<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access denied on 7-mode NFS qtree in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126037#M8614</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok, I'm test enviroment and i'm free to change whatever i want.&lt;/P&gt;&lt;P&gt;I understand that i need to map client linux user ; USER01 with the Windows user on the filer, and add that mapping information to usermap.cfg&lt;/P&gt;&lt;P&gt;Results of&amp;nbsp;fsecurity command is is as pasted below so in this case what is the correct mapping?&lt;/P&gt;&lt;P&gt;i was adding line "USER01" == root&amp;nbsp; earlier as i thought it will resolve the access issue, but no results&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;netapp01&amp;gt; fsecurity show /vol/test/qtree_test&lt;BR /&gt;[/vol/test/qtree_test - Directory (inum 96)]&lt;BR /&gt;&amp;nbsp; Security style: NTFS&lt;BR /&gt;&amp;nbsp; Effective style: NTFS&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; DOS attributes: 0x0030 (---AD---)&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; Unix security:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; uid: 0 (root)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; gid: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mode: 0777 (rwxrwxrwx)&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; NTFS security descriptor:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Owner: BUILTIN\Administrators&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group: BUILTIN\Administrators&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; DACL:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Allow - Everyone - 0x001f01ff (Full Control)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Allow - Everyone - 0x10000000 - OI|CI|IO&lt;BR /&gt;netapp01&amp;gt;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Dec 2016 15:28:59 GMT</pubDate>
    <dc:creator>explorer12</dc:creator>
    <dc:date>2016-12-07T15:28:59Z</dc:date>
    <item>
      <title>Access denied on 7-mode NFS qtree</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126027#M8610</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 7-mode netapp where we store snapshots with NFS exports for redhat servers&lt;/P&gt;&lt;P&gt;User rights for that netapp are NOT managed by AD etc, there are just couple of local admin users only used by netap admins.&lt;/P&gt;&lt;P&gt;Linux user1@redhat1 can map to the export and see the snapshots so i think exports settings are ok, (i have just added IP of that Linux host to Allow Read Write list for /vol/test )&lt;/P&gt;&lt;P&gt;Export Rule -&amp;gt; Security flavor is set as :&lt;STRONG&gt; UNIX&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;user1@redhat1 /mnt/tony1 $ cd .snapshot&lt;/P&gt;&lt;P&gt;user1@redhat1 /mnt/tony1/.snapshot $ pwd&lt;/P&gt;&lt;P&gt;/mnt/tony1/.snapshot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that user cannot step into the qtree that contains the files user needs, qtree security style is&lt;STRONG&gt; NTFS&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[user1@redhat1 sv_weekly.0]$ ls -la qtree_test/&lt;/P&gt;&lt;P&gt;ls: cannot open directory qtree_test/: Permission denied&lt;/P&gt;&lt;P&gt;[user1@redhat1 sv_weekly.0]$ cd qtree_test/&lt;/P&gt;&lt;P&gt;-bash: cd: qtree_test/: Permission denied&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can i resolve that issue ?&lt;/P&gt;&lt;P&gt;Do I need to modify usermap.cfg file ? If so, i understand i will have to create additional local user on the netapp.&lt;/P&gt;&lt;P&gt;What entry should i add to usermap.cfg file.&lt;/P&gt;&lt;P&gt;How that mapping should be done so that linux user has just read/right rights to that one qtree.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;explorer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 18:07:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126027#M8610</guid>
      <dc:creator>explorer12</dc:creator>
      <dc:date>2025-06-04T18:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied on 7-mode NFS qtree</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126034#M8611</link>
      <description>&lt;P&gt;Any time you have to access NTFS security style with NFS/Linux clients, you need a valid Windows user that has access to the files/folders to map the UNIX user to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, yes, you would need to adjust usermap.cfg.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The mapping is only to help the filer determine *who* the UNIX user should be in Window land. After that, the ACLs control access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Usermap syntax is located in the usermap file.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 14:33:38 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126034#M8611</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2016-12-07T14:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied on 7-mode NFS qtree</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126035#M8612</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for you replay, but to be honest I do not understand sth basic here, where that Windows user came from ? if i have Linux sever directly connecting to Netapp NFS, there is now Windows OS involved in that.&lt;/P&gt;&lt;P&gt;Where that Windows user schould be created ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;explorer12&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 14:44:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126035#M8612</guid>
