<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting 13003:Insufficient privileges after more than a year running with no issues in OpenStack Discussions</title>
    <link>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112704#M265</link>
    <description>&lt;P&gt;Ruben,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think we need to clarify that there are different environments involved in this thread.&amp;nbsp; On the storage side, the NetApp cluster "rac51" provides the back end storage to your production OpenStack environment, where the NetApp cluster c02 provides storage to your test environment.&amp;nbsp; On the nodes of cluster c02, we observed a clear indication of an issue with permission to a specific API call:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;0000004c.001e2477 02290ef2 Mon Nov 02 2015 14:33:17  01:00 [kern_command-history:info:934] ontapi :: 128.142.140.42 :: ois_admin :: &amp;lt;netapp xmlns="&lt;A href="http://www.netapp.com/filer/admin" target="_blank"&gt;http://www.netapp.com/filer/admin&lt;/A&gt;" version="1.31" vfiler="vsiscsi"&amp;gt;&amp;lt;lun-map&amp;gt;&amp;lt;path&amp;gt;/vol/openstack_vol01/volume-49196581-99df-4351-b689-9351af0a4f4f&amp;lt;/path&amp;gt;&amp;lt;initiator-group&amp;gt;openstack-bd 18dce0-0922-4269-8a74-2520a902a8c5&amp;lt;/initiator-group&amp;gt;&amp;lt;/lun-map&amp;gt;&amp;lt;/netapp&amp;gt; :: Pending&lt;BR /&gt;0000004c.001e2479 02290ef2 Mon Nov 02 2015 14:33:17  01:00 [kern_command-history:info:934] ontapi :: 128.142.140.42 :: ois_admin :: Insufficient privileges: user 'ois_admin' does not have write access to this resource :: ONTAPI :: Error&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;In this case the call to "lun map" results in "Insufficient privileges".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the "rac51" cluster, we observe an entirely different error returned for the "lun map" API call:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;00000009.00c2f308 11a76240 Mon Nov 02 2015 09:34:31  01:00 [kern_command-history:info:1040] ontapi :: 188.184.64.171 :: cinder_admin :: &amp;lt;netapp xmlns="&lt;A href="http://www.netapp.com/filer/admin" target="_blank"&gt;http://www.netapp.com/filer/admin&lt;/A&gt;" version="1.21" vfiler="vs2rac51"&amp;gt;&amp;lt;lun-map&amp;gt;&amp;lt;path&amp;gt;/vol/cinder01/volume-388e4dd6-0fc4-4876-a305-3b1b57e9dcb1&amp;lt;/path&amp;gt;&amp;lt;initiator-group&amp;gt;openstack-3b99cdc9 -888c-4074-a47f-bfa17886f810&amp;lt;/initiator-group&amp;gt;&amp;lt;/lun-map&amp;gt;&amp;lt;/netapp&amp;gt; :: Pending &lt;BR /&gt;00000009.00c2f30f 11a76240 Mon Nov 02 2015 09:34:31 01:00 [kern_command-history:info:1040] ontapi :: 188.184.64.171 :: cinder_admin :: LUN already mapped to this group :: ONTAPI :: Error&lt;/PRE&gt;&lt;P&gt;Here, we see the error "LUN already mapped to this group" being returned from the "lun map" API call.&amp;nbsp; We don't see any indication in the logs from the production storage cluster of a permission issue to the API calls being made from OpenStack.&amp;nbsp; The error "LUN already mapped" began to appear in the logs of the "rac51" cluster on September 30th.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two different issues here, both of which impact the "lun map" API calls.&amp;nbsp; We need to treat these two issues separately in our troubleshooting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Nov 2015 18:31:31 GMT</pubDate>
    <dc:creator>DougCarman</dc:creator>
    <dc:date>2015-11-18T18:31:31Z</dc:date>
    <item>
      <title>Getting 13003:Insufficient privileges after more than a year running with no issues</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112094#M257</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to debug this situation: our openstack people deployed kilo a while ago. Since apparently last Friday that they noticed that after resizing a lun they couldnt mount/attach it back to same VM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In production I am running kilo on a clustered ONTAP 8.2.2P1, we get this error while trying to reattach:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2015-11-02 