<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inconsistent Behavior AD Authenticated vServer and Domain Tunnel in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Inconsistent-Behavior-AD-Authenticated-vServer-and-Domain-Tunnel/m-p/152367#M27357</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's a few commands here to clear the different caches.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1002483/loc/en_US" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1002483/loc/en_US&lt;/A&gt; -&amp;nbsp; What is the command to expire credential cache in clustered Data ONTAP 8.2.1?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Nov 2019 14:44:28 GMT</pubDate>
    <dc:creator>GidonMarcus</dc:creator>
    <dc:date>2019-11-18T14:44:28Z</dc:date>
    <item>
      <title>Inconsistent Behavior AD Authenticated vServer and Domain Tunnel</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Inconsistent-Behavior-AD-Authenticated-vServer-and-Domain-Tunnel/m-p/152275#M27339</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're using a vServer that's authenticated to our domain controller with AD integration. We create a domain tunnel and then give users in a specified group login rights to the cluster.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're seeing that when we remove a user from the same group that was given cluster login rights (while forcing replication on domain controller), the user is still able to login for about 20 minutes afterward.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we disable the account the intended effect is immediate. The user cannot login.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, if we remove the user from the group, disable the account, the user will not be able to login. But as soon as it is re-enabled they can login.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Every command I've tried for clearing kerberos cache or otherwise doesn't affect the results. Anyone have advice on a command that works to do this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, I want to point out that I have verified that the forced AD replication is occuring immediately on the secondary domain controllers. So I believe this to be&amp;nbsp; a problem on the NetApp side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 12:08:45 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Inconsistent-Behavior-AD-Authenticated-vServer-and-Domain-Tunnel/m-p/152275#M27339</guid>
      <dc:creator>StorageNob</dc:creator>
      <dc:date>2025-06-04T12:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent Behavior AD Authenticated vServer and Domain Tunnel</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Inconsistent-Behavior-AD-Authenticated-vServer-and-Domain-Tunnel/m-p/152367#M27357</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's a few commands here to clear the different caches.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1002483/loc/en_US" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1002483/loc/en_US&lt;/A&gt; -&amp;nbsp; What is the command to expire credential cache in clustered Data ONTAP 8.2.1?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 14:44:28 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Inconsistent-Behavior-AD-Authenticated-vServer-and-Domain-Tunnel/m-p/152367#M27357</guid>
      <dc:creator>GidonMarcus</dc:creator>
      <dc:date>2019-11-18T14:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent Behavior AD Authenticated vServer and Domain Tunnel</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Inconsistent-Behavior-AD-Authenticated-vServer-and-Domain-Tunnel/m-p/152449#M27370</link>
      <description>&lt;P&gt;Thanks for that, unfortunately none of those commands worked. Users removed from a security group could still log in for upt o 20 minutes on our NetApp systems.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a ticket open with support but I wasn't really getting the answers I was looking for so I came here. So far removing the security group entirely from the vsadmin role and then re-adding it back in is all I can get working. But that seems to defy the point.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;security login delete -vserver &amp;lt;cluster&amp;gt; -user-or-group-name "&amp;lt;domain&amp;gt;\&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3e3e3e; cursor: text; font-family: 'Source Sans Pro','Lato','Helvetica Neue','Helvetica','Arial','sans-serif'; font-size: 16px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 27.42px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;securitygroupname&lt;/SPAN&gt;" -application ssh -authentication-method domain&lt;BR /&gt;security login delete -vserver &amp;lt;cluster&amp;gt; -user-or-group-name "&amp;lt;domain&amp;gt;\&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3e3e3e; cursor: text; font-family: 'Source Sans Pro','Lato','Helvetica Neue','Helvetica','Arial','sans-serif'; font-size: 16px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 27.42px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;securitygroupname&lt;/SPAN&gt;" -application http -authentication-method domain&lt;BR /&gt;security login delete -vserver &amp;lt;cluster&amp;gt; -user-or-group-name "&amp;lt;domain&amp;gt;\&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3e3e3e; cursor: text; font-family: 'Source Sans Pro','Lato','Helvetica Neue','Helvetica','Arial','sans-serif'; font-size: 16px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 27.42px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;securitygroupname&lt;/SPAN&gt;" -application ontapi -authentication-method domain&lt;BR /&gt;security login create -vserver &amp;lt;cluster&amp;gt; -user-or-group-name "&amp;lt;domain&amp;gt;\&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3e3e3e; cursor: text; font-family: 'Source Sans Pro','Lato','Helvetica Neue','Helvetica','Arial','sans-serif'; font-size: 16px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 27.42px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;securitygroupname&lt;/SPAN&gt;" -application ssh -authentication-method domain&lt;BR /&gt;security login create -vserver &amp;lt;cluster&amp;gt; -user-or-group-name "&amp;lt;domain&amp;gt;\&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3e3e3e; cursor: text; font-family: 'Source Sans Pro','Lato','Helvetica Neue','Helvetica','Arial','sans-serif'; font-size: 16px; font-style: normal; font-variant: normal; font-weight: 300; letter-spacing: normal; line-height: 27.42px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;securitygroupname&lt;/SPAN&gt;" -application http -authentication-method domain&lt;BR /&gt;security login create -vserver &amp;lt;cluster&amp;gt; -user-or-group-name "&amp;lt;domain&amp;gt;\securitygroupname" -application ontapi -authentication-method domain&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think that's overkill though.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 12:10:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/Inconsistent-Behavior-AD-Authenticated-vServer-and-Domain-Tunnel/m-p/152449#M27370</guid>
      <dc:creator>StorageNob</dc:creator>
      <dc:date>2019-11-20T12:10:18Z</dc:date>
    </item>
  </channel>
</rss>

