Announcement Banner

AndrewF76

updated

4 years ago

A

AndrewF76

46 Posts

0

3926

April 3rd, 2022 01:00

Isilon Ldap samba authenticating issue

Hi,

We have a cluster of X400 nodes, still on OneFS 7.1.1.11.

We have an Xserve MacOs Ldap server, OneFS is connected to it, I can list the users and groups from the Ldap server in the webgui.

The issue is that I can't mount any of the smb mountpoints I created from Linux, Win or Mac, I get a permission denied if I try to mount with a network user credentials. I created local users on the cluster, I was able to smb mount with these local users credentials but I need to be able to do the same with network users credentials from the Ldap server..

I found a manual how to set it but I can't get it to work.

Could someone please help me solve this issue?

Many thx

  • Phil.Lam

    4 Apprentice

    •

    642 Posts

    •

    15 Points

    1212

    0

    Posted April 26th, 2022 15:00

    @AndrewF76 , I found this old doc for OneFS 7.x and mac  "using-mac-os-x-clients-with-isilon-onefs-7x.pdf", google it.


    PhilLam_0-1651012454475.png

    PhilLam_1-1651012540952.png

    PhilLam_2-1651012716033.png

     

  • DELL-Sam L

    Community Manager

    •

    8097 Posts

    •

    34553 Points

    1313

    0

    Posted April 4th, 2022 12:00

    Hello AndrewF76,

    Here are a few links to some kb’s that maybe of assistance.

    https://dell.to/37hFgzZ

    https://dell.to/3KgHjDm

    https://dell.to/35D4Hvs

  • AndrewF76

    46 Posts

    1297

    0

    Posted April 5th, 2022 07:00

    Hi Sam,

    As the manual from the first link suggests I added the sambaNTPassword but it seems that didn't help.

    The LDAP server supports NTLM v1 and v2.

    The configs are:

    gyar-1# isi auth ldap view --provider-name=xserve01.local
    Name: xserve01.local
    Base DN: dc=xserve01,dc=local
    Server Uris: ldap://192.168.100.30
    Status: online
    Alternate Security Identities Attribute:
    Authentication: Yes
    Balance Servers: No
    Bind DN:
    Bind Timeout: 10
    Cache Entry Expiry: 15m
    Certificate Authority File:
    Check Online Interval: 3m
    CN Attribute: cn
    Create Home Directory: No
    Crypt Password Attribute:
    Email Attribute: mail
    Enabled: Yes
    Enumerate Groups: Yes
    Enumerate Users: Yes
    Findable Groups: -
    Findable Users: -
    GECOS Attribute: gecos
    GID Attribute: gidNumber
    Group Base DN:
    Group Domain: LDAP_GROUPS
    Group Filter: (objectClass=posixGroup)
    Group Members Attribute: memberUid
    Group Search Scope: default
    Home Directory Template:
    Homedir Attribute: homeDirectory
    Ignore TLS Errors: No
    Listable Groups: -
    Listable Users: -
    Login Shell:
    Member Of Attribute:
    Name Attribute: uid
    Netgroup Base DN:
    Netgroup Filter: (objectClass=nisNetgroup)
    Netgroup Members Attribute: memberNisNetgroup
    Netgroup Search Scope: default
    Netgroup Triple Attribute: nisNetgroupTriple
    Normalize Groups: No
    Normalize Users: No
    Nt Password Attribute: sambaNTPassword
    Ntlm Support: all
    Provider Domain:
    Require Secure Connection: No
    Restrict Findable: No
    Restrict Listable: No
    Search Scope: subtree
    Search Timeout: 100
    Shell Attribute: loginShell
    UID Attribute: uidNumber
    Unfindable Groups: -
    Unfindable Users: -
    Unique Group Members Attribute:
    Unlistable Groups: -
    Unlistable Users: -
    User Base DN:
    User Domain: LDAP_USERS
    User Filter: (objectClass=posixAccount)
    User Search Scope: default
    gyar-1#































































