<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: capabilities for ONTAP WFA user account? in Active IQ Unified Manager Discussions</title>
    <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26222#M5480</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if using api-* would work for all kind of workflows it would at least disable logging in to the CLI with that user account&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Jan 2012 13:09:51 GMT</pubDate>
    <dc:creator>nscherer</dc:creator>
    <dc:date>2012-01-12T13:09:51Z</dc:date>
    <item>
      <title>capabilities for ONTAP WFA user account?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26209#M5474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does the ONTAP user account that WFA is using to connect to the filers need to be a member of the Administrators group?&lt;/P&gt;&lt;P&gt;Is it possible to use a role with a restricted set of capabilities?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nico&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:37:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26209#M5474</guid>
      <dc:creator>nscherer</dc:creator>
      <dc:date>2025-06-05T06:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: capabilities for ONTAP WFA user account?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26214#M5476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It will depend on which commands you are executing - you will need access to the underlying api's; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My advice would be to create an account wfaroot and place it either in an admin group or a group with api-* capabilities to be used as a service account and then use the WFA Auditing to audit who is running which workflows.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jan 2012 12:41:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26214#M5476</guid>
      <dc:creator>fenton</dc:creator>
      <dc:date>2012-01-12T12:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: capabilities for ONTAP WFA user account?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26217#M5478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rich is right.&amp;nbsp; The answer is "it depends".&amp;nbsp; It really depends on what you want the WFA workflows to do.&amp;nbsp; You can create an ONTAP user with limited capabilities.&amp;nbsp; However, some customers want to have workflows that perform administration tasks on the controllers like changing settings / options, updating /etc/rc, creation of aggregates and so on.&amp;nbsp; The easiest thing is to have a WFA user account as a member of the Administrator group, but it is not the only answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jan 2012 12:59:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26217#M5478</guid>
      <dc:creator>hill</dc:creator>
      <dc:date>2012-01-12T12:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: capabilities for ONTAP WFA user account?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26222#M5480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if using api-* would work for all kind of workflows it would at least disable logging in to the CLI with that user account&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jan 2012 13:09:51 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26222#M5480</guid>
      <dc:creator>nscherer</dc:creator>
      <dc:date>2012-01-12T13:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: capabilities for ONTAP WFA user account?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26227#M5482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes - it would also highlight any work that is being driven from WFA within ONTAP;&amp;nbsp; It would be nice for a workflow to identify which API's it will use so you could advise the minimum level of capabilities required - that would be one for Product Management/Engineering though&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jan 2012 13:14:41 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26227#M5482</guid>
      <dc:creator>fenton</dc:creator>
      <dc:date>2012-01-12T13:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: capabilities for ONTAP WFA user account?</title>
      <link>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26231#M5484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is an interesting question and I thought about providing some of my own feedback.&amp;nbsp; The question about RBAC to the controller comes up often and here are some of my answers:&lt;/P&gt;&lt;P&gt;Q) Should I use root as my WFA credentials for the Array?&lt;/P&gt;&lt;P&gt;A) It is always a good idea to use a different account for WFA Array Credentials.&amp;nbsp; The reason for this is to allow for controller auditing especially if a Syslog server is used on the Array and the audit logs are archived.&amp;nbsp; Though the Execution status is archived it is helpful to see from the Array audit logs which users are executing commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q) Should the WFA Credentials be restricted and if so what limitations?&lt;/P&gt;&lt;P&gt;A) Kevin gave a very good answer with 'it depends'.&amp;nbsp; Though this sounds very vague, it is true.&amp;nbsp; Limiting WFA Array credential capabilities is possible and as nscherer said using the 'api-*' option can add an extra level of security.&amp;nbsp; However, there are a few things to think about.&amp;nbsp; End users do not have access to the WFA Array Credentials.&amp;nbsp; Only Workflow Architects would be able to add new Storage Arrays and Operators will only be able to execute workflows.&amp;nbsp; This adds a different layer of security to WFA.&amp;nbsp; Because the operators can only do what the designers build, you can have a sense of security knowing that the NOC Team or whoever you have execute workflows (end customers) are restricted to only what you allow them to do.&amp;nbsp; Another important note is that future road map conversations would imply that there will be a new level of security.&amp;nbsp; The plan is to limit access to workflows based on user account and category.&amp;nbsp; This will be a huge benefit when considering role based provisioning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q) Determining which credentials are necessary?&lt;/P&gt;&lt;P&gt;A) There is no easy way to do this.&amp;nbsp; WFA Array Credentials are global to WFA not a specific workflow.&amp;nbsp; Limiting scope will be based on api's necessary for the Data ONTAP Powershell Toolkit and more importantly which commands will be leveraged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q) How are WFA Array Credentials stored?&lt;/P&gt;&lt;P&gt;A) The password entered in the Credentials section will be stored as an encrypted entry in the WFA Database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best option is to limit the users that can create workflows to those that are responsible for product development.&amp;nbsp; Create a new account on the controllers with a strong password scheme.&amp;nbsp; Limit the capabilities to api-* initially though bear in mind that you may find as you develop commands that you build wrappers to perform actual CLI calls.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just my two bits&lt;/P&gt;&lt;P&gt;-Jeremy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Jan 2012 15:09:43 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Active-IQ-Unified-Manager-Discussions/capabilities-for-ONTAP-WFA-user-account/m-p/26231#M5484</guid>
      <dc:creator>goodrum</dc:creator>
      <dc:date>2012-01-14T15:09:43Z</dc:date>
    </item>
  </channel>
</rss>

