<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access NetApp from several Domain (via CIFS) in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31274#M2824</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some clarification is needed here, I think.&lt;/P&gt;&lt;P&gt;Authentication can be confusing in modern Data ONTAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I know ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two different sets of local users kept in Data ONTAP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RBAC users kept in the registry and managed with the 'useradmin' command.&lt;/P&gt;&lt;P&gt;These are the users used for Workgroup type authentication. Passwords can be&lt;/P&gt;&lt;P&gt;managed with the 'passwd' command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/etc/passwd users. There is no shadow file - passwords are kept in /etc/passwd.&lt;/P&gt;&lt;P&gt;/etc/passwd will be used for multiprotocol user mapping and for cifs authentication&lt;/P&gt;&lt;P&gt;in a non-windows workgroup ( /etc/passwd ) cifs setup and FTP.&lt;/P&gt;&lt;P&gt;These users are managed by editing the file. You generate a password hash for an /etc/password user with the 'cifs passwd' command, then paste it into the file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are some examples to illustrate:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sim1&amp;gt; rdfile /etc/passwd&lt;BR /&gt;root:_J9...crlrN3mwj5GjQs:0:1::/:&lt;BR /&gt;ekashp:_J9..xJx4OWqsuoJFXps:1001:1001::/:&lt;BR /&gt;pcuser::65534:65534::/:&lt;BR /&gt;nobody::65535:65535::/:&lt;BR /&gt;ftp::65533:65533:FTP Anonymous:/home/ftp:&lt;BR /&gt;sim1&amp;gt; useradmin user list&lt;BR /&gt;Name: root&lt;BR /&gt;Info: Default system administrator.&lt;BR /&gt;Rid: 0&lt;BR /&gt;Groups:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name: administrator&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Info: Built-in account for administering the filer&lt;BR /&gt;Rid: 500&lt;BR /&gt;Groups: Administrators&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sim1&amp;gt; cifs passwd mynewpasswd&lt;BR /&gt;password is _J9..VLG2fYad1gOEuKc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;root exists in both sets of users.&lt;/P&gt;&lt;P&gt;administrator only exists in RBAC&lt;/P&gt;&lt;P&gt;ekashp only exists in /etc/passwd&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this response has been helpful to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At your service,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Eugene E. Kashpureff&lt;BR /&gt;&lt;A class="jive-link-email-small" href="mailto:ekashp@kashpureff.org" target="_blank"&gt;ekashp@kashpureff.org&lt;/A&gt;&lt;BR /&gt;NetApp Instructor and Independent Consultant&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.linkedin.com/in/eugenekashpureff" target="_blank"&gt;http://www.linkedin.com/in/eugenekashpureff&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(P.S. I appreciate points for helpful or correct answers.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Dec 2010 15:53:02 GMT</pubDate>
    <dc:creator>ekashpureff</dc:creator>
    <dc:date>2010-12-23T15:53:02Z</dc:date>
    <item>
      <title>Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31128#M2780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I need to access our NetApp via CIFS from 2 different domains while we migrate all useres/computers from one domain to the other. We have thought of changing the netapp to work with internal local users or users in /etc/passwd so users can access to it previous local authentication. However I am getting access denied without even challenge to credentials. Do you know if that is possible? It works ok if we use domain authentication but obviously only for done domain, not 2 at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any way to do that? Since it is temporary we don't mind having to challenge the user for user and password and check it against local filer users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 07:03:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31128#M2780</guid>
      <dc:creator>cr_emilio</dc:creator>
      <dc:date>2025-06-05T07:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31132#M2781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With Multistore you could create a vfiler and join it into the second domain.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I hope this response has been helpful to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At your service,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Eugene E. Kashpureff&lt;BR /&gt;&lt;A class="jive-link-email-small" href="mailto:ekashp@kashpureff.org" target="_blank"&gt;ekashp@kashpureff.org&lt;/A&gt;&lt;BR /&gt;NetApp Instructor and Independent Consultant&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.linkedin.com/in/eugenekashpureff" target="_blank"&gt;http://www.linkedin.com/in/eugenekashpureff&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(P.S. I appreciate points for helpful or correct answers.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 18:58:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31132#M2781</guid>
      <dc:creator>ekashpureff</dc:creator>
      <dc:date>2010-12-22T18:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31138#M2782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well we want just a temporary solution access. It is not like it worths to purchase new products for just this step. Is it technically imposible with a normal NetApp filer?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 19:13:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31138#M2782</guid>
      <dc:creator>cr_emilio</dc:creator>
