<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QUESTION - Interaction between OnCommand and a LDAP server with users/groups in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/QUESTION-Interaction-between-OnCommand-and-a-LDAP-server-with-users-groups/m-p/78711#M16407</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Emanuel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just recently setup OnCommand 5 on a RHEL 5 x86_64 system and ran into some similar issues regarding the AD/LDAP configuration. First make sure your OnCommand LDAP configuration matches the following screenshot (I got these settings through several other communities.netapp.com posts):&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://community.netapp.com/legacyfs/online/16511_Screen+Shot+2012-08-11+at+12.48.13+PM.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next when you add a group to the administrative users page you will need to specify the full LDAP path for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cn=LDAP Group Name,ou=Groups,dc=domain,dc=org&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as your second questions goes, I have not dealt with this as I have been using the root account when working from the command line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 11 Aug 2012 18:03:44 GMT</pubDate>
    <dc:creator>dburkland</dc:creator>
    <dc:date>2012-08-11T18:03:44Z</dc:date>
    <item>
      <title>QUESTION - Interaction between OnCommand and a LDAP server with users/groups</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/QUESTION-Interaction-between-OnCommand-and-a-LDAP-server-with-users-groups/m-p/78705#M16405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am following up on a previous discussion about establishing authentication; we got that working.&amp;nbsp; But a couple of new issues have appeared and I am hoping for community feed back.&amp;nbsp; We have a Linux host with a package that allows authentication through a Windows W2K8 domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q1:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; They are authenticating using something other than "PAM" on the Linux host with Windows AD; this seems to be okay for users but not groups; groups are not showing up as contain name objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we enter a group in a full W2K8 domain we enter them as admin users as - "DOMAIN/Domain Group" name ( i think... its been a while for me ); when we enter the AD group with just the name it seems to accept it but does not enter the group name as a container-name style as it does for individual users.&amp;nbsp; Is there a specific way to add groups in this sort of configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q2:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A successful admin user on the GUI ( able to make changes to the database ) does not have the same privilege on the command line; only ROOT seems to work for them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have one of their admin users log into the GUI and change properties on a storage controller ( changing the default protocol from global to SSH and committing the change ).&amp;nbsp; this works fine but in the command line the same user is not allowed to run DFM commands ( like dfm eventType list ); complaining user does not have READ privileges.&amp;nbsp; This would be a caching issue on the host or something else.&amp;nbsp; Has anyone else experienced this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for ideas ... thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:21:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/QUESTION-Interaction-between-OnCommand-and-a-LDAP-server-with-users-groups/m-p/78705#M16405</guid>
      <dc:creator>emanuel</dc:creator>
      <dc:date>2025-06-05T06:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: QUESTION - Interaction between OnCommand and a LDAP server with users/groups</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/QUESTION-Interaction-between-OnCommand-and-a-LDAP-server-with-users-groups/m-p/78711#M16407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Emanuel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just recently setup OnCommand 5 on a RHEL 5 x86_64 system and ran into some similar issues regarding the AD/LDAP configuration. First make sure your OnCommand LDAP configuration matches the following screenshot (I got these settings through several other communities.netapp.com posts):&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://community.netapp.com/legacyfs/online/16511_Screen+Shot+2012-08-11+at+12.48.13+PM.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next when you add a group to the administrative users page you will need to specify the full LDAP path for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cn=LDAP Group Name,ou=Groups,dc=domain,dc=org&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as your second questions goes, I have not dealt with this as I have been using the root account when working from the command line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Aug 2012 18:03:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/QUESTION-Interaction-between-OnCommand-and-a-LDAP-server-with-users-groups/m-p/78711#M16407</guid>
      <dc:creator>dburkland</dc:creator>
      <dc:date>2012-08-11T18:03:44Z</dc:date>
    </item>
  </channel>
</rss>

