<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic read only account in Software Development Kit (SDK) and API Discussions</title>
    <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34637#M301</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See this for more info on that capability&lt;/P&gt;&lt;P&gt;&lt;A href="http://hd.kvsconsulting.us/netappdoc/733docs/html/ontap/rnote/rel_notes/concept/c_oc_rn_feat73-admin-filerview-readonly-capability.html" title="http://hd.kvsconsulting.us/netappdoc/733docs/html/ontap/rnote/rel_notes/concept/c_oc_rn_feat73-admin-filerview-readonly-capability.html" target="_blank"&gt;http://hd.kvsconsulting.us/netappdoc/733docs/html/ontap/rnote/rel_notes/concept/c_oc_rn_feat73-admin-filerview-readonly-capability.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont think it's impossible, it's just a matter of knowing what capabilities you need to give granularity to a role.&lt;/P&gt;&lt;P&gt;I think you need to determine what you need from this account and what are you trying to do exactly.&lt;/P&gt;&lt;P&gt;What does your API script do?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Jan 2014 22:16:11 GMT</pubDate>
    <dc:creator>DANIELCM6</dc:creator>
    <dc:date>2014-01-23T22:16:11Z</dc:date>
    <item>
      <title>read only account</title>
      <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34624#M298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is ontap 8.1.17 7 mode able to create a read-only account, so a API scirpt can safely run? If so, how? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jan 2014 21:58:54 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34624#M298</guid>
      <dc:creator>HAIT_NETAPP</dc:creator>
      <dc:date>2014-01-22T21:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: read only account</title>
      <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34628#M299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look at this link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://library.netapp.com/ecmdocs/ECMP1196890/html/man1/na_useradmin.1.html" title="https://library.netapp.com/ecmdocs/ECMP1196890/html/man1/na_useradmin.1.html" target="_blank"&gt;https://library.netapp.com/ecmdocs/ECMP1196890/html/man1/na_useradmin.1.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use useradmin to control user access.&amp;nbsp; You can probably create an account with certain capabilities and fine tune it to your use.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 21:18:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34628#M299</guid>
      <dc:creator>DANIELCM6</dc:creator>
      <dc:date>2014-01-23T21:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: read only account</title>
      <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34633#M300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have to laugh at NetApp. they make creating a read only account mission impossible. If anyone disagrees, please provide your complete commands to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===========================&lt;/P&gt;&lt;P&gt;A sixth capability, filerview-readonly, is unused and ignored. - what does this mean? can this used or not?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 21:55:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34633#M300</guid>
      <dc:creator>HAIT_NETAPP</dc:creator>
      <dc:date>2014-01-23T21:55:01Z</dc:date>
    </item>
    <item>
      <title>read only account</title>
      <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34637#M301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See this for more info on that capability&lt;/P&gt;&lt;P&gt;&lt;A href="http://hd.kvsconsulting.us/netappdoc/733docs/html/ontap/rnote/rel_notes/concept/c_oc_rn_feat73-admin-filerview-readonly-capability.html" title="http://hd.kvsconsulting.us/netappdoc/733docs/html/ontap/rnote/rel_notes/concept/c_oc_rn_feat73-admin-filerview-readonly-capability.html" target="_blank"&gt;http://hd.kvsconsulting.us/netappdoc/733docs/html/ontap/rnote/rel_notes/concept/c_oc_rn_feat73-admin-filerview-readonly-capability.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont think it's impossible, it's just a matter of knowing what capabilities you need to give granularity to a role.&lt;/P&gt;&lt;P&gt;I think you need to determine what you need from this account and what are you trying to do exactly.&lt;/P&gt;&lt;P&gt;What does your API script do?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 22:16:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34637#M301</guid>
      <dc:creator>DANIELCM6</dc:creator>
      <dc:date>2014-01-23T22:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: read only account</title>
      <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34641#M302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have 2 different issues I believe.&amp;nbsp; You would need to invoke a RBAC users on the filer to insure that some CLI commands could not be run nor login to the filer.&amp;nbsp; However with PowerShell (PS) depending on what APIs you are calling or invoking if you can access .Net framework and issue commands the user restrictions no longer apply at that point.&amp;nbsp; You can issue any public API that the system would allow and that you are aware to call upon in the .Net framework&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jun 2014 19:57:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34641#M302</guid>
      <dc:creator>WOODROGER</dc:creator>
      <dc:date>2014-06-26T19:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: read only account</title>