    gyar-1# isi smb settings global view
    Access Based Share Enum: No
    Dot Snap Accessible Child: Yes
    Dot Snap Accessible Root: Yes
    Dot Snap Visible Child: No
    Dot Snap Visible Root: Yes
    Enable Security Signatures: No
    Guest User: nobody
    Ignore Eas: No
    Onefs Cpu Multiplier: 4
    Onefs Num Workers: 0
    Require Security Signatures: No
    Server String: isilon server
    Srv Cpu Multiplier: 4
    Srv Num Workers: 0
    Support Multichannel: Yes
    Support NetBIOS: Yes
    Support Smb2: Yes


















    gyar-1# isi smb settings shares view
    Access Based Enumeration: No
    Access Based Enumeration Root Only: No
    Allow Delete Readonly: No
    Allow Execute Always: No
    Change Notify: norecurse
    Create Permissions: default acl
    Directory Create Mask: 0775
    Directory Create Mode: 0775
    File Create Mask: 0775
    File Create Mode: 0775
    Hide Dot Files: No
    Host ACL: -
    Impersonate Guest: never
    Impersonate User:
    Mangle Byte Start: 0XED00
    Mangle Map: 0x01-0x1F:-1, 0x22:-1, 0x2A:-1, 0x3A:-1, 0x3C:-1, 0x3E:-1, 0x3F:-1, 0x5C:-1
    Ntfs ACL Support: Yes
    Oplocks: Yes
    Strict Flush: Yes
    Strict Locking: No
    gyar-1#





















    The permission check from the 3rd link isn't working, the syntax isn't correct:

    gyar-1# isi auth mapping token --name=VMTEST\\testuser1 -v
    unknown option name
    Usage:
    isi auth mapping token { | --uid | --kerberos-principal }
    [--zone ]
    [--primary-gid ]
    [--gid ]
    [{--help | -h}]
    See 'isi auth mapping token --help' for more information.







    So I'm still stuck...

    Screenshot 2022-04-05 at 16.48.20.jpg

  • DELL-Sam L

    Community Manager

    •

    8097 Posts

    •

    34553 Points

    1291

    0

    Posted April 5th, 2022 12:00

    Hello AndrewF76,

    For this issue it is best to open a support case so that we can take a deeper look into your issue.

  • AndrewF76

    46 Posts

    1280

    0

    Posted April 5th, 2022 22:00

    Hi Sam,

    We don't have support contract on this cluster, it's not the latest model... I think that contacting support would be a bit too expensive, but I might be wrong.

    Maybe, if someone is willing to help us privately could contact me...

    Andrew

  • AndrewF76

    46 Posts

    1276

    0

    Posted April 6th, 2022 00:00

    Hi Sam,

    Is there a log file on the Isilon that might be worth checking to see what is the reason (error message) for not mounting with smb?

    Thx

    Best

    Andrew

  • Phil.Lam

    4 Apprentice

    •

    642 Posts

    •

    15 Points

    1260

    0

    Posted April 6th, 2022 10:00

    @AndrewF76,

    try
    isi auth mapping token --user=VMTEST\\testuser1 -v

  • AndrewF76

    46 Posts

    1255

    0

    Posted April 6th, 2022 11:00

    I was planning to do an upgrade to 8.1.2 but I'm not sure about the licenses, I read that when upgrading to 8.1.x.x I need to request new licenses.

     

    gyar-3# isi auth mapping token --user=testuser1
    Failed to map user 'testuser1': No such user
    gyar-3#

     

  • AndrewF76

    46 Posts

    1259

    0

    Posted April 6th, 2022 11:00

    Hi,

    gyar-3# isi auth mapping token --user=VMTEST\\testuser1 -v
    unknown option v
    Usage:
    isi auth mapping token { | --uid | --kerberos-principal
    }
    [--zone ]
    [--primary-gid ]
    [--gid ]
    [{--help | -h}]
    See 'isi auth mapping token --help' for more information.
    gyar-3#

    gyar-3# isi auth mapping token --user=VMTEST\\testuser1
    Failed to map user 'VMTEST\testuser1': No such user
    gyar-3#

  • Phil.Lam

    4 Apprentice

    •

    642 Posts

    •

    15 Points

    1256

    0

    Posted April 6th, 2022 11:00

    @AndrewF76 

     

    upgrade to OneFS 8.1.2

    try  
    isi auth mapping token --user=testuser1