<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: howto create separate, least priveledged role for OCUM Service Account user ? in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/145821#M26491</link>
    <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your solution.&lt;/P&gt;
&lt;P&gt;I tried it on my 9.3P7 and works fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One question though.&lt;/P&gt;
&lt;P&gt;We moved from local admin accounts to domain passthrough accounts for our administrators.&lt;/P&gt;
&lt;P&gt;But, as domain passthrough accounts doesn´t have SSH we can´t use the restore function in OCUM (therefor I´m looking at your solution)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But same here now when we have a RO role.&lt;/P&gt;
&lt;P&gt;What function do I need to change to be able to do a restore in OCUM with this kind of security login role?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;//Henrik&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jan 2019 07:36:50 GMT</pubDate>
    <dc:creator>connoisseur</dc:creator>
    <dc:date>2019-01-10T07:36:50Z</dc:date>
    <item>
      <title>how to create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/133828#M24276</link>
      <description>&lt;P&gt;We have OCUM 7.1 with integrated (linked with cert) OCPM, by policy it is not allowed to use the default admin role for the service account which will gather the Filers.&lt;/P&gt;
&lt;P&gt;So we need to create a seperate role with the required permissions and add the user to this role.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know if there is a howto ?? (i found one for DFM 7-Mode but not for OCUM cDOT) or can advise howto do this ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards imho&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://en.wikipedia.org/wiki/Principle_of_least_privilege" target="_blank"&gt;https://en.wikipedia.org/wiki/Principle_of_least_privilege&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 14:42:09 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/133828#M24276</guid>
      <dc:creator>IMHOTEPSON</dc:creator>
      <dc:date>2025-06-04T14:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134155#M24336</link>
      <description>&lt;P&gt;hopefully this would help&lt;/P&gt;
&lt;P&gt;&lt;A href="https://library.netapp.com/ecm/ecm_get_file/ECMLP2638750" target="_blank"&gt;https://library.netapp.com/ecm/ecm_get_file/ECMLP2638750&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 11:30:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134155#M24336</guid>
      <dc:creator>Jeff_Yao</dc:creator>
      <dc:date>2017-09-01T11:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134156#M24337</link>
      <description>&lt;P&gt;no not really because i did not find the detailed requirements for creating a sep. OCUM User role on Netapp cDOT.&lt;/P&gt;&lt;P&gt;- on DFM there was a documentation howto create a least privileged User for DFM....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Guide says only admin role &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.netapp.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 12:02:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134156#M24337</guid>
      <dc:creator>IMHOTEPSON</dc:creator>
      <dc:date>2017-09-01T12:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134160#M24339</link>
      <description>&lt;P&gt;* CORRECTION/UPDATE * - I just grabbed what I think is the lates RBAC/privs file and it doesn't look like it'll work - no version # for OCUM appears in the tool. &amp;nbsp;I pinged dbkelly to see if I'm just missing something...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The RBAC tool (discussed here):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.netapp.com/t5/Virtualization-and-Cloud-Articles-and-Resources/How-to-use-the-RBAC-User-Creator-for-Data-ONTAP/ta-p/86601" target="_blank"&gt;https://community.netapp.com/t5/Virtualization-and-Cloud-Articles-and-Resources/How-to-use-the-RBAC-User-Creator-for-Data-ONTAP/ta-p/86601&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has a template/profile for OCUM. &amp;nbsp;We used that in our shop and it seemed to work out pretty well. &amp;nbsp;Haven't run into any errors/problems so far with the resulting account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Chris&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 17:01:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134160#M24339</guid>
      <dc:creator>colsen</dc:creator>
      <dc:date>2017-09-01T17:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134192#M24345</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;installed the tool, but it failed on selecting the product OnCommand Unified Manager Select the version (no version selctable)&lt;/P&gt;&lt;P&gt;We are using ONTAP 9.0P2 with OCUM 7.1&lt;/P&gt;&lt;P&gt;If i check the ontapPrivs.xml, i only see the 7 Mode Version DFM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;product id="dfm" label="OnCommand Unified Manager" description="OnCommand Unified Manager (DFM)"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;dfm id="dfm51" label="DFM 5.1"&amp;gt;&lt;/P&gt;&lt;P&gt;and i did not the ONTAP 9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2017 09:10:33 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134192#M24345</guid>
      <dc:creator>IMHOTEPSON</dc:creator>
      <dc:date>2017-09-04T09:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134224#M24350</link>
      <description>&lt;P&gt;Yes - I have a question into the product team as to what version of the privs.xml file has OCUM 7.x included. &amp;nbsp;I know we had a working version at one point but not sure why it's not working now (and/or if I'm just completely mis-remembering it).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will post an update as soon as I hear back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 11:54:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134224#M24350</guid>