      <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34646#M303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's just wrong. With RBAC, you can restrict a user to certain API calls (anything that begins with "api-") just as you can limit the CLI commands that user can exceute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, for one of my applications I have the following user that only has read-only API access to the system info, aggregate, volume and snapshot information. The user does not have CLI access at all, and attempts to access other API calls will be logged and rejected:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;useradmin role add myrole -a login-http-admin,api-system-get-info,api-aggr-list-info,api-volume-list-info,api-snapshot-list-info&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;useradmin group add mygroup -r myrole&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;useradmin user add myuser -g mygroup&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;&lt;BR /&gt;&lt;/CODE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jun 2014 10:44:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34646#M303</guid>
      <dc:creator>obrakmann</dc:creator>
      <dc:date>2014-06-27T10:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: read only account</title>
      <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34651#M304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not impossible. In fact it's quite easy as long as we're talking about the HTTP API here (and I assume we do, since we're in the NMSDK API area of the forum).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I would agree that creating a read-only CLI user is not possible, since there are some corner cases (like the vfiler commands, if I remember correctly) where destructive and read-only commands are not separated well enough.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's an example for a read-only API user, though:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;useradmin role add myrole -a login-http-admin,api-system-get-info,api-aggr-list-info,api-volume-list-info,api-snapshot-list-info&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;useradmin group add mygroup -r myrole&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;useradmin user add myuser -g mygroup&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jun 2014 10:50:36 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34651#M304</guid>
      <dc:creator>obrakmann</dc:creator>
      <dc:date>2014-06-27T10:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: read only account</title>
      <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34655#M305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure I follow you Oliver.&amp;nbsp; You called out what I said was wrong.&amp;nbsp; Was that about the RBAC or the PS?&amp;nbsp; You then restated my comment about the RBAC and gave a CLI example about the creation of a RBAC user.&amp;nbsp; Did you mean what I stated about the Powershell was wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I stated , "You would need to invoke a RBAC users on the filer to insure that some CLI commands could not be run nor login to the filer." and you said&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"With RBAC, you can restrict a user to certain API calls (anything that begins with "api-") just as you can limit the CLI commands that user can exceute."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jun 2014 16:37:32 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34655#M305</guid>
      <dc:creator>WOODROGER</dc:creator>
      <dc:date>2014-06-27T16:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: read only account</title>
      <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34659#M306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The statement that prompted my reply was "However with PowerShell (PS) depending on what APIs you are calling or invoking if you can access .Net framework and issue commands the user restrictions no longer apply at that point."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's wrong because of course you can restrict which APIs are available to PowerShell users. But maybe I just misunderstood what you wrote somewhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point that I was trying to get across is that CLI access and API access have different sets of capabilities that pertain to them, and if you want to properly restrict a user that has access to both CLI and API, you need to consider both when setting up RBAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jun 2014 12:48:25 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/34659#M306</guid>
      <dc:creator>obrakmann</dc:creator>
      <dc:date>2014-06-30T12:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: read only account</title>
      <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/138622#M2603</link>
      <description>&lt;P&gt;What if I need to just create a read-only account with all the show commands or commands which cannot change filer configuration? Are we able to create such read-only account in 7-mode?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 00:15:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/138622#M2603</guid>
      <dc:creator>vkbathala</dc:creator>
      <dc:date>2018-03-06T00:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: read only account</title>
      <link>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/140916#M2682</link>
      <description>&lt;P&gt;Check this out:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1030500" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1030500&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 14:26:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Software-Development-Kit-SDK-and-API-Discussions/read-only-account/m-p/140916#M2682</guid>
      <dc:creator>bkamil</dc:creator>
      <dc:date>2018-06-14T14:26:58Z</dc:date>
    </item>
  </channel>
</rss>