      <dc:date>2010-12-22T19:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31143#M2784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is possible to connect to netapp filer from another domain using trusted domains, without doing another login (not that you see anyway, everything is automatic)&lt;/P&gt;&lt;P&gt;It works by setting "altSecurityIdenties" attribute&amp;nbsp; for each user in the "netapp" (receiving) AD domain.&lt;/P&gt;&lt;P&gt;That way you get a one-to-one user mapping (or many-to-one whatever you need is) for accessing the Filer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We successfully experimented with this, but at the end it failed on the fact it didn't work as we expected/wanted in NFS envirovment.&lt;/P&gt;&lt;P&gt;If you use ony CIFS then this might be the answer you are looking for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you set the "altSecurityIdentities", user &lt;A _jive_internal="true" href="https://community.netapp.com/mailto:user1@olddomain" target="_blank"&gt;user1@olddomain&lt;/A&gt; becomes &lt;A _jive_internal="true" href="https://community.netapp.com/mailto:user2@newdomain" target="_blank"&gt;user2@newdomain&lt;/A&gt; on the Netapp, with all the correct ownership and security implications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works by a way of Microsoft utilities the Kerberos protocol in a ingenious way with a extension called PAC.&lt;/P&gt;&lt;P&gt;Simply put it the Kerberos secret is usualy some random data passed between the client and server.&lt;/P&gt;&lt;P&gt;Windows (and obviously Netapp) instead throws in data about the account, like SSID/username and/or other stuff.&lt;/P&gt;&lt;P&gt;As the client doesn't interpret this data, its just recrypting and passing it on again, it even works (although limited) with non-Windows clients.&lt;/P&gt;&lt;P&gt;But as it need to pass on more bytes than a "standard" Kerberos ticket some implementations might fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; / Dejan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Added:&lt;/P&gt;&lt;P&gt; Found a article that describs the process. Read the last part about "Cross-realm trust"&lt;/P&gt;&lt;P&gt; &lt;A href="http://searchwindowsserver.techtarget.com/feature/Kerberos-interoperability" target="_blank"&gt;http://searchwindowsserver.techtarget.com/feature/Kerberos-interoperability&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; The altSecurityIdentities value has to be prepended with the keyword "Kerberos:"&lt;/P&gt;&lt;P&gt; ie a LDAP attribute definition in the receiving AD could look like this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;dn: cn=John Smith,cn=users,o=newdomain,c=us
objectclass: inetorgperson
cn: John Smith
sn: Smith
altsecurityidentities: Kerberos:jsmith@olddomain.com&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: dejan-liuit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 20:16:37 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31143#M2784</guid>
      <dc:creator>dejanliuit</dc:creator>
      <dc:date>2010-12-22T20:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31149#M2787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answer, it helps but there is still some peculiarities in our environment. Do you know if there is just a simpler way to connect? I just want to have access from any windows machine using the local user and password users in /etc/passwd I dont mind being challenged.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 10:53:50 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31149#M2787</guid>
      <dc:creator>cr_emilio</dc:creator>
      <dc:date>2010-12-23T10:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31153#M2789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's easily achieved if that's all you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simply create a local user on the filer (use the MMC to connect to the NetApp if this is easier for you), and then when you try to connect to a CIFS share or map a drive, use this local user to authenticate. The filer (even when in a domain) fully supports local users, exactly the same as a windows machine would do. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was actually working with a customer on this last week. The following KB article may be of assistance to you: &lt;A href="https://kb.netapp.com/support/index?page=content&amp;amp;id=2010383" target="_blank"&gt;https://kb.netapp.com/support/index?page=content&amp;amp;id=2010383&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 10:58:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31153#M2789</guid>
      <dc:creator>chriskranz</dc:creator>
      <dc:date>2010-12-23T10:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31159#M2793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just get this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The account is not authorized to log in from this station.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I try with an non existing user then i get (which makes perfect sense):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Login failure: unkown user name or bad password.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea? it works great if joined into the domain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 11:49:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31159#M2793</guid>
      <dc:creator>cr_emilio</dc:creator>
      <dc:date>2010-12-23T11:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31164#M2796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're using a local user from the NetApp? The share is exported with everyone full control? Is the time synchronised properly between the 2? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 11:53:20 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31164#M2796</guid>
      <dc:creator>chriskranz</dc:creator>
      <dc:date>2010-12-23T11:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31170#M2799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, they are users in /etc/passwd&lt;/P&gt;&lt;P&gt;The CIFS share is everyone FullAccess&lt;/P&gt;&lt;P&gt;The clocks are quite synced like 3-4 seconds of diference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying both /etc/passwd and windows workgroup configs. None of them seems to work. Not sure what I can be doing wrong. User to be authenticated because if I try wrong password or user I get the other error...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 12:08:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31170#M2799</guid>
      <dc:creator>cr_emilio</dc:creator>
