LINUXOR.SK ... open source notes ...

NetApp - ONTAP CIFS server, LDAP client and domain tunnel for admin logins

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

NetApp Solution · Config document · referenced from Access and directory integration

noteThe domain join itself was done in System Manager and asks for a domain account that may create computer objects; there is no command for it here. No password appears in this command set.

The commands that let members of two Active Directory groups log in to a cluster over SSH, System Manager and ONTAPI: a CIFS SVM as domain member, an LDAP client on that SVM, the SVM declared as domain tunnel, and the login entries that map the groups to roles.

ItemValue
Runs oncluster shell of DC1-A-XNAS001, as admin
Shown herecluster A with tunnel SVM DC1-S-VCVSM003
Also applied toDC1-B-XNAS001 with DC1-S-VCVSM004; site 2 by the design, without notes
DomainAD.EXAMPLE.NET, NetBIOS name EXAMPLE
ONTAP version at the time9.1P8

The command set

bash
# 1. Before the join: talk SMB2, not SMB1, to the domain controllers
cifs security modify -vserver DC1-S-VCVSM003 -smb1-enabled-for-dc-connections false -smb2-enabled-for-dc-connections true

# 2. Join the SVM to the domain AD.EXAMPLE.NET as CIFS server DC1-S-VCVSM003:
#    done in the web interface (System Manager) of the cluster, not on the
#    command line

# 3. LDAP client configuration on the tunnel SVM: AD-IDMU schema, StartTLS on
#    port 389, sealed session, binding as the CIFS server (machine account)
ldap client create -vserver DC1-S-VCVSM003 -client-config DC1-S-VCVSM003_ldap -schema AD-IDMU -port 389 -query-timeout 10 -min-bind-level sasl -bind-dn netapp_svc -base-dn DC=ad,DC=example,DC=net -base-scope subtree -use-start-tls true -session-security seal -bind-as-cifs-server true -ad-domain AD.EXAMPLE.NET

# 4. Associate the LDAP client configuration with the SVM and enable it
vserver services name-service ldap create -vserver DC1-S-VCVSM003 -client-config DC1-S-VCVSM003_ldap -client-enabled true

# 5. CIFS security of the tunnel SVM: NTLMv2 and Kerberos only, signing
#    required, sealed LDAP sessions to AD, SMB2 to the domain controllers
vserver cifs security modify -vserver DC1-S-VCVSM003 -lm-compatibility-level ntlmv2-krb -is-smb-encryption-required false -session-security-for-ad-ldap seal -smb1-enabled-for-dc-connections false -smb2-enabled-for-dc-connections true -is-signing-required true

# 6. Use the SVM as authentication tunnel for the cluster (admin SVM)
security login domain-tunnel create -vserver DC1-S-VCVSM003

# 7. Administrators: AD group -> role admin, for SSH, HTTP and ONTAPI
security login create -user-or-group-name example\netapp_adm -application ssh -authentication-method domain -role admin -vserver DC1-A-XNAS001
security login create -user-or-group-name example\netapp_adm -application http -authentication-method domain -role admin -vserver DC1-A-XNAS001
security login create -user-or-group-name example\netapp_adm -application ontapi -authentication-method domain -role admin -vserver DC1-A-XNAS001

# 8. Operators: AD group -> role readonly, for SSH, HTTP and ONTAPI
security login create -user-or-group-name example\netapp_opr -application ssh -authentication-method domain -role readonly -vserver DC1-A-XNAS001
security login create -user-or-group-name example\netapp_opr -application http -authentication-method domain -role readonly -vserver DC1-A-XNAS001
security login create -user-or-group-name example\netapp_opr -application ontapi -authentication-method domain -role readonly -vserver DC1-A-XNAS001

Cluster B differs as follows:

ParameterCluster ACluster B
Tunnel SVMDC1-S-VCVSM003DC1-S-VCVSM004
LDAP client configurationDC1-S-VCVSM003_ldapDC1-S-VCVSM004_ldap
-query-timeout103
-vserver of the login entriesDC1-A-XNAS001DC1-B-XNAS001
Preferred domain controller of the CIFS server, in the as-built reportnone10.11.16.209

The as-built report confirms the result on both tunnel SVMs: CIFS server in AD.EXAMPLE.NET, LDAP client with schema AD-IDMU and minimum bind level sasl, client enabled, SMB2 and SMB3 enabled, and one name mapping rule on DC1-S-VCVSM003 (direction krb_unix, stripping the EXAMPLE\ prefix) for which the notes hold no command.

-bind-dn netapp_svc and -bind-as-cifs-server true are both given. With the second, the SVM binds with its machine account, so the service account and its password are not used by this configuration; the notes show no password prompt.

What was tried before and is not part of this

The LDAP client configurations DC1-A-XNAS001_ldap and LDAP-ADMIN-VSM on the admin SVM, the ns-switch change to files,ldap, the login entries with the method nsswitch and the first tunnel through DC1-S-VCVSM001 belong to the abandoned attempt described in the Article. The notes do not show their removal.

Checked against ONTAP 9.19.1

As builtToday
CIFS SVM plus security login domain-tunnel createStill valid, and required before ONTAP 9.16.1. From 9.16.1 vserver active-directory create accepts the admin SVM, so the cluster can have its own computer account and needs no tunnel SVM. Kerberos is used for tunnel authentication since 9.10.1, with NTLM as fallback
security login create for an AD group with -application httpThe syntax is valid, but AD group access is documented only for the applications ssh, ontapi and rest. The group entries for http are outside what is documented
-application ontapiStill accepted. From ONTAP 9.14 ONTAPI is disabled automatically when no call is seen for 30 days after an upgrade; new features are REST only
ldap client create (short path)The documented path is vserver services name-service ldap client create. -servers, used in the abandoned attempt, is deprecated in favour of -ldap-servers
-bind-as-cifs-server true together with -bind-dn and -min-bind-levelWith -bind-as-cifs-server true only SASL bind is used; -min-bind-level and -bind-dn are ignored
StartTLS on port 389 with -session-security sealStill NetApp's stated preference over LDAPS. LDAPS is a mode of its own (-ldaps-enabled, from 9.9.1). Channel binding is tried by default since 9.10.1, only with StartTLS or LDAPS plus sign or seal
-smb1-enabled-for-dc-connections falseThe parameter is deprecated because SMB1 is obsolete; the other vserver cifs security modify options used here still exist. The default LM compatibility level is still lm-ntlm-ntlmv2-krb, so ntlmv2-krb remains a deliberate setting
Netlogon secure channel left at its defaultAES session keys are supported from 9.10.1 and enabled by default only for SVMs created on 9.14.1 or later; older SVMs need -aes-enabled-for-netlogon-channel true

On the last release a FAS8200 can run, 9.16.1, the tunnel SVM is no longer necessary. The combination tried and abandoned in 2017, plain LDAP on port 389 without StartTLS, without session security and with a bind DN, must not be copied: a simple bind without TLS sends the bind password in clear text.

← solutionz