<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secondary Membership Groups with Active Directory and likewise in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Secondary-Membership-Groups-with-Active-Directory-and-likewise/m-p/56932#M5265</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for picking up this old thread but I stumbled across a similar issue today when trying to configure nfsv4. I can't see the secondary group memberships.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 2008 R2 with RFC schema enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our OnTAP version is 8.0.1 P4. Accoding to the bug report it should be fixed in this release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Jul 2012 11:15:45 GMT</pubDate>
    <dc:creator>oweinmann</dc:creator>
    <dc:date>2012-07-17T11:15:45Z</dc:date>
    <item>
      <title>Secondary Membership Groups with Active Directory and likewise</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Secondary-Membership-Groups-with-Active-Directory-and-likewise/m-p/56919#M5261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are trying to setup authentication through Active Directory. We are using Likewise to add uid, gid and other unix attributes to objects in AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our setup is FAS3240 with DataONTAP 8.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our Active Directory server is running Windows server 2003 R2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our use case is volumes which are shared both through cifs and nfs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have based most of our configuration on the following documents:&lt;/P&gt;&lt;P&gt;- netapp tr 3458&lt;/P&gt;&lt;P&gt;- "Authenticating network appliances file servers with likewise and ad", from likewise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far, we were able to:&lt;/P&gt;&lt;P&gt;- Join the filer to the domain.&lt;/P&gt;&lt;P&gt;- Configure ldap so that the following commands return information&lt;/P&gt;&lt;P&gt;&amp;nbsp; - wcc -s domain\user&lt;/P&gt;&lt;P&gt;&amp;nbsp; - getXXbyYY getpwbyname_r user&lt;/P&gt;&lt;P&gt;- Access a share through cifs and browse and create files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is that &lt;/P&gt;&lt;P&gt;getXXbyYY getgrlist user&lt;/P&gt;&lt;P&gt;only returns one group, even though the user does have secondary groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we run &lt;/P&gt;&lt;P&gt;wcc -s domain\user&lt;/P&gt;&lt;P&gt;we see one group listed under unix uid and multiple groups listed under nt membership.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how do we retrieve all group membership from Active Directory?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a reference, here is our ldap configuration&lt;/P&gt;&lt;P id="ColorBandedcontent"&gt;&lt;/P&gt;&lt;DIV style="font-family: MS Shell Dlg 2; direction: ltr; color: #000000; font-size: 9pt;"&gt;&amp;gt; options ldap&lt;BR /&gt;ldap.ADdomain&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; blabla.net&lt;BR /&gt;ldap.base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DC=blabla,DC=net&lt;BR /&gt;ldap.base.group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dc=blabla,dc=net&lt;BR /&gt;ldap.base.netgroup&lt;BR /&gt;ldap.base.passwd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DC=blabla,DC=net&lt;BR /&gt;ldap.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;ldap.minimum_bind_level&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; simple&lt;BR /&gt;ldap.name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CN=Last\, First,OU=Users,OU=Some Place,DC=blabla,DC=net&lt;BR /&gt;ldap.nssmap.attribute.gecos&amp;nbsp; gecos&lt;BR /&gt;ldap.nssmap.attribute.gidNumber gidNumber&lt;BR /&gt;ldap.nssmap.attribute.groupname cn&lt;BR /&gt;ldap.nssmap.attribute.homeDirectory unixHomeDirectory&lt;BR /&gt;ldap.nssmap.attribute.loginShell loginShell&lt;BR /&gt;ldap.nssmap.attribute.memberNisNetgroup memberNisNetgroup&lt;BR /&gt;ldap.nssmap.attribute.memberUid memberUid&lt;BR /&gt;ldap.nssmap.attribute.netgroupname cn&lt;BR /&gt;ldap.nssmap.attribute.nisNetgroupTriple nisNetgroupTriple&lt;BR /&gt;ldap.nssmap.attribute.uid&amp;nbsp;&amp;nbsp;&amp;nbsp; sAMAccountName&lt;BR /&gt;ldap.nssmap.attribute.uidNumber uidNumber&lt;BR /&gt;ldap.nssmap.attribute.uniqueMember member&lt;BR /&gt;ldap.nssmap.attribute.userPassword userPassword&lt;BR /&gt;ldap.nssmap.objectClass.groupOfUniqueNames group&lt;BR /&gt;ldap.nssmap.objectClass.nisNetgroup nisNetgroup&lt;BR /&gt;ldap.nssmap.objectClass.posixAccount user&lt;BR /&gt;ldap.nssmap.objectClass.posixGroup group&lt;BR /&gt;ldap.passwd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ******&lt;BR /&gt;ldap.port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 389&lt;BR /&gt;ldap.rfc2307bis.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;ldap.servers&lt;BR /&gt;ldap.servers.preferred&lt;BR /&gt;ldap.ssl.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;ldap.timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20&lt;BR /&gt;ldap.usermap.attribute.unixaccount sAMAccountName&lt;BR /&gt;ldap.usermap.attribute.windowsaccount sAMAccountName&lt;BR /&gt;ldap.usermap.base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dc=blabla,dc=net&lt;BR /&gt;ldap.usermap.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;ldap.usermap.symmetriclookup no&lt;BR /&gt;ldap.usermap.windows-to-unix.objectClass User&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:49:16 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Secondary-Membership-Groups-with-Active-Directory-and-likewise/m-p/56919#M5261</guid>
      <dc:creator>CURUFINWE</dc:creator>
      <dc:date>2025-06-05T06:49:16Z</dc:date>
    </item>
    <item>
      <title>Secondary Membership Groups with Active Directory and likewise</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Secondary-Membership-Groups-with-Active-Directory-and-likewise/m-p/56924#M5263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have had a lot of back and forth with NetApp support on this. In the end, we found the following:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- This is caused by bug 314631 (see &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://now.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=314631" target="_blank"&gt;https://now.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=314631&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- The resolution is to set the following hidden option: &lt;/P&gt;&lt;P&gt;ldap.skip_cn_unescape.enable on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once we set this option, things work much better.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2011 19:59:33 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Secondary-Membership-Groups-with-Active-Directory-and-likewise/m-p/56924#M5263</guid>
      <dc:creator>CURUFINWE</dc:creator>
      <dc:date>2011-09-01T19:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary Membership Groups with Active Directory and likewise</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Secondary-Membership-Groups-with-Active-Directory-and-likewise/m-p/56932#M5265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for picking up this old thread but I stumbled across a similar issue today when trying to configure nfsv4. I can't see the secondary group memberships.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 2008 R2 with RFC schema enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our OnTAP version is 8.0.1 P4. Accoding to the bug report it should be fixed in this release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 11:15:45 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Secondary-Membership-Groups-with-Active-Directory-and-likewise/m-p/56932#M5265</guid>
      <dc:creator>oweinmann</dc:creator>
      <dc:date>2012-07-17T11:15:45Z</dc:date>
    </item>
  </channel>
</rss>

