<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OnTap + LDAP (Active Directory) help needed in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44326#M4028</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you explain something to me ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dc=mydomain,dc=local ?sub?&amp;amp;(objectCategory=Group) (gidnumber=*)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why do you put : ?sub?&amp;amp;(objectCategory=Group) (gidnumber=*)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;behind your scope ? I am having currently some ldap performance issues, and this could help me.&lt;/P&gt;&lt;P&gt;Where did you find this information ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings .. Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Aug 2010 12:17:32 GMT</pubDate>
    <dc:creator>rsmits1074</dc:creator>
    <dc:date>2010-08-30T12:17:32Z</dc:date>
    <item>
      <title>OnTap + LDAP (Active Directory) help needed</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44311#M4025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to authenticate a FAS6040 with OnTap 8.0 against the LDAP interface of Active Directory (i.e. without CIFS).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far I can connect to the LDAP server and query records (getXXbyYY) but the records I get back are missing all supplemental groups (memberOf in Active Directory).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do I have to map to get access to the supplemental groups so I can add the right users to the correct roles?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my LDAP configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV id="_mcePaste"&gt;ldap.ADdomain&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dc=mydomain,dc=local&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.base.group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dc=mydomain,dc=local&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.base.netgroup&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.base.passwd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dc=mydomain,dc=local ?sub?&amp;amp;(objectCategory=Group) (gidnumber=*)&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.minimum_bind_level&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; anonymous&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; myLDAPuser&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.gecos&amp;nbsp; cn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.gidNumber gidNumber&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.groupname memberOf&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.homeDirectory unixHomeDirectory&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.loginShell loginShell&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.memberNisNetgroup memberNisNetgroup&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.memberUid memberUid&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.netgroupname cn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.nisNetgroupTriple nisNetgroupTriple&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.uid&amp;nbsp;&amp;nbsp;&amp;nbsp; sAMAccountName&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.uidNumber uidNumber&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.attribute.userPassword userPassword&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.objectClass.nisNetgroup nisNetgroup&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.objectClass.posixAccount User&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.nssmap.objectClass.posixGroup Group&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.passwd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; myPassword&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 389&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.servers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; my.ldap.server&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.servers.preferred&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.ssl.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.usermap.attribute.unixaccount unixaccount&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.usermap.attribute.windowsaccount windowsaccount&lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.usermap.base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV id="_mcePaste"&gt;ldap.usermap.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 07:11:00 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44311#M4025</guid>
      <dc:creator>christianhuebner</dc:creator>
      <dc:date>2025-06-05T07:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: OnTap + LDAP (Active Directory) help needed</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44316#M4026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure this is right ? : ldap.base.passwd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dc=mydomain,dc=local ?sub?&amp;amp;(objectCategory=Group) (gidnumber=*)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am no expert on this, but objectCategory=Group ? This is not the : group ldap setting, but the passwd entry. Or is this some trick I do not know about ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings .. Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 15:17:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44316#M4026</guid>
      <dc:creator>rsmits1074</dc:creator>
      <dc:date>2010-08-04T15:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: OnTap + LDAP (Active Directory) help needed</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44321#M4027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct, that was supposed to go into group, not passwd and I corrected it after posting this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alas, it does not make a difference, even when set in ldap.base.group. It works for our Linux hosts, that's why I tried it on the NetApp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 15:35:45 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44321#M4027</guid>
      <dc:creator>christianhuebner</dc:creator>
      <dc:date>2010-08-04T15:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: OnTap + LDAP (Active Directory) help needed</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44326#M4028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you explain something to me ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dc=mydomain,dc=local ?sub?&amp;amp;(objectCategory=Group) (gidnumber=*)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why do you put : ?sub?&amp;amp;(objectCategory=Group) (gidnumber=*)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;behind your scope ? I am having currently some ldap performance issues, and this could help me.&lt;/P&gt;&lt;P&gt;Where did you find this information ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings .. Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Aug 2010 12:17:32 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44326#M4028</guid>
      <dc:creator>rsmits1074</dc:creator>
      <dc:date>2010-08-30T12:17:32Z</dc:date>
    </item>
    <item>
      <title>OnTap + LDAP (Active Directory) help needed</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44330#M4029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't know if this has been resolved, but just in case you may want to check this post&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://communities.netapp.com/thread/16160" target="_blank"&gt;http://communities.netapp.com/thread/16160&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The resolution boils down to&lt;/P&gt;&lt;P&gt;- bug 314631 (see &lt;A class="jive-link-external-small" href="https://now.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=314631" target="_blank"&gt;https://now.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=314631&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;- set the following hidden option: &lt;/P&gt;&lt;P&gt;ldap.skip_cn_unescape.enable on&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2011 20:02:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44330#M4029</guid>
      <dc:creator>CURUFINWE</dc:creator>
      <dc:date>2011-09-01T20:02:34Z</dc:date>
    </item>
    <item>
      <title>OnTap + LDAP (Active Directory) help needed</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44335#M4030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Had a similar problem, and it came down to sAMAccountName having title caps for some (but not all) users in AD.&amp;nbsp; It appears that OnTap searches for secondary groups by using whatever it receives back from "ldap.nssmap.attribute.uid" and looks in the attribute "ldap.nssmap.attribute.memberUid" within group objects. In my AD, this attribute only included all lower case names (so searches with title caps were failing).&amp;nbsp; I changed "ldap.nssmap.attribute.uid" to msSFU30Name which solved my problem.&amp;nbsp; However, you may or may not have this attribute depending on how you expanded your schema.&amp;nbsp; Either way, find an attribute in your user objects that always matches the case of the attribute memberUid in your group objects.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 18:26:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/OnTap-LDAP-Active-Directory-help-needed/m-p/44335#M4030</guid>
      <dc:creator>loudymanschwab</dc:creator>
      <dc:date>2011-11-11T18:26:18Z</dc:date>
    </item>
  </channel>
</rss>

