<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate Based Authentication against Unified Manager 6.4 in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Certificate-Based-Authentication-against-Unified-Manager-6-4/m-p/123216#M22124</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/48477"&gt;@acjackson﻿&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not believe SSL cert based auth is possible with Unified Manager 6+ releases. &amp;nbsp;I checked the SDK 5.5 docs and found this that agrees:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="NaServer::set_style" href="https://community.netapp.com/t5/forums/replypage/board-id/oncommand-storage-management-software-discussions/message-id/help/programming_guide/perl_api_bindings/session_mngmnt_apis_perl_bindings.htm#NaServer::set_style" target="_blank"&gt;NaServer::set_style&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;$style&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;The authentication style&lt;/P&gt;&lt;P&gt;Following are the supported values:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;HOSTS&lt;/SPAN&gt;—to use the hosts.equiv file on the storage system to determine access rights.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;LOGIN&lt;/SPAN&gt;—to provide user name and password information. You can set the user name by using the API set_admin_user.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;CERTIFICATE&lt;/SPAN&gt;—to use certificates to authenticate clients who attempt to connect to a server, without using login credentials. This style automatically sets HTTPS as the transport mechanism. You can use this authentication mechanism for clustered Data ONTAP 8.2 and OnCommand Unified Manager 5.0.2, 5.1, and 5.2.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;To authenticate the server, server certificate verification and hostname verification is required.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;For more information, see the APIs&lt;SPAN&gt;NaServer::set_client_cert_and_key()&lt;/SPAN&gt;,&lt;SPAN&gt;NaServer::set_ca_certs(),&lt;/SPAN&gt;&lt;SPAN&gt;NaServer::set_server_cert_verification(),&lt;/SPAN&gt;and&lt;SPAN&gt;NaServer::set_hostname_verification()&lt;/SPAN&gt;.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Chris Madden&lt;/P&gt;&lt;P&gt;Solution Architect - 3rd Platform - Systems Engineering NetApp EMEA (and author of Harvest)&lt;/P&gt;&lt;P&gt;Blog:&amp;nbsp;&lt;A href="http://blog.pkiwi.com/" target="_blank"&gt;It all begins with data&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If this post resolved your issue, please help others by selecting&amp;nbsp;&lt;STRONG&gt;ACCEPT AS SOLUTION&lt;/STRONG&gt;&amp;nbsp;or adding a&amp;nbsp;&lt;STRONG&gt;KUDO &lt;/STRONG&gt;or both!&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Sep 2016 18:15:41 GMT</pubDate>
    <dc:creator>madden</dc:creator>
    <dc:date>2016-09-13T18:15:41Z</dc:date>
    <item>
      <title>Certificate Based Authentication against Unified Manager 6.4</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Certificate-Based-Authentication-against-Unified-Manager-6-4/m-p/123171#M22114</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to setup Certificate Based Authentication against&amp;nbsp;Unified Manager 6.4 to use with NMSDK.&lt;/P&gt;&lt;P&gt;I did manage to setup CBA against DFM 5.2, but I didnt found any option on the Unified Manager: the&amp;nbsp;"dfm" command on console has no 'dfm ssl service' option anymore&lt;/P&gt;&lt;P&gt;Because I couldn't find any topic on CBA in the Unified Manager 6.4 manual either, I am not sure, if it's still supported.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I have to use LDAP for certificate&amp;nbsp;based authentication?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 19:08:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Certificate-Based-Authentication-against-Unified-Manager-6-4/m-p/123171#M22114</guid>
      <dc:creator>acjackson</dc:creator>
      <dc:date>2025-06-04T19:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate Based Authentication against Unified Manager 6.4</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Certificate-Based-Authentication-against-Unified-Manager-6-4/m-p/123216#M22124</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/48477"&gt;@acjackson﻿&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not believe SSL cert based auth is possible with Unified Manager 6+ releases. &amp;nbsp;I checked the SDK 5.5 docs and found this that agrees:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="NaServer::set_style" href="https://community.netapp.com/t5/forums/replypage/board-id/oncommand-storage-management-software-discussions/message-id/help/programming_guide/perl_api_bindings/session_mngmnt_apis_perl_bindings.htm#NaServer::set_style" target="_blank"&gt;NaServer::set_style&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;$style&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;The authentication style&lt;/P&gt;&lt;P&gt;Following are the supported values:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;HOSTS&lt;/SPAN&gt;—to use the hosts.equiv file on the storage system to determine access rights.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;LOGIN&lt;/SPAN&gt;—to provide user name and password information. You can set the user name by using the API set_admin_user.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;CERTIFICATE&lt;/SPAN&gt;—to use certificates to authenticate clients who attempt to connect to a server, without using login credentials. This style automatically sets HTTPS as the transport mechanism. You can use this authentication mechanism for clustered Data ONTAP 8.2 and OnCommand Unified Manager 5.0.2, 5.1, and 5.2.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;To authenticate the server, server certificate verification and hostname verification is required.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;For more information, see the APIs&lt;SPAN&gt;NaServer::set_client_cert_and_key()&lt;/SPAN&gt;,&lt;SPAN&gt;NaServer::set_ca_certs(),&lt;/SPAN&gt;&lt;SPAN&gt;NaServer::set_server_cert_verification(),&lt;/SPAN&gt;and&lt;SPAN&gt;NaServer::set_hostname_verification()&lt;/SPAN&gt;.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Chris Madden&lt;/P&gt;&lt;P&gt;Solution Architect - 3rd Platform - Systems Engineering NetApp EMEA (and author of Harvest)&lt;/P&gt;&lt;P&gt;Blog:&amp;nbsp;&lt;A href="http://blog.pkiwi.com/" target="_blank"&gt;It all begins with data&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If this post resolved your issue, please help others by selecting&amp;nbsp;&lt;STRONG&gt;ACCEPT AS SOLUTION&lt;/STRONG&gt;&amp;nbsp;or adding a&amp;nbsp;&lt;STRONG&gt;KUDO &lt;/STRONG&gt;or both!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 18:15:41 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Certificate-Based-Authentication-against-Unified-Manager-6-4/m-p/123216#M22124</guid>
      <dc:creator>madden</dc:creator>
      <dc:date>2016-09-13T18:15:41Z</dc:date>
    </item>
  </channel>
</rss>

