothing ONTAP S3-specific in this process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's an API that lets you create own keys, but again, how you store and access them is up to you.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/s3-config/generate-access-keys-api.html" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/s3-config/generate-access-keys-api.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In theory you could auth against LDAP and always create a new set of keys to access S3 without storing the key pair anywhere. But I'm not sure if there's a best practice for this (that is, if ONTAP S3 can tolerate everyone creating a new pair every time they use S3).&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jan 2024 09:21:19 GMT</pubDate>
    <dc:creator>elementx</dc:creator>
    <dc:date>2024-01-30T09:21:19Z</dc:date>
    <item>
      <title>S3-Bucket Key Authentication</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/S3-Bucket-Key-Authentication/m-p/450510#M10007</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Hello everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I would like to know if I can use a FAS 2720 and ONTAP 9.12 to share S3 buckets with public and private key authentication? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;The idea is that the client has the private key on his workstation and when he mounts the S3 share, the authentication is done with the encryption keys. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thanks for your help. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Neolitics&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:41:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/S3-Bucket-Key-Authentication/m-p/450510#M10007</guid>
      <dc:creator>Neolitics</dc:creator>
      <dc:date>2025-06-04T09:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: S3-Bucket Key Authentication</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/S3-Bucket-Key-Authentication/m-p/450513#M10008</link>
      <description>&lt;P&gt;S3 uses its own key pairs and there's no way to "map" them to some other keys stored on ONTAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to build some client-side stuff that prompts the user to enter a password (for Active Directory, LDAP, password for encrypted Zip file, etc.) and get the S3 key pair from there or some other database, you may do that but S3 service doesn't know or care how it's done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;S3 API access must use a valid access &amp;amp; secret key. How you get it and whether you encrypt it or not is a client-side concern. There's nothing ONTAP S3-specific in this process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's an API that lets you create own keys, but again, how you store and access them is up to you.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/s3-config/generate-access-keys-api.html" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/s3-config/generate-access-keys-api.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In theory you could auth against LDAP and always create a new set of keys to access S3 without storing the key pair anywhere. But I'm not sure if there's a best practice for this (that is, if ONTAP S3 can tolerate everyone creating a new pair every time they use S3).&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 09:21:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/S3-Bucket-Key-Authentication/m-p/450513#M10008</guid>
      <dc:creator>elementx</dc:creator>
      <dc:date>2024-01-30T09:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: S3-Bucket Key Authentication</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/S3-Bucket-Key-Authentication/m-p/450596#M10010</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Thank you elementx for your reply. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Your answer and the documentation provided in your reply will help me in my study. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Best wishes for 2024. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Philippe (Paris France)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 12:43:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/S3-Bucket-Key-Authentication/m-p/450596#M10010</guid>
      <dc:creator>Neolitics</dc:creator>
      <dc:date>2024-02-02T12:43:22Z</dc:date>
    </item>
  </channel>
</rss>