09:34:36.493 21340 ERROR oslo_messaging._drivers.common [req-62d7c63f-efea-4417-893f-b81c7cc5c8cd bukowiec 4d679467-f828-41bc-90fa-ef8633594a6f - - -] Returning exception Bad or unexpected response from the storage volume backend API: Unable to fetch connection information from backend: NetApp API failed. Reason - 13003:Insufficient privileges: user 'cinder_admin' does not have read access to this resource to caller&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cinder_admin have following privilages as per doc:&lt;A href="http://netapp.github.io/openstack-deploy-ops-guide/kilo/openstack-deployment-ops-guide.pdf&amp;nbsp;" target="_blank"&gt;http://netapp.github.io/openstack-deploy-ops-guide/kilo/openstack-deployment-ops-guide.pdf&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;rac51::*&amp;gt; security login role show -vserver rac51 -role cinder_cluster&lt;BR /&gt;Role Command/ Access&lt;BR /&gt;Vserver Name Directory Query Level&lt;BR /&gt;---------- ------------- --------- ----------------------------------- --------&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;DEFAULT none&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;event all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun readonly&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun create all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun delete all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun igroup readonly&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun igroup add all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun igroup create all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun igroup modify all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun igroup show all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun map all&lt;/P&gt;&lt;P&gt;Role Command/ Access&lt;BR /&gt;Vserver Name Directory Query Level&lt;BR /&gt;---------- ------------- --------- ----------------------------------- --------&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun mapped readonly&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun modify all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun resize all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun show all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;lun unmap all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;security readonly&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;snapmirror readonly&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;storage aggregate readonly&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;storage disk readonly&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;version all&lt;/P&gt;&lt;P&gt;Role Command/ Access&lt;BR /&gt;Vserver Name Directory Query Level&lt;BR /&gt;---------- ------------- --------- ----------------------------------- --------&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;volume readonly&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;volume efficiency readonly&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;volume file clone create all&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;vserver readonly&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;vserver iscsi readonly&lt;BR /&gt;rac51 cinder_cluster&lt;BR /&gt;vserver iscsi interface readonly&lt;BR /&gt;27 entries were displayed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for the formating.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of my colleagues has done a test setup of openstack and I have done the same on a test ONTAP cluster, this one running ONTAP 8.3.1.