      <dc:creator>explorer12</dc:creator>
      <dc:date>2016-12-07T14:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied on 7-mode NFS qtree</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126036#M8613</link>
      <description>&lt;P&gt;It comes from the NTFS security style qtree. UNIX users and permissions have no idea how to translate NTFS ACLs. The ACLs have users and groups that the UNIX side does not understand. Thus, when authenticating to the filer, ONTAP helps translate from UNIX semantics into NTFS semantics.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You don't create the Windows user; you use an existing AD user that is already on the NTFS style qtree's ACLs. You can see permissions from the filer with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;filer&amp;gt; fsecurity show /vol/volname/qtree&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 14:59:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126036#M8613</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2016-12-07T14:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied on 7-mode NFS qtree</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126037#M8614</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok, I'm test enviroment and i'm free to change whatever i want.&lt;/P&gt;&lt;P&gt;I understand that i need to map client linux user ; USER01 with the Windows user on the filer, and add that mapping information to usermap.cfg&lt;/P&gt;&lt;P&gt;Results of&amp;nbsp;fsecurity command is is as pasted below so in this case what is the correct mapping?&lt;/P&gt;&lt;P&gt;i was adding line "USER01" == root&amp;nbsp; earlier as i thought it will resolve the access issue, but no results&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;netapp01&amp;gt; fsecurity show /vol/test/qtree_test&lt;BR /&gt;[/vol/test/qtree_test - Directory (inum 96)]&lt;BR /&gt;&amp;nbsp; Security style: NTFS&lt;BR /&gt;&amp;nbsp; Effective style: NTFS&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; DOS attributes: 0x0030 (---AD---)&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; Unix security:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; uid: 0 (root)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; gid: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mode: 0777 (rwxrwxrwx)&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; NTFS security descriptor:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Owner: BUILTIN\Administrators&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group: BUILTIN\Administrators&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; DACL:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Allow - Everyone - 0x001f01ff (Full Control)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Allow - Everyone - 0x10000000 - OI|CI|IO&lt;BR /&gt;netapp01&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 15:28:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126037#M8614</guid>
      <dc:creator>explorer12</dc:creator>
      <dc:date>2016-12-07T15:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied on 7-mode NFS qtree</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126038#M8615</link>
      <description>&lt;P&gt;The folder has "Everyone - Full" so any windows mapping will work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What does "wcc -u root" show? Is it mapping to a valid Windows user?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 15:37:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126038#M8615</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2016-12-07T15:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied on 7-mode NFS qtree</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126039#M8616</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like no mapping at all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; wcc -u root&lt;BR /&gt;Mapped user not found&lt;BR /&gt;Issue "options cifs.trace_login on" to get more detailed information.&lt;BR /&gt;&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 15:46:43 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126039#M8616</guid>
      <dc:creator>explorer12</dc:creator>
      <dc:date>2016-12-07T15:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Access denied on 7-mode NFS qtree</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126040#M8617</link>
      <description>&lt;P&gt;Looks like you found the issue then.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the filer joined to AD at all?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If not, change the security style to UNIX.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If so, make sure your usermap entry syntax is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://library.netapp.com/ecmdocs/ECMP1196993/html/GUID-83730CE4-A3FC-46B5-918D-2790D205A22B.html" target="_blank"&gt;https://library.netapp.com/ecmdocs/ECMP1196993/html/GUID-83730CE4-A3FC-46B5-918D-2790D205A22B.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your case:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;domain\user == root&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 16:35:48 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Access-denied-on-7-mode-NFS-qtree/m-p/126040#M8617</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2016-12-07T16:35:48Z</dc:date>
    </item>
  </channel>
</rss>

