<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't get LDAP to work. in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Can-t-get-LDAP-to-work/m-p/77939#M7065</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;G'day!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't get LDAP to work on my filer at all! I know other people have it working so I must be doing something wrong. Can someone sanity check my config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the setup:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;FAS3140 running 7.3.1.1&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;OpenLDAP 2.3.43&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Samba 3.0.33&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;QTree with Unix style permissions.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Samba NT4 domain with LDAP backend.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Linux hosts authenticate to LDAP directly.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Windows hosts authenticate to LDAP via Samba domain controller.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Windows usernames are the same as Linux usernames.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What works:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Linux LDAP authentication.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Windows LDAP/Domain authentication.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Filer can join Windows domain (Option 1 or 2 in 'cifs setup' command authentication question.)&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;NFS mounts from Linux. (Correct Unix permissions.)&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;CIFS mounts if 'wafl.default_unix_user' is set to 'pcuser'. (Auth via domain seems to work but all CIFS users are mapped to this user.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What doesn't work:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;getXXbyYY getpwbyname_r username (Returns 'Could not get passwd entry for name = username')&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;wcc -u username (returns 'no passwd entry for username')&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;wcc -s username (returns Domain user information but has 'UNIX uid = 65534')&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Setting 'wafl.default_unix_user' to null results in 'Permission denied' message during CIFS mount.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Output during a CIFS mount attempt when 'cifs.trace_login' is ON:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With wafl.default_unix_user=pcuser:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.trace.authenticateUser.loginTraceIP:info]: AUTH: Login attempt by user smcewan of domain CGI2 from client machine 172.17.52.123 (OAK).&lt;BR /&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.dc.trace.DCConnection.statusMsg:info]: AUTH: TraceDC- attempting authentication with domain controller \\AW-LDAP.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.trace.authenticateUser.loginTraceMsg:info]: AUTH: User from 172.17.52.123 authenticated by DC.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.trace.mapNTToUnix:info]: AUTH: Mapping Windows user smcewan to Unix user smcewan.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.trace.mapNTToUnix:info]: AUTH: Mapping Windows user smcewan to Unix user pcuser.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.trace.authenticateUser.loginAccepted:info]: AUTH: Login by smcewan from 172.17.52.123 accepted.&lt;/P&gt;&lt;P&gt;(Mount succeeds but all access is mapped to the 'pcuser' Unix user.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With wafl.default_unix_user="":&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Thu Sep&amp;nbsp; 3 10:59:27 BST [AWFiler002: auth.trace.authenticateUser.loginTraceIP:info]: AUTH: Login attempt by user smcewan of domain CGI2 from client machine 172.17.52.123 (OAK).&lt;BR /&gt;Thu Sep&amp;nbsp; 3 10:59:27 BST [AWFiler002: auth.dc.trace.DCConnection.statusMsg:info]: AUTH: TraceDC- attempting authentication with domain controller \\AW-LDAP.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 10:59:28 BST [AWFiler002: auth.trace.authenticateUser.loginTraceMsg:info]: AUTH: User from 172.17.52.123 authenticated by DC.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 10:59:28 BST [AWFiler002: auth.trace.mapNTToUnix:info]: AUTH: Mapping Windows user smcewan to Unix user smcewan.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 10:59:28 BST [AWFiler002: auth.mapNTToUnix.failed:error]: AUTH: Error mapping NT user smcewan to Unix user: 0xc0000001 (Unix user name not valid). Login is rejected.&lt;/P&gt;&lt;P&gt;(Mount fails with 'Permission denied'.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Leaving the Domain and choosing option 4 (passwd, NIS or LDAP auth) during 'cifs setup' results in an 'Input/Output' error on the CIFS client and NO authentication trace messages from the filer. I don't really care if the filer is part of the Domain or not (we're 95% Linux) as long as I can get Windows clients to read and write files with the correct Unix ownership.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the above, and the fact that I'm not seeing any connections from the filer to the LDAP server, I've come to the conclusion that the filer isn't talking to the LDAP server at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My 'options ldap' output:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;ldap.ADdomain&lt;BR /&gt;ldap.base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dc=mydomain,dc=com&lt;BR /&gt;ldap.base.group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ou=Groups,dc=mydomain,dc=com&lt;BR /&gt;ldap.base.netgroup&lt;BR /&gt;ldap.base.passwd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ou=Users,dc=mydomain,dc=com&lt;BR /&gt;ldap.