<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH key authentication using domain users? Then how about SFTP? in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/SSH-key-authentication-using-domain-users-Then-how-about-SFTP/m-p/46041#M4204</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually you can do this.&amp;nbsp; I've set it up and use it daily.&amp;nbsp; Send me a message and I'll explain if you are interested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Nov 2012 19:46:14 GMT</pubDate>
    <dc:creator>JERROD_FINN</dc:creator>
    <dc:date>2012-11-07T19:46:14Z</dc:date>
    <item>
      <title>SSH key authentication using domain users? Then how about SFTP?</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/SSH-key-authentication-using-domain-users-Then-how-about-SFTP/m-p/46026#M4201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We cannot seem to get this to work with domain users. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using this KB as a guide to setup passwordless ssh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://kb.netapp.com/support/index?page=content&amp;amp;id=1011670" target="_blank"&gt;https://kb.netapp.com/support/index?page=content&amp;amp;id=1011670&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is working for root and local users. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; For domain users we have tested both naming conventions for folder names in /etc/sshd&lt;/P&gt;&lt;P&gt;/etc/sshd/username@domainname/.ssh/authenticated_keys&lt;/P&gt;&lt;P&gt;/etc/sshd/domainname\username/.ssh/authenticated_keys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It finds the keys, but ONTAP spits back:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User 'lab.demo\administrator' denied access - missing required capability: 'login-ssh'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two separate environments with the same results.&amp;nbsp; Again, we can get local users to work so the keys are good, and with domain users it is finding the keys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried useradmin group modify administrators -r admin,root to give maximum permissions, but still no luck.&amp;nbsp; Just the default role of admin should be sufficient..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So getting SSH to work is one thing, but we are really trying to get passwordless SFTP working.&amp;nbsp; Here is the error when we try with a domain user.&amp;nbsp; The Authentication type for SFTP is mixed, we have also tried with NTLM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SFTP (SSH File Transfer Protocol) connection request from client system xxx.xxx.xxx.xxx, user lab.demo\administrator failed, because the user is not permitted to do SFTP (SSH File Transfer Protocol) operations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone successfully implemented passwordless SFTP using domain credentials? Is this even supported?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:52:31 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/SSH-key-authentication-using-domain-users-Then-how-about-SFTP/m-p/46026#M4201</guid>
      <dc:creator>audifreakjim</dc:creator>
      <dc:date>2025-06-05T06:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSH key authentication using domain users? Then how about SFTP?</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/SSH-key-authentication-using-domain-users-Then-how-about-SFTP/m-p/46029#M4202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This post is a bit old, but this KB(for SSH breaking when roles change) has the info you need.&amp;nbsp; Any ssh based authentication, with AD accounts is not supported in ONTAP, and believe me I really wish it were.&amp;nbsp; We have ran into a bug recently(2 months ago) and this KB was brought up to us as still being correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="CAUSES"&gt;&lt;/P&gt;&lt;H3&gt;Cause&lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="attr CAUSE"&gt;&lt;DIV class="content"&gt;Data ONTAP does not support key exchange with Active Directory Accounts.&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;Solution&lt;/H3&gt;&lt;P&gt; Use local filer accounts for SSH key exchange to avoid this issue. NetApp does not currently support key exchange with Active Directory accounts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://kb.netapp.com/support/index?page=content&amp;amp;id=2012318" target="_blank"&gt;https://kb.netapp.com/support/index?page=content&amp;amp;id=2012318&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jul 2011 14:08:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/SSH-key-authentication-using-domain-users-Then-how-about-SFTP/m-p/46029#M4202</guid>
      <dc:creator>columbus_admin</dc:creator>
      <dc:date>2011-07-08T14:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSH key authentication using domain users? Then how about SFTP?</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/SSH-key-authentication-using-domain-users-Then-how-about-SFTP/m-p/46036#M4203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for clearing this up!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jul 2011 15:30:33 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/SSH-key-authentication-using-domain-users-Then-how-about-SFTP/m-p/46036#M4203</guid>
      <dc:creator>audifreakjim</dc:creator>
      <dc:date>2011-07-11T15:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSH key authentication using domain users? Then how about SFTP?</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/SSH-key-authentication-using-domain-users-Then-how-about-SFTP/m-p/46041#M4204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually you can do this.&amp;nbsp; I've set it up and use it daily.&amp;nbsp; Send me a message and I'll explain if you are interested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 19:46:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/SSH-key-authentication-using-domain-users-Then-how-about-SFTP/m-p/46041#M4204</guid>
      <dc:creator>JERROD_FINN</dc:creator>
      <dc:date>2012-11-07T19:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSH key authentication using domain users? Then how about SFTP?</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/SSH-key-authentication-using-domain-users-Then-how-about-SFTP/m-p/101275#M7593</link>
      <description>&lt;P&gt;What was the fix?&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/11584"&gt;@JERROD_FINN&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Actually you can do this.&amp;nbsp; I've set it up and use it daily.&amp;nbsp; Send me a message and I'll explain if you are interested.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2015 16:41:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/SSH-key-authentication-using-domain-users-Then-how-about-SFTP/m-p/101275#M7593</guid>
      <dc:creator>PC70</dc:creator>
      <dc:date>2015-03-02T16:41:23Z</dc:date>
    </item>
  </channel>
</rss>