&amp;nbsp;I get similar errors:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2015-11-02 16:53:56.222 17313 WARNING cinder.volume.drivers.netapp.dataontap.client.client_base [req-eec18ed9-147e-4a8d-8943-9ad895f69497 9ad073f097c347509aee2414c0021f27 81b42e48d34446da9688d691078cbcd6 - - -] Error mapping LUN. Code :13003, Message:Insufficient privileges: user 'ois_admin' does not have write access to this resource&lt;BR /&gt;2015-11-02 16:53:56.459 17313 ERROR cinder.volume.manager [req-eec18ed9-147e-4a8d-8943-9ad895f69497 9ad073f097c347509aee2414c0021f27 81b42e48d34446da9688d691078cbcd6 - - -] Unable to fetch connection information from backend: NetApp API failed. Reason - 13003:Insufficient privileges: user 'ois_admin' does not have write access to this resource&lt;BR /&gt;2015-11-02 16:53:56.461 17313 ERROR oslo_messaging.rpc.dispatcher [req-eec18ed9-147e-4a8d-8943-9ad895f69497 9ad073f097c347509aee2414c0021f27 81b42e48d34446da9688d691078cbcd6 - - -] Exception during message handling: Bad or unexpected response from the storage volume backend API: Unable to fetch connection information from backend: NetApp API failed. Reason - 13003:Insufficient privileges: user 'ois_admin' does not have write access to this resource&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again while trying to attach the volume to a vm:&lt;/P&gt;&lt;P&gt;[root@ps-kilo-temp cinder(keystone_admin)]# nova volume-attach c5db89c5-7dbf-4d39-88ff-59cc16a85c57 49196581-99df-4351-b689-9351af0a4f4f auto&lt;BR /&gt;+----------+--------------------------------------+&lt;BR /&gt;| Property | Value |&lt;BR /&gt;+----------+--------------------------------------+&lt;BR /&gt;| device | /dev/vdb |&lt;BR /&gt;| id | 49196581-99df-4351-b689-9351af0a4f4f |&lt;BR /&gt;| serverId | c5db89c5-7dbf-4d39-88ff-59cc16a85c57 |&lt;BR /&gt;| volumeId | 49196581-99df-4351-b689-9351af0a4f4f |&lt;BR /&gt;+----------+--------------------------------------+&lt;BR /&gt;[root@ps-kilo-temp cinder(keystone_admin)]# cinder list&lt;BR /&gt;+--------------------------------------+----------------+--------------+------+-------------+----------+-------------+&lt;BR /&gt;| ID | Status | Display Name | Size | Volume Type | Bootable | Attached to |&lt;BR /&gt;+--------------------------------------+----------------+--------------+------+-------------+----------+-------------+&lt;BR /&gt;| 1f4464d2-f954-4874-93c7-90622dd7ba0a | available | cephv01 | 1 | ceph | false | |&lt;BR /&gt;| 400b4ea6-08f2-427a-88b6-221d638a8902 | available | testvol01 | 1 | netapp | false | |&lt;BR /&gt;| 49196581-99df-4351-b689-9351af0a4f4f | available | testvol04 | 1 | netapp | false | |&lt;BR /&gt;| 63b1b607-7f40-4b5f-b9b5-c2768d93e1a7 | deleting | testvol03 | 2 | netapp | false | |&lt;BR /&gt;| f8cfc64c-a9c9-4588-b1d3-0ed69fa41c74 | error_deleting | testvol02 | 2 | netapp | false | |&lt;BR /&gt;+--------------------------------------+----------------+--------------+------+-------------+----------+-------------+&lt;BR /&gt;[root@ps-kilo-temp cinder(keystone_admin)]# nova volume-attach c5db89c5-7dbf-4d39-88ff-59cc16a85c57 49196581-99df-4351-b689-9351af0a4f4f auto&lt;BR /&gt;+----------+--------------------------------------+&lt;BR /&gt;| Property | Value |&lt;BR /&gt;+----------+--------------------------------------+&lt;BR /&gt;| device | /dev/vdb |&lt;BR /&gt;| id | 49196581-99df-4351-b689-9351af0a4f4f |&lt;BR /&gt;| serverId | c5db89c5-7dbf-4d39-88ff-59cc16a85c57 |&lt;BR /&gt;| volumeId | 49196581-99df-4351-b689-9351af0a4f4f |&lt;BR /&gt;+----------+--------------------------------------+&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The security is as per doc again:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;c02::*&amp;gt; security login role show -vserver c02 -role openstach&lt;BR /&gt;Role Command/ Access&lt;BR /&gt;Vserver Name Directory Query Level&lt;BR /&gt;---------- ------------- --------- ----------------------------------- --------&lt;BR /&gt;c02 openstach DEFAULT none&lt;BR /&gt;c02 openstach event all&lt;BR /&gt;c02 openstach lun readonly&lt;BR /&gt;c02 openstach lun create all&lt;BR /&gt;c02 openstach lun delete all&lt;BR /&gt;c02 openstach lun igroup readonly&lt;BR /&gt;c02 openstach lun igroup add all&lt;BR /&gt;c02 openstach lun igroup create all&lt;BR /&gt;c02 openstach lun igroup modify all&lt;BR /&gt;c02 openstach lun igroup show all&lt;BR /&gt;c02 openstach lun map all&lt;BR /&gt;c02 openstach lun mapped readonly&lt;BR /&gt;c02 openstach lun modify all&lt;BR /&gt;c02 openstach lun resize all&lt;BR /&gt;c02 openstach lun show all&lt;BR /&gt;c02 openstach lun unmap all&lt;BR /&gt;c02 openstach security readonly&lt;BR /&gt;c02 openstach snapmirror readonly&lt;BR /&gt;c02 openstach storage aggregate