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;ldap.minimum_bind_level&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; anonymous&lt;BR /&gt;ldap.name&lt;BR /&gt;ldap.nssmap.attribute.gecos&amp;nbsp; gecos&lt;BR /&gt;ldap.nssmap.attribute.gidNumber gidNumber&lt;BR /&gt;ldap.nssmap.attribute.groupname cn&lt;BR /&gt;ldap.nssmap.attribute.homeDirectory homeDirectory&lt;BR /&gt;ldap.nssmap.attribute.loginShell loginShell&lt;BR /&gt;ldap.nssmap.attribute.memberNisNetgroup memberNisNetgroup&lt;BR /&gt;ldap.nssmap.attribute.memberUid memberUid&lt;BR /&gt;ldap.nssmap.attribute.netgroupname cn&lt;BR /&gt;ldap.nssmap.attribute.nisNetgroupTriple nisNetgroupTriple&lt;BR /&gt;ldap.nssmap.attribute.uid&amp;nbsp;&amp;nbsp;&amp;nbsp; uid&lt;BR /&gt;ldap.nssmap.attribute.uidNumber uidNumber&lt;BR /&gt;ldap.nssmap.attribute.userPassword userPassword&lt;BR /&gt;ldap.nssmap.objectClass.nisNetgroup nisNetgroup&lt;BR /&gt;ldap.nssmap.objectClass.posixAccount posixAccount&lt;BR /&gt;ldap.nssmap.objectClass.posixGroup posixGroup&lt;BR /&gt;ldap.passwd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ******&lt;BR /&gt;ldap.port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 389&lt;BR /&gt;ldap.servers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap.mydomain.com&lt;BR /&gt;ldap.servers.preferred&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap.mydomain.com&lt;BR /&gt;ldap.ssl.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;ldap.timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20&lt;BR /&gt;ldap.usermap.attribute.unixaccount unixaccount&lt;BR /&gt;ldap.usermap.attribute.windowsaccount windowsaccount&lt;BR /&gt;ldap.usermap.base&lt;BR /&gt;ldap.usermap.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My /etc/nsswitch.conf file:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;hosts: files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dns&lt;BR /&gt;passwd: ldap files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&lt;BR /&gt;netgroup: ldap files&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&lt;BR /&gt;group: ldap files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&lt;BR /&gt;shadow: files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/etc/usermap.cfg is empty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm at a loss. Can anyone offer some advice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jun 2025 07:24:22 GMT</pubDate>
    <dc:creator>shane_mcewan</dc:creator>
    <dc:date>2025-06-05T07:24:22Z</dc:date>
    <item>
      <title>Can't get LDAP to work.</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Can-t-get-LDAP-to-work/m-p/77939#M7065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;G'day!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't get LDAP to work on my filer at all! I know other people have it working so I must be doing something wrong. Can someone sanity check my config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the setup:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;FAS3140 running 7.3.1.1&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;OpenLDAP 2.3.43&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Samba 3.0.33&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;QTree with Unix style permissions.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Samba NT4 domain with LDAP backend.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Linux hosts authenticate to LDAP directly.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Windows hosts authenticate to LDAP via Samba domain controller.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Windows usernames are the same as Linux usernames.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What works:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Linux LDAP authentication.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Windows LDAP/Domain authentication.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Filer can join Windows domain (Option 1 or 2 in 'cifs setup' command authentication question.)&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;NFS mounts from Linux. (Correct Unix permissions.)&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;CIFS mounts if 'wafl.default_unix_user' is set to 'pcuser'. (Auth via domain seems to work but all CIFS users are mapped to this user.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What doesn't work:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;getXXbyYY getpwbyname_r username (Returns 'Could not get passwd entry for name = username')&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;wcc -u username (returns 'no passwd entry for username')&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;wcc -s username (returns Domain user information but has 'UNIX uid = 65534')&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Setting 'wafl.default_unix_user' to null results in 'Permission denied' message during CIFS mount.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Output during a CIFS mount attempt when 'cifs.trace_login' is ON:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With wafl.default_unix_user=pcuser:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.trace.authenticateUser.loginTraceIP:info]: AUTH: Login attempt by user smcewan of domain CGI2 from client machine 172.17.52.123 (OAK).&lt;BR /&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.dc.trace.DCConnection.statusMsg:info]: AUTH: TraceDC- attempting authentication with domain controller \\AW-LDAP.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.trace.authenticateUser.loginTraceMsg:info]: AUTH: User from 172.17.52.123 authenticated by DC.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.trace.mapNTToUnix:info]: AUTH: Mapping Windows user smcewan to Unix user smcewan.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.trace.mapNTToUnix:info]: AUTH: Mapping Windows user smcewan to Unix user pcuser.