      <dc:creator>colsen</dc:creator>
      <dc:date>2017-09-05T11:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134330#M24364</link>
      <description>&lt;P&gt;Upfront warning - this user setup below is not approved by NetApp support and they won't take any responsibility for failed polling, missing data, alarms not triggering/catching issues, etc. &amp;nbsp;I don't expect any issues with this configuration but wanted to be as clear on this as possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've had success using a limited role with OCUM/OPM 7.1 using&amp;nbsp;the commands below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;security login role create -vserver &amp;lt;cluster_vserver&amp;gt; -role ocum_readonly_role -cmddirname DEFAULT -access readonly
security login role create -vserver &amp;lt;cluster_vserver&amp;gt; -role ocum_readonly_role -cmddirname "cluster application-record" -access all
security login role create -vserver &amp;lt;cluster_vserver&amp;gt; -role ocum_readonly_role -cmddirname "metrocluster modify" -access all
security login role create -vserver &amp;lt;cluster_vserver&amp;gt; -role ocum_readonly_role -cmddirname "metrocluster show" -access all
vserver services web access create -vserver &amp;lt;cluster_vserver&amp;gt; -name spi -role ocum_readonly_role
security login create -vserver &amp;lt;cluster_vserver&amp;gt; -user ocum_readonly -application ontapi -authmethod password -role ocum_readonly_role
security login create -vserver &amp;lt;cluster_vserver&amp;gt; -user ocum_readonly -application http -authmethod password -role ocum_readonly_role&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the rationale for the commands above. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- A limited role is setup with access to the 'cluster application-record' command tree. This is where ONTAP tracks what OCUM/OPM/WFA instances are managing the cluster.&lt;/P&gt;&lt;P&gt;- OCUM also demands access to the 'metrocluster' command tree and polling fails without this access.&lt;BR /&gt;- A SPI role is created to allow OCUM/OPM to pull performance files.&lt;BR /&gt;- A login is created with http/ontapi access. All connectivity should be through API calls for most metrics, or HTTP calls to the SPI interface to pull performance data.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 20:47:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134330#M24364</guid>
      <dc:creator>joele</dc:creator>
      <dc:date>2017-09-07T20:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134380#M24373</link>
      <description>&lt;P&gt;Good morning - thanks a bunch for posting that role/account listing. &amp;nbsp;I had some time this morning so I tried setting up an account that way and applying it to the cluster data sources section on our COOP/non-prod cluster. &amp;nbsp;Anyway, after I updated the credentials on this particular cluster I got a "cluster login failed" status inside OCUM 7.2 - then no polling would occur and the cluster was unreachable. &amp;nbsp;I gave it a bit just to see if the polling cycle would pick it back up, but no dice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I went ahead and added a ssh privilege to the role and verified the acct/pswd work via an interactive shell (i.e. just making sure I didn't fat-finger anything) but OCUM must be trying some method/whatever that isn't supported in the role as you've specified. &amp;nbsp;Any ideas what might be missing and/or where I'd look to see what the specific problem was?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2017 13:16:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134380#M24373</guid>
      <dc:creator>colsen</dc:creator>
      <dc:date>2017-09-11T13:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134381#M24374</link>
      <description>&lt;P&gt;this solution looks fine until now, the first tests are successful, we will check the Metrocluster at next and then we will see if we still get some issues.&lt;/P&gt;&lt;P&gt;many thanks for now &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2017 13:33:32 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134381#M24374</guid>
      <dc:creator>IMHOTEPSON</dc:creator>
      <dc:date>2017-09-11T13:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134383#M24375</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/2935"&gt;@colsen&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't tried this configuration with OCUM 7.2 yet but will take a look in the near future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/10433"&gt;@IMHOTEPSON&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Glad to hear the first tests are looking good!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2017 14:03:41 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134383#M24375</guid>
      <dc:creator>joele</dc:creator>
      <dc:date>2017-09-11T14:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134407#M24383</link>
      <description>&lt;P&gt;we use a seperate role for compliance scripts ... (custom)&lt;/P&gt;&lt;P&gt;added the&lt;/P&gt;&lt;P&gt;-cmddirname "system node run" -access all&lt;/P&gt;&lt;P&gt;-cmddirname "set" -access all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for testing, this will be reduced to the dedicated commands, thanks for the keep in mind thoughts &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 15:11:33 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134407#M24383</guid>
      <dc:creator>IMHOTEPSON</dc:creator>
      <dc:date>2017-09-12T15:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134417#M24384</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/10433"&gt;@IMHOTEPSON&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is OCUM running those compliance scripts as well? &amp;nbsp;Adding the 'system node run' tree with 'all' access opens up the roles capabilities by quite a bit, just a quick thought.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 13:41:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134417#M24384</guid>