      <dc:date>2010-12-23T12:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31173#M2801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same timezone?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It could be an issue with SMB signing: &lt;A href="http://support.microsoft.com/?id=281648" target="_blank"&gt;http://support.microsoft.com/?id=281648&lt;/A&gt; Also check the CIFS options on the filer (from the CLI run "options cifs" and check the smb signing options).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From this same host, can you connect to a share on the filer using a different user? Say a domain user or local admin on the filer? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 12:15:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31173#M2801</guid>
      <dc:creator>chriskranz</dc:creator>
      <dc:date>2010-12-23T12:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31178#M2803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems like no signature&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cifs.LMCompatibilityLevel&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;BR /&gt;cifs.audit.account_mgmt_&lt;/P&gt;&lt;DIV id=":1nj"&gt;events.enable on&lt;BR /&gt;cifs.audit.autosave.file.extension timestamp&lt;BR /&gt;cifs.audit.autosave.file.limit 0&lt;BR /&gt;cifs.audit.autosave.onsize.enable off&lt;BR /&gt;cifs.audit.autosave.onsize.threshold 90%&lt;BR /&gt; cifs.audit.autosave.ontime.enable on&lt;BR /&gt;cifs.audit.autosave.ontime.interval 1d&lt;BR /&gt;cifs.audit.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;cifs.audit.file_access_events.enable on&lt;BR /&gt;cifs.audit.liveview.allowed_users&lt;BR /&gt;cifs.audit.liveview.enable&amp;nbsp;&amp;nbsp; off&lt;BR /&gt; cifs.audit.logon_events.enable on&lt;BR /&gt;cifs.audit.logsize&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 524288&lt;BR /&gt;cifs.audit.nfs.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;cifs.audit.nfs.filter.filename&lt;BR /&gt;cifs.audit.saveas&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /etc/log/adtlog.evt&lt;BR /&gt;cifs.bypass_traverse_checking off&lt;BR /&gt; cifs.client.dup-detection&amp;nbsp;&amp;nbsp;&amp;nbsp; ip-address&lt;BR /&gt;cifs.comment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P839 NetApp Simulator&lt;BR /&gt;cifs.enable_share_browsing&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;cifs.gpo.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;cifs.gpo.trace.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;cifs.grant_implicit_exe_perms off&lt;BR /&gt; cifs.guest_account&lt;BR /&gt;cifs.home_dir_namestyle&lt;BR /&gt;cifs.home_dirs_public_for_admin off&lt;BR /&gt;cifs.idle_timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1800&lt;BR /&gt;cifs.ipv6.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;cifs.max_mpx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50&lt;BR /&gt;cifs.ms_snapshot_mode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt; cifs.netbios_aliases&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P839NETAPP&lt;BR /&gt;cifs.netbios_over_tcp.enable on&lt;BR /&gt;cifs.nfs_root_ignore_acl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;cifs.oplocks.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;cifs.oplocks.opendelta&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&lt;BR /&gt;cifs.per_client_stats.enable on&lt;BR /&gt;cifs.perfmon.allowed_users&lt;BR /&gt; cifs.perm_check_ro_del_ok&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;cifs.perm_check_use_gid&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;cifs.preserve_unix_security&amp;nbsp; on&lt;BR /&gt;cifs.restrict_anonymous&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;BR /&gt;cifs.restrict_anonymous.enable on&lt;BR /&gt;cifs.save_case&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;cifs.scopeid&lt;BR /&gt; cifs.search_domains&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MYDOMAINNAME&lt;BR /&gt;cifs.show_dotfiles&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;cifs.show_snapshot&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;cifs.shutdown_msg_level&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;BR /&gt;cifs.sidcache.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;cifs.sidcache.lifetime&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1200&lt;BR /&gt;cifs.signing.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt; cifs.smb2.client.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;cifs.smb2.durable_handle.enable on&lt;BR /&gt;cifs.smb2.durable_handle.timeout 16m&lt;BR /&gt;cifs.smb2.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;cifs.smb2.signing.required&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;cifs.snapshot_file_folding.enable off&lt;BR /&gt; cifs.symlinks.cycleguard&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;cifs.symlinks.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;cifs.trace_dc_connection&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;cifs.trace_login&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;cifs.universal_nested_groups.enable off&lt;BR /&gt;cifs.weekly_W2K_password_change off&lt;BR /&gt; cifs.widelink.ttl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12h&lt;BR /&gt;cifs.wins_servers&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Yeah they are in the same timezone. I cannot connect to any share in the filer I can only can if I join the netapp back to the domain &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.netapp.com/4.0.8/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 12:26:20 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31178#M2803</guid>
      <dc:creator>cr_emilio</dc:creator>
      <dc:date>2010-12-23T12:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31183#M2804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And when you authenticate to the share, you use "filername\username" and not just "username"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not entirely sure in that case. I've run filers in workgroup mode on many occasions without issue. Silly questions, but CIFS is definitely running? You ran through CIFS setup and configured it in workgroup mode?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 12:33:48 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31183#M2804</guid>