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 11:30:14 BST [AWFiler002: auth.trace.authenticateUser.loginAccepted:info]: AUTH: Login by smcewan from 172.17.52.123 accepted.&lt;/P&gt;&lt;P&gt;(Mount succeeds but all access is mapped to the 'pcuser' Unix user.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With wafl.default_unix_user="":&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Thu Sep&amp;nbsp; 3 10:59:27 BST [AWFiler002: auth.trace.authenticateUser.loginTraceIP:info]: AUTH: Login attempt by user smcewan of domain CGI2 from client machine 172.17.52.123 (OAK).&lt;BR /&gt;Thu Sep&amp;nbsp; 3 10:59:27 BST [AWFiler002: auth.dc.trace.DCConnection.statusMsg:info]: AUTH: TraceDC- attempting authentication with domain controller \\AW-LDAP.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 10:59:28 BST [AWFiler002: auth.trace.authenticateUser.loginTraceMsg:info]: AUTH: User from 172.17.52.123 authenticated by DC.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 10:59:28 BST [AWFiler002: auth.trace.mapNTToUnix:info]: AUTH: Mapping Windows user smcewan to Unix user smcewan.&lt;BR /&gt;Thu Sep&amp;nbsp; 3 10:59:28 BST [AWFiler002: auth.mapNTToUnix.failed:error]: AUTH: Error mapping NT user smcewan to Unix user: 0xc0000001 (Unix user name not valid). Login is rejected.&lt;/P&gt;&lt;P&gt;(Mount fails with 'Permission denied'.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Leaving the Domain and choosing option 4 (passwd, NIS or LDAP auth) during 'cifs setup' results in an 'Input/Output' error on the CIFS client and NO authentication trace messages from the filer. I don't really care if the filer is part of the Domain or not (we're 95% Linux) as long as I can get Windows clients to read and write files with the correct Unix ownership.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the above, and the fact that I'm not seeing any connections from the filer to the LDAP server, I've come to the conclusion that the filer isn't talking to the LDAP server at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My 'options ldap' output:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;ldap.ADdomain&lt;BR /&gt;ldap.base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dc=mydomain,dc=com&lt;BR /&gt;ldap.base.group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ou=Groups,dc=mydomain,dc=com&lt;BR /&gt;ldap.base.netgroup&lt;BR /&gt;ldap.base.passwd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ou=Users,dc=mydomain,dc=com&lt;BR /&gt;ldap.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on&lt;BR /&gt;ldap.minimum_bind_level&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; anonymous&lt;BR /&gt;ldap.name&lt;BR /&gt;ldap.nssmap.attribute.gecos&amp;nbsp; gecos&lt;BR /&gt;ldap.nssmap.attribute.gidNumber gidNumber&lt;BR /&gt;ldap.nssmap.attribute.groupname cn&lt;BR /&gt;ldap.nssmap.attribute.homeDirectory homeDirectory&lt;BR /&gt;ldap.nssmap.attribute.loginShell loginShell&lt;BR /&gt;ldap.nssmap.attribute.memberNisNetgroup memberNisNetgroup&lt;BR /&gt;ldap.nssmap.attribute.memberUid memberUid&lt;BR /&gt;ldap.nssmap.attribute.netgroupname cn&lt;BR /&gt;ldap.nssmap.attribute.nisNetgroupTriple nisNetgroupTriple&lt;BR /&gt;ldap.nssmap.attribute.uid&amp;nbsp;&amp;nbsp;&amp;nbsp; uid&lt;BR /&gt;ldap.nssmap.attribute.uidNumber uidNumber&lt;BR /&gt;ldap.nssmap.attribute.userPassword userPassword&lt;BR /&gt;ldap.nssmap.objectClass.nisNetgroup nisNetgroup&lt;BR /&gt;ldap.nssmap.objectClass.posixAccount posixAccount&lt;BR /&gt;ldap.nssmap.objectClass.posixGroup posixGroup&lt;BR /&gt;ldap.passwd&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ******&lt;BR /&gt;ldap.port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 389&lt;BR /&gt;ldap.servers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap.mydomain.com&lt;BR /&gt;ldap.servers.preferred&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap.mydomain.com&lt;BR /&gt;ldap.ssl.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;BR /&gt;ldap.timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20&lt;BR /&gt;ldap.usermap.attribute.unixaccount unixaccount&lt;BR /&gt;ldap.usermap.attribute.windowsaccount windowsaccount&lt;BR /&gt;ldap.usermap.base&lt;BR /&gt;ldap.usermap.enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My /etc/nsswitch.conf file:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;hosts: files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dns&lt;BR /&gt;passwd: ldap files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&lt;BR /&gt;netgroup: ldap files&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&lt;BR /&gt;group: ldap files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&lt;BR /&gt;shadow: files&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/etc/usermap.cfg is empty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm at a loss. Can anyone offer some advice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 07:24:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Can-t-get-LDAP-to-work/m-p/77939#M7065</guid>
      <dc:creator>shane_mcewan</dc:creator>
      <dc:date>2025-06-05T07:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get LDAP to work.</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Can-t-get-LDAP-to-work/m-p/77945#M7067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I knew I was doing something stupid! &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.netapp.com/images/emoticons/confused.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The filer couldn't resolve the name of the LDAP server. I put in the IP address and it started working! It would have been helpful if there was a DNS lookup error message or something in the logs rather than just silently failing. It could have saved me several hours.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Sep 2009 13:55:27 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Can-t-get-LDAP-to-work/m-p/77945#M7067</guid>
      <dc:creator>shane_mcewan</dc:creator>
      <dc:date>2009-09-03T13:55:27Z</dc:date>
    </item>
  </channel>
</rss>

