<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CIFS role based access control in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/CIFS-role-based-access-control/m-p/36526#M3333</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I feel your pain, Sal... RBAC is a real PITA...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you consider "CIFS administration"?&amp;nbsp; What do you want the user to NOT be able to do?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 Oct 2011 23:43:11 GMT</pubDate>
    <dc:creator>shaunjurr</dc:creator>
    <dc:date>2011-10-31T23:43:11Z</dc:date>
    <item>
      <title>CIFS role based access control</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/CIFS-role-based-access-control/m-p/36520#M3332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a vfiler for one of our customers to use as a CIFS server. The customer should be able to administer CIFS by himself over the MMC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a group CIFSAdmins and attached the a new role with the following capabilities: &lt;SPAN style="font-family: courier new,courier;"&gt;api-cifs-list-*,api-cifs-session-*,api-cifs-share-*,api-quota-*,api-cifs-homedir-*&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The strange issue is that with this capabilities an ACCESS DENIED message is displayed on shares. For testing purposes I added the customer to the power user group, everything works fine but the customer is still able to change the members of the local groups. The default capabilities for the power user group is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Name:&amp;nbsp;&amp;nbsp;&amp;nbsp; power&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Info:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Allowed Capabilities: cli-cifs*,cli-exportfs*,cli-nfs*,cli-useradmin*,api-cifs-*,api-nfs-*,login-telnet,login-http-admin,login-rsh,login-ssh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I changed the power role to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Name:&amp;nbsp;&amp;nbsp;&amp;nbsp; power&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Info:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Allowed Capabilities: cli-cifs*,api-cifs-*,login-telnet,login-http-admin,login-rsh,login-ssh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but no change happened, still able to create new groups and change the members of the group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which capabilities should be allowed on a rule to have the rights to only do CIFS administration tasks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:42:20 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/CIFS-role-based-access-control/m-p/36520#M3332</guid>
      <dc:creator>SALVATORE_PUGLISI</dc:creator>
      <dc:date>2025-06-05T06:42:20Z</dc:date>
    </item>
    <item>
      <title>CIFS role based access control</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/CIFS-role-based-access-control/m-p/36526#M3333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I feel your pain, Sal... RBAC is a real PITA...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you consider "CIFS administration"?&amp;nbsp; What do you want the user to NOT be able to do?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Oct 2011 23:43:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/CIFS-role-based-access-control/m-p/36526#M3333</guid>
      <dc:creator>shaunjurr</dc:creator>
      <dc:date>2011-10-31T23:43:11Z</dc:date>
    </item>
  </channel>
</rss>