      <dc:creator>chriskranz</dc:creator>
      <dc:date>2010-12-23T12:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31189#M2805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your time Chris.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes actually I have tried all the different combinations I think...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With workgroup stuff:&lt;/P&gt;&lt;P&gt;net use x: \\hostname\share /user:username ---&amp;gt; I get account is not authorized&lt;/P&gt;&lt;P&gt;net use x: \\hostname\share /user:hostname\username ---&amp;gt; I get bad user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With /etc/passwd:&lt;/P&gt;&lt;P&gt;net use x: \\hostname\share /user:username ---&amp;gt; I get account is not authorized&lt;/P&gt;&lt;P&gt;net use x: \\hostname\share /user:hostname\username ---&amp;gt; I get account is not authorized&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually it doesnt matter if I use an account which exists or not I always get the same error with /etc/passwd...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 13:48:55 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31189#M2805</guid>
      <dc:creator>cr_emilio</dc:creator>
      <dc:date>2010-12-23T13:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31195#M2806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Based on the fact that "hostname\username ---&amp;gt; I get bad user", can you confirm how you are adding the user locally onto the NetApp please? You definitely want to get this working in workgroup mode and not using /etc/passwd.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 13:57:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31195#M2806</guid>
      <dc:creator>chriskranz</dc:creator>
      <dc:date>2010-12-23T13:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31201#M2807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually I am adding the users in /etc/passwd. My idea is, for legacy reasons, to use Unix permissions and try to auth against /etc/passwd. This worked in our previous environment but authenticating against AD. Just want to make it work outside of the domain for several weeks...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 14:02:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31201#M2807</guid>
      <dc:creator>cr_emilio</dc:creator>
      <dc:date>2010-12-23T14:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31207#M2808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree - I think that it is the problem here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should be a 'useradmin' RBAC user for this authentication.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I hope this response has been helpful to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At your service,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Eugene E. Kashpureff&lt;BR /&gt;&lt;A class="jive-link-email-small" href="mailto:ekashp@kashpureff.org" target="_blank"&gt;ekashp@kashpureff.org&lt;/A&gt;&lt;BR /&gt;NetApp Instructor and Independent Consultant&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.linkedin.com/in/eugenekashpureff" target="_blank"&gt;http://www.linkedin.com/in/eugenekashpureff&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(P.S. I appreciate points for helpful or correct answers.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 14:03:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31207#M2808</guid>
      <dc:creator>ekashpureff</dc:creator>
      <dc:date>2010-12-23T14:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31212#M2809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're using "useradmin user add" to add new users then? Not editing /etc/passwd directly? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 14:11:52 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31212#M2809</guid>
      <dc:creator>chriskranz</dc:creator>
      <dc:date>2010-12-23T14:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31216#M2810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can try running through CIFS setup again and select 'etc/passwd and/or NIS/LDAP authentication' to do a non-windows workgroup authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I hope this response has been helpful to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At your service,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Eugene E. Kashpureff&lt;BR /&gt;&lt;A class="jive-link-email-small" href="mailto:ekashp@kashpureff.org" target="_blank"&gt;ekashp@kashpureff.org&lt;/A&gt;&lt;BR /&gt;NetApp Instructor and Independent Consultant&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.linkedin.com/in/eugenekashpureff" target="_blank"&gt;http://www.linkedin.com/in/eugenekashpureff&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(P.S. I appreciate points for helpful or correct answers.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 14:15:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31216#M2810</guid>
      <dc:creator>ekashpureff</dc:creator>
      <dc:date>2010-12-23T14:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31222#M2811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried with root user which seems to be a admin user definetly and i am getting the same results. This is really painfull as I expected it to work straight away, not sure what I am doing absolutely wrong...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 14:19:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31222#M2811</guid>
      <dc:creator>cr_emilio</dc:creator>
      <dc:date>2010-12-23T14:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Access NetApp from several Domain (via CIFS)</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31228#M2812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using users in /etc/passwd not adding users from CLI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 14:26:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-NetApp-from-several-Domain-via-CIFS/m-p/31228#M2812</guid>
      <dc:creator>cr_emilio</dc:creator>
      <dc:date>2010-12-23T14:26:05Z</dc:date>
    </item>
  </channel>
</rss>

