<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Read only&amp;quot; cli- user in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23130#M4930</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This doc is a good start:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.netapp.com/us/library/technical-reports/tr-3358.html" target="_blank"&gt;http://www.netapp.com/us/library/technical-reports/tr-3358.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Dec 2008 13:21:18 GMT</pubDate>
    <dc:creator>donaldmann</dc:creator>
    <dc:date>2008-12-11T13:21:18Z</dc:date>
    <item>
      <title>"Read only" cli- user</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23126#M4928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to configure on our NetApp storage systems, an user which will be allowed to connect himself via ssh, and that will be only allowed any non-modifying commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I would like to allow him commands like those :&lt;/P&gt;&lt;P&gt;vol status &amp;lt;volname&amp;gt;&lt;/P&gt;&lt;P&gt;aggr status -r (or -s / -f)&lt;/P&gt;&lt;P&gt;rdfile &amp;lt;filepath&amp;gt;&lt;/P&gt;&lt;P&gt;snap list&lt;/P&gt;&lt;P&gt;lun show -m -g &amp;lt;igroup_name&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But not allow him commands like those :&lt;/P&gt;&lt;P&gt;vol size &amp;lt;volname&amp;gt; +Xg&lt;/P&gt;&lt;P&gt;aggr add &amp;lt;aggr_name&amp;gt; &amp;lt;ndisks&amp;gt; / aggr offline &amp;lt;aggr_name&amp;gt;&lt;/P&gt;&lt;P&gt;wrfile &amp;lt;filepath&amp;gt;&lt;/P&gt;&lt;P&gt;snap delete&lt;/P&gt;&lt;P&gt;lun offline &amp;lt;lunpath&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does someone knows if (or already have) such a role with corresponding capabilities exists ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not, where can I find an exhaustive list of all existing capabilities so that I can build such a role ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 07:32:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23126#M4928</guid>
      <dc:creator>xavierpitz</dc:creator>
      <dc:date>2025-06-05T07:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: "Read only" cli- user</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23130#M4930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This doc is a good start:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.netapp.com/us/library/technical-reports/tr-3358.html" target="_blank"&gt;http://www.netapp.com/us/library/technical-reports/tr-3358.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 13:21:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23130#M4930</guid>
      <dc:creator>donaldmann</dc:creator>
      <dc:date>2008-12-11T13:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: "Read only" cli- user</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23135#M4933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you mentioned, the "Role-Based Access Controls in Data ONTAP™: Granular Administration of Capabilities" doc is a great one.&lt;/P&gt;&lt;P&gt;It explains (with examples) how to implement RBAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the end of the document (page 9), there's a list of all cli- capabilities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem it that this document is now 4+ years old.&lt;/P&gt;&lt;P&gt;I'm sure that, since then, new capabilities have been implemented in DOT.&lt;/P&gt;&lt;P&gt;I was not able to find any up-to-date list of implemented capabilities for DOT 7.2.4 7.2.5 7.2.6 or 7.3.&lt;/P&gt;&lt;P&gt;I would be really interested in a per release exhaustive list of implemented capabilities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Moreover with such year-2004 capabilities, when for example the cli-aggr-* is granted to a role users with this one assigned he will not only be able to perform "aggr status -r/-s/-f" but also aggr offline/destroy commands.&lt;/P&gt;&lt;P&gt;I want to be more granular than that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that this is possible with the new capabilities that were probably introduced in DOT since then.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will be really great if someone already implemented such a role that is limited to "read-only" cli- capabilities. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 14:12:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23135#M4933</guid>
      <dc:creator>xavierpitz</dc:creator>
      <dc:date>2008-12-11T14:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: "Read only" cli- user</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23139#M4935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OnTap sysadmin guide seems to be a good place to start for any changes to this capability. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm looking in the 7.3 sysadmin guide &lt;A href="http://now.netapp.com/NOW/knowledge/docs/ontap/rel73/pdfs/ontap/sysadmin.pdf" target="_blank"&gt;http://now.netapp.com/NOW/knowledge/docs/ontap/rel73/pdfs/ontap/sysadmin.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a filerview-readonly option - GUI only of course.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On page 109:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P align="left"&gt;Grants the specified role read-only access to FilerView.&lt;/P&gt;&lt;P align="left"&gt;This capability type includes only the&lt;/P&gt;&lt;P align="left"&gt;filerview-readonly capability, which grants the&lt;/P&gt;&lt;P align="left"&gt;specified role the capability to view but not change&lt;/P&gt;&lt;P align="left"&gt;manageable objects on systems managed by FilerView.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P align="left"&gt;Note:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P align="left"&gt;There is no predefined role or group for read-only&lt;/P&gt;&lt;P align="left"&gt;FilerView access. You must first assign the&lt;/P&gt;&lt;P align="left"&gt;filerview-readonly capability to a role and&lt;/P&gt;&lt;P align="left"&gt;then assign the role to a group, before you can create&lt;/P&gt;&lt;P&gt;a user in such a group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 14:30:45 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23139#M4935</guid>
      <dc:creator>donaldmann</dc:creator>
      <dc:date>2008-12-11T14:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: "Read only" cli- user</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23144#M4938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A colleague already informed me about this filerview-readonly capability that was introduced in DOT 7.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At page 107 from the "Data ONTAP® 7.3 System Administration Guide", there is a &lt;U&gt;short list&lt;/U&gt; of capabilities present in DOT 7.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody knows if I can find an &lt;U&gt;exhaustive per-release capability list&lt;/U&gt; ?&lt;/P&gt;&lt;P&gt;Some of our systems are still running DOT 7.2, and anyway my goal is to defile a read only role for cli- commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will be great if I can add a bunch of cli- capabilities into a role so that it would behave like the filerview-readonly role, but on the cli side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already tried with cli-readonly, also on DOT 7.3, but there's no such a capability yet defined.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be granular I need to know all capabilities that exists, I really searched for this, and I was not able to find such a list yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 15:11:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23144#M4938</guid>
      <dc:creator>xavierpitz</dc:creator>
      <dc:date>2008-12-11T15:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: "Read only" cli- user</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23149#M4940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would be nice to find that exhaustive list that you are requesting.&amp;nbsp; Funny that no one from NetApp seems to have one.&amp;nbsp; Seems to be the case on a few matters that have come up.&amp;nbsp; Like things are only partially thought through.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 17:04:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23149#M4940</guid>
      <dc:creator>ASUNDSTROM</dc:creator>
      <dc:date>2012-03-01T17:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: "Read only" cli- user</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23155#M4941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can check the capabilities of a NetApp via API (or just via the ZExplore tool).&lt;/P&gt;&lt;P&gt;The API call to consider would be: system -&amp;gt; system-api-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the XML output, see attachment, you could grep for "&amp;lt;name&amp;gt;" and then for things like "read" and "list"... those should be your "safe APIs" &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon jive_emote" height="1" src="https://community.netapp.com/5.0.1/images/emoticons/wink.gif" width="1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have fun&lt;/P&gt;&lt;P&gt; Anton&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2012 10:14:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23155#M4941</guid>
      <dc:creator>anton_oks</dc:creator>
      <dc:date>2012-03-02T10:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: "Read only" cli- user</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23160#M4942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where can I find info for 8.x?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 12:29:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/quot-Read-only-quot-cli-user/m-p/23160#M4942</guid>
      <dc:creator>D_BEREZENKO</dc:creator>
      <dc:date>2014-08-13T12:29:01Z</dc:date>
    </item>
  </channel>
</rss>

