<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: permission denied on mount operation for NFS volume with netgroup in LDAP in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/permission-denied-on-mount-operation-for-NFS-volume-with-netgroup-in-LDAP/m-p/57250#M5307</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My problem was that names that i specified in netgroup OU lacked PTR records in DNS.&lt;/P&gt;&lt;P&gt;On connection filer has only IP address that it need to map back to DNS name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i fixed reverse lookup everything start working fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Nov 2012 17:41:15 GMT</pubDate>
    <dc:creator>zinovik_igor</dc:creator>
    <dc:date>2012-11-28T17:41:15Z</dc:date>
    <item>
      <title>permission denied on mount operation for NFS volume with netgroup in LDAP</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/permission-denied-on-mount-operation-for-NFS-volume-with-netgroup-in-LDAP/m-p/57246#M5306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp; Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to figure out why my filer do not allow me to mount volume for my netgroups that are stored in LDAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client is opensuse 12.1&lt;/P&gt;&lt;P&gt;ldap2:~ # uname -r&lt;/P&gt;&lt;P&gt;3.1.10-1.9-desktop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NFS4 support is disabled:&lt;/P&gt;&lt;P&gt;ldap2:~ # grep NFS4_SUPPORT /etc/sysconfig/nfs&lt;/P&gt;&lt;P&gt;NFS4_SUPPORT="no" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NFS client services are running: &lt;/P&gt;&lt;P&gt;ldap2:~ # systemctl status nfs.service&lt;/P&gt;&lt;P&gt;nfs.service - LSB: NFS client services&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Loaded: loaded (/etc/init.d/nfs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active: active (exited) since Wed, 12 Sep 2012 10:24:12 +0400; 51min ago&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Process: 16025 ExecStop=/etc/init.d/nfs stop (code=exited, status=0/SUCCESS)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Process: 16047 ExecStart=/etc/init.d/nfs start (code=exited, status=0/SUCCESS)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CGroup: name=systemd:/system/nfs.service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall is turned off.&amp;nbsp; There is no NAT gateway between client and netapp filer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I store my netgroups in LDAP:&lt;/P&gt;&lt;P&gt;dn: cn=home-hosts,ou=Netgroup,dc=local,dc=prv&lt;/P&gt;&lt;P&gt;objectClass: top&lt;/P&gt;&lt;P&gt;objectClass: nisNetgroup&lt;/P&gt;&lt;P&gt;cn: home-hosts&lt;/P&gt;&lt;P&gt;nisNetgroupTriple: (ldap1.local.prv,,)&lt;/P&gt;&lt;P&gt;nisNetgroupTriple: (ldap2.local.prv,,)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; On filer side:&lt;/P&gt;&lt;P&gt;fas2&amp;gt; vol create test sataaggr 1g &lt;/P&gt;&lt;P&gt;fas2&amp;gt; exportfs -io rw=@home-hosts,anon=0 /vol/test &lt;/P&gt;&lt;P&gt;fas2&amp;gt; qtree status test&lt;/P&gt;&lt;P&gt;Volume&amp;nbsp;&amp;nbsp; Tree&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Style Oplocks&amp;nbsp; Status&lt;/P&gt;&lt;P&gt; -------- -------- ----- -------- ---------&lt;/P&gt;&lt;P&gt; test&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unix&amp;nbsp; enabled&amp;nbsp; normal &lt;/P&gt;&lt;P&gt;fas2&amp;gt; ping ldap2.local.prv&lt;/P&gt;&lt;P&gt; ldap2.local.prv is alive&lt;/P&gt;&lt;P&gt;fas2&amp;gt; rdfile /etc/nsswitch.conf&lt;/P&gt;&lt;P&gt;hosts: files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dns &lt;/P&gt;&lt;P&gt;passwd: files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap &lt;/P&gt;&lt;P&gt;netgroup: files&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&amp;nbsp; ldap &lt;/P&gt;&lt;P&gt;group: files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap&lt;/P&gt;&lt;P&gt;shadow: files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Filer can successfully find host in netgroups that are stored in LDAP catalog:&lt;/P&gt;&lt;P&gt;fas2&amp;gt; options ldap.base.netgroup ldap.base.netgroup&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt; ou=Netgroup,dc=local,dc=prv &lt;/P&gt;&lt;P&gt;fas2&amp;gt; priv set advanced&lt;/P&gt;&lt;P&gt;fas2*&amp;gt; getXXbyYY netgrp home-hosts ldap2.local.prv&lt;/P&gt;&lt;P&gt;client ldap2.local.prv is in netgroup home-hosts&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With all this client still cannot mount volume. &lt;/P&gt;&lt;P&gt;ldap2:~ # mount.nfs -o rw,tcp,hard,timeo=600,nfsvers=3 fas2:/vol/test /mnt &lt;/P&gt;&lt;P&gt;mount.nfs: access denied by server while mounting fas2:/vol/test&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ldap2:~ # showmount -e fas2 &lt;/P&gt;&lt;P&gt;Export list for fas2: &lt;/P&gt;&lt;P&gt;/vol/test&amp;nbsp;&amp;nbsp; home-hosts &lt;/P&gt;&lt;P&gt;/vol/backup 172.20.20.29 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I enabled nfs.mountd.trace option, but i do not see any messages regarding denied access in /etc/messages on filer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i change access to volume &lt;/P&gt;&lt;P&gt;fas2&amp;gt; exportfs -io rw=ldap2.local.prv /vol/test &lt;/P&gt;&lt;P&gt;client is able to mount volume.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to `exportfs -f`, but it does not help.&amp;nbsp; I'm just wondering why when i try to check host membership in netgroup&lt;/P&gt;&lt;P&gt; with getXXbyYY on filer i see queries on LDAP server, but i do not see queries when I'm trying to mount volume from client.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:19:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/permission-denied-on-mount-operation-for-NFS-volume-with-netgroup-in-LDAP/m-p/57246#M5306</guid>
      <dc:creator>zinovik_igor</dc:creator>
      <dc:date>2025-06-05T06:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: permission denied on mount operation for NFS volume with netgroup in LDAP</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/permission-denied-on-mount-operation-for-NFS-volume-with-netgroup-in-LDAP/m-p/57250#M5307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My problem was that names that i specified in netgroup OU lacked PTR records in DNS.&lt;/P&gt;&lt;P&gt;On connection filer has only IP address that it need to map back to DNS name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i fixed reverse lookup everything start working fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2012 17:41:15 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/permission-denied-on-mount-operation-for-NFS-volume-with-netgroup-in-LDAP/m-p/57250#M5307</guid>
      <dc:creator>zinovik_igor</dc:creator>
      <dc:date>2012-11-28T17:41:15Z</dc:date>
    </item>
  </channel>
</rss>

