メインコンテンツへスキップ

必要な権限を持つユーザが古いクレデンシャルを使用して既存のCIFSセッションがあるとCIFSパスにアクセスできない

Views:
52
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

環境

  • ONTAP 9
  • CIFS

問題

  • 必要なすべての権限を持つユーザがCIFSパスにアクセスできず、permission deniedまたはaccess is deniedエラーが発生しています。
  • ユーザにCIFSパスに対する読み取り/書き込み権限があり、WindowsユーザはUNIXルートにマッピングされています。
cluster1::> vserver security file-directory show-effective-permissions -vserver vs1 -win-user-name domain1\user1 -path /volume/path
Vserver: vs1
Windows User Name: domain1\user1
Unix User Name: root
File Path: /volume/path
CIFS Share Path: -
Effective Permissions:
Effective File or Directory Permission: 0x1f01ff
Read
Write
Read Attributes
Write Attributes
  • sectrace では、ユーザに読み取り権限がなく、UNIX pcuserへのマッピングが表示されます。
cluster1::*> sectrace trace-result show
Vserver: vs1
Node       Index Filter Details       Reason
--------------- ----- -------------------------- ------------------------------
node1    Security Style: NTFS and        Access is denied. The
NT ACL              requested permissions are not
granted by the ACE while
opening existing file or
directory. Access is not
granted for: "Read
Attributes", "Read"
Protocol: cifs
Volume: -
Share: share1
Path: /volume/path
Win-User: domain1\user1
UNIX-User: pcuser
Session-ID: 1013872866111782917

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.