      <dc:creator>joele</dc:creator>
      <dc:date>2017-09-12T13:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134422#M24386</link>
      <description>&lt;P&gt;sure you are right, the compliance tool will have a seperate user and will run fro another system, so it is not addressed to ocum itself.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 15:09:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134422#M24386</guid>
      <dc:creator>IMHOTEPSON</dc:creator>
      <dc:date>2017-09-12T15:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134431#M24389</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Okay - so I get the honorary "follow the rules dummy" award. &amp;nbsp;Anyway, I looked at your role list and saw the "metrocluster modify/show" and said "oh, we don't run metrocluster" so I didn't add those. &amp;nbsp;My colleague said, "well maybe if it gets a deny on any call it says discover failed". &amp;nbsp;We added those two permissions and voila - it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We'll let it run against our COOP cluster and make sure things look good and then apply it to the other clusters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks so much for the list - wish I had just followed it correctly in the first place!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 18:11:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134431#M24389</guid>
      <dc:creator>colsen</dc:creator>
      <dc:date>2017-09-12T18:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134432#M24390</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/2935"&gt;@colsen&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Happens to all of us at one point or another! &amp;nbsp;I'm glad that OCUM is no longer complaining about failed polling. &amp;nbsp;I haven't had a chance to test out 7.2 with this custom role yet - let me know if you see any issues.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 18:34:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/134432#M24390</guid>
      <dc:creator>joele</dc:creator>
      <dc:date>2017-09-12T18:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/138466#M25176</link>
      <description>&lt;P&gt;On Ontap 9.3, the cluster vserver already has a service called "spi" in the admin role (and type admin). Wouldn't this conflict with the commands you've listed?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(cluster)::&amp;gt; vserver services web access show&lt;BR /&gt;Vserver Type Service Name Role&lt;BR /&gt;-------------- -------- ---------------- ----------------&lt;BR /&gt;(cluster) admin spi admin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Ed&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 19:15:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/138466#M25176</guid>
      <dc:creator>EdRubins</dc:creator>
      <dc:date>2018-02-26T19:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/138551#M25196</link>
      <description>&lt;P&gt;It's quite&amp;nbsp;likely it would, yes.&amp;nbsp; I'm curious to see how a 9.1/9.2 cluster with that previous set of commands run is impacted after upgrading to 9.3.&amp;nbsp; I'll add this to the list of things to check&amp;nbsp;on.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 15:21:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/138551#M25196</guid>
      <dc:creator>joele</dc:creator>
      <dc:date>2018-03-01T15:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/139554#M25465</link>
      <description>&lt;P&gt;To close this one out -&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I spun up a new 9.1 simulator, upgraded it to 9.3, and was able to run the previous command set without any issues or collisions.&amp;nbsp;&amp;nbsp;I'm adding it to an OCUM 7.3 instance now to see how things look.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 16:00:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/139554#M25465</guid>
      <dc:creator>joele</dc:creator>
      <dc:date>2018-04-12T16:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/141658#M25873</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I followed your instructions and created on ontap 9.1P9 the ocum_readonly with your readonly role.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The OCUM 9.4 doesn't add the new cluster with following error message:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"Mon Jul 23 13:15:26 2018&amp;nbsp; scxxxxx&amp;nbsp; [kern_audit:info:1865] 8503e8000082515d :: scxxxxx:ontapi :: 10.xxx.xxx.xx:42836 :: scxxxxx:ocum_readonly :: Insufficient privileges: user 'ocum_readonly' does not have write access to this resource :: ONTAPI :: Error"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to have detailed readonly role for ontapi requests?&lt;BR /&gt;&lt;BR /&gt;thx bjoern&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 13:30:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/141658#M25873</guid>
      <dc:creator>bjoern_shd</dc:creator>
      <dc:date>2018-07-23T13:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: howto create separate, least priveledged role for OCUM Service Account user ?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/141660#M25874</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;bjoern,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I haven't tested this role with OCUM 9.4&amp;nbsp;yet unfortunately, but will take a look when I have some free time.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:12:20 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/how-to-create-separate-least-priveledged-role-for-OCUM-Service-Account-user/m-p/141660#M25874</guid>
      <dc:creator>joele</dc:creator>
      <dc:date>2018-07-23T15:12:20Z</dc:date>
    </item>
  </channel>
</rss>