readonly&lt;BR /&gt;c02 openstach storage disk readonly&lt;BR /&gt;c02 openstach version all&lt;BR /&gt;c02 openstach volume readonly&lt;BR /&gt;c02 openstach volume efficiency readonly&lt;BR /&gt;c02 openstach volume file clone create all&lt;BR /&gt;c02 openstach vserver readonly&lt;BR /&gt;c02 openstach vserver iscsi readonly&lt;BR /&gt;c02 openstach vserver iscsi interface readonly&lt;BR /&gt;27 entries were displayed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you let me know what do you think, which permissions I am missing. Still astonished this started to fail now, this operations has been done plenty of times in the past.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;THank you&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 22:54:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112094#M257</guid>
      <dc:creator>gasparuben</dc:creator>
      <dc:date>2025-06-04T22:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: Getting 13003:Insufficient privileges after more than a year running with no issues</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112133#M258</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to add more information.&lt;BR /&gt;Both ois_admin and cinder_admin are cluster accounts like:&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;security login create -username cinder_admin -application ontapi -authmethod password -role cinder_cluster&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;This as defined in the documentation:&amp;nbsp;&lt;A href="http://netapp.github.io/openstack-deploy-ops-guide/kilo/openstack-deployment-ops-guide.pdf&amp;nbsp;" target="_blank"&gt;http://netapp.github.io/openstack-deploy-ops-guide/kilo/openstack-deployment-ops-guide.pdf&amp;nbsp;&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please let us know if you need further evidence.&lt;BR /&gt;Thank you&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2015 13:09:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112133#M258</guid>
      <dc:creator>gasparuben</dc:creator>
      <dc:date>2015-11-03T13:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: Getting 13003:Insufficient privileges after more than a year running with no issues</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112154#M259</link>
      <description>&lt;P&gt;Further analysis of my colleages in Openstack has found that the call that is not working is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;'&amp;lt;netapp xmlns="&lt;A href="http://www.netapp.com/filer/admin" target="_blank"&gt;http://www.netapp.com/filer/admin&lt;/A&gt;" version="1.31" vfiler="vsiscsi"&amp;gt;&amp;lt;lun-map&amp;gt;&amp;lt;path&amp;gt;/vol/openstack_vol01/volume-babd5700-2ebb-48c6-ae27-667ba167b209&amp;lt;/path&amp;gt;&amp;lt;initiator-group&amp;gt;openstack-573d9b2b-ae32-457f-8227-119707531793&amp;lt;/initiator-group&amp;gt;&amp;lt;/lun-map&amp;gt;&amp;lt;/netapp&amp;gt;'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The response that we get is: NetApp API failed. Reason - 13003:Insufficient privileges .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you advice. As you can see above the account should have that privilege by means of a role.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 11:10:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112154#M259</guid>
      <dc:creator>gasparuben</dc:creator>
      <dc:date>2015-11-04T11:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Getting 13003:Insufficient privileges after more than a year running with no issues</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112166#M261</link>
      <description>&lt;P&gt;Can you try the following to see if it makes a difference?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;c02::*&amp;gt; security login role modify -role openstach -vserver c02 -cmddirname "lun mapped" -access all&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would probably be best to open a support case via&amp;nbsp;&lt;A href="http://mysupport.netapp.com" target="_blank"&gt;http://mysupport.netapp.com&lt;/A&gt;&amp;nbsp;to ensure that this is driven in a timely manner, should the above command not help. &amp;nbsp;I cannot explain why this worked for so long and then suddenly stopped.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 17:21:34 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112166#M261</guid>
