Unix users from VAS/Vintela/OneIdentity/Quest fail to get group-based access via NFS
Applies to
- ONTAP 9
- LDAP
- VAS/Vintela/Quest/OneIdentity using Unix Personality Containers
Issue
getxxbyyy getgrlist
gives a partial list of group members, rather than all group members- Access checks requiring full group membership info do not succeed due to incomplete group membership information
- This specifically impacts configurations where Unix Personality Containers are in use
- Unix Personality Containers are an optional feature of the VAS/Vintela/OneIdentity/Quest LDAP environment, which allows a constrained view of users within a specific OU which contains those users and groups only by reference