      <dc:creator>dcain</dc:creator>
      <dc:date>2015-11-04T17:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: Getting 13003:Insufficient privileges after more than a year running with no issues</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112212#M262</link>
      <description>&lt;P&gt;Thanks for your reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still get the same error. I opened in the past a case on mysupport and I was redirected to the NetApp community. I can always try for sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you need further evidencies please let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have open case&amp;nbsp;&lt;SPAN&gt;2005973370.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 10:43:38 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112212#M262</guid>
      <dc:creator>gasparuben</dc:creator>
      <dc:date>2015-11-05T10:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Getting 13003:Insufficient privileges after more than a year running with no issues</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112287#M263</link>
      <description>&lt;P&gt;Hi Ruben&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have no real openstack knowhow, but the call looks like a 7-Mode call to me and you are saying you run on cDOT. Anything you can change there?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;netapp xmlns="&lt;A href="http://www.netapp.com/filer/admin" target="_blank" rel="nofollow"&gt;http://www.netapp.com/filer/admin&lt;/A&gt;" version="1.31" &lt;FONT color="#FF0000"&gt;vfiler=&lt;/FONT&gt;"vsiscsi"&amp;gt;&amp;lt;lun-map&amp;gt;&amp;lt;path&amp;gt;/vol/openstack_vol01/volume-babd5700-2ebb-48c6-ae27-667ba167b209&amp;lt;/path&amp;gt;&amp;lt;initiator-group&amp;gt;openstack-573d9b2b-ae32-457f-8227-119707531793&amp;lt;/initiator-group&amp;gt;&amp;lt;/lun-map&amp;gt;&amp;lt;/netapp&amp;gt;'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The response that we get is: NetApp API failed. Reason - 13003:Insufficient privileges .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Christoph&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 13:18:17 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112287#M263</guid>
      <dc:creator>cschnidr</dc:creator>
      <dc:date>2015-11-06T13:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Getting 13003:Insufficient privileges after more than a year running with no issues</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112289#M264</link>
      <description>&lt;P&gt;Just checking but it looks like the cinder.conf is good:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2896 [netapp02]&lt;BR /&gt;2897 volume_backend_name=netapp&lt;BR /&gt;2898 volume_driver=cinder.volume.drivers.netapp.common.NetAppDriver&lt;BR /&gt;2899 netapp_server_hostname=10.X.X.X&lt;BR /&gt;2900 netapp_server_port=443&lt;BR /&gt;2901 netapp_storage_protocol=iscsi&lt;BR /&gt;2902 netapp_storage_family=ontap_cluster&lt;BR /&gt;2903 netapp_login=vsadmin&lt;BR /&gt;2904 netapp_password=XXXXXX&lt;BR /&gt;2905 netapp_vserver=vsiscsi&lt;BR /&gt;2906 netapp_size_multiplier=1.0&lt;BR /&gt;2907 reserved_percentage=5&lt;BR /&gt;2908 #use_multipath_for_image_xfer=True&lt;BR /&gt;2909 netapp_transport_type=https&lt;BR /&gt;2910 nfs_shares_config=/etc/cinder/shares.conf&lt;BR /&gt;2911 netapp_eseries_host_type=linux_dm_mp&lt;BR /&gt;2912 netapp_storage_pools=&lt;BR /&gt;2913 expiry_thres_minutes=720&lt;BR /&gt;2914 netapp_vfiler=&lt;BR /&gt;2915 thres_avl_size_perc_stop=60&lt;BR /&gt;2916 netapp_copyoffload_tool_path=&lt;BR /&gt;2917 thres_avl_size_perc_start=20&lt;BR /&gt;2918 netapp_controller_ips=&lt;BR /&gt;2919 netapp_volume_list=&lt;BR /&gt;2920 netapp_webservice_path=/devmgr/v2&lt;BR /&gt;2921 netapp_partner_backend_name=&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried (together with my Openstack colleague) with a vsadmin account and a cluster account with full rights account. With both it worked. It still doesnt work with a cluster account with svm scope as per documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's clearly a permission issue.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Ruben&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 14:37:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112289#M264</guid>
      <dc:creator>gasparuben</dc:creator>
      <dc:date>2015-11-06T14:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Getting 13003:Insufficient privileges after more than a year running with no issues</title>
      <link>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112704#M265</link>
      <description>&lt;P&gt;Ruben,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think we need to clarify that there are different environments involved in this thread.&amp;nbsp; On the storage side, the NetApp cluster "rac51" provides the back end storage to your production OpenStack environment, where the NetApp cluster c02 provides storage to your test environment.&amp;nbsp; On the nodes of cluster c02, we observed a clear indication of an issue with permission to a specific API call:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;0000004c.001e2477 02290ef2 Mon Nov 02 2015 14:33:17  01:00 [kern_command-history:info:934] ontapi :: 128.142.140.42 :: ois_admin :: &amp;lt;netapp xmlns="&lt;A href="http://www.netapp.com/filer/admin" target="_blank"&gt;http://www.netapp.com/filer/admin&lt;/A&gt;" version="1.31" vfiler="vsiscsi"&amp;gt;&amp;lt;lun-map&amp;gt;&amp;lt;path&amp;gt;/vol/openstack_vol01/volume-49196581-99df-4351-b689-9351af0a4f4f&amp;lt;/path&amp;gt;&amp;lt;initiator-group&amp;gt;openstack-bd 18dce0-0922-4269-8a74-2520a902a8c5&amp;lt;/initiator-group&amp;gt;&amp;lt;/lun-map&amp;gt;&amp;lt;/netapp&amp;gt; :: Pending&lt;BR /&gt;0000004c.001e2479 02290ef2 Mon Nov 02 2015 14:33:17  01:00 [kern_command-history:info:934] ontapi :: 128.142.140.42 :: ois_admin :: Insufficient privileges: user 'ois_admin' does not have write access to this resource :: ONTAPI :: Error&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;In this case the call to "lun map" results in "Insufficient privileges".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the "rac51" cluster, we observe an entirely different error returned for the "lun map" API call:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;00000009.00c2f308 11a76240 Mon Nov 02 2015 09:34:31  01:00 [kern_command-history:info:1040] ontapi :: 188.184.64.171 :: cinder_admin :: &amp;lt;netapp xmlns="&lt;A href="http://www.netapp.com/filer/admin" target="_blank"&gt;http://www.netapp.com/filer/admin&lt;/A&gt;" version="1.21" vfiler="vs2rac51"&amp;gt;&amp;lt;lun-map&amp;gt;&amp;lt;path&amp;gt;/vol/cinder01/volume-388e4dd6-0fc4-4876-a305-3b1b57e9dcb1&amp;lt;/path&amp;gt;&amp;lt;initiator-group&amp;gt;openstack-3b99cdc9 -888c-4074-a47f-bfa17886f810&amp;lt;/initiator-group&amp;gt;&amp;lt;/lun-map&amp;gt;&amp;lt;/netapp&amp;gt; :: Pending &lt;BR /&gt;00000009.00c2f30f 11a76240 Mon Nov 02 2015 09:34:31 01:00 [kern_command-history:info:1040] ontapi :: 188.184.64.171 :: cinder_admin :: LUN already mapped to this group :: ONTAPI :: Error&lt;/PRE&gt;&lt;P&gt;Here, we see the error "LUN already mapped to this group" being returned from the "lun map" API call.&amp;nbsp; We don't see any indication in the logs from the production storage cluster of a permission issue to the API calls being made from OpenStack.&amp;nbsp; The error "LUN already mapped" began to appear in the logs of the "rac51" cluster on September 30th.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two different issues here, both of which impact the "lun map" API calls.&amp;nbsp; We need to treat these two issues separately in our troubleshooting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 18:31:31 GMT</pubDate>
      <guid>https://community.netapp.com/t5/OpenStack-Discussions/Getting-13003-Insufficient-privileges-after-more-than-a-year-running-with-no/m-p/112704#M265</guid>
      <dc:creator>DougCarman</dc:creator>
      <dc:date>2015-11-18T18:31:31Z</dc:date>
    </item>
  </channel>
</rss>

