ONTAP 9.12.1 commands

50←PDF
  • ONTAP 9.12.1 commands(CA08871-263en.pdf)
  • vserver nfs kerberos interface show

    Display the Kerberos configurations of NFS servers

    Availability: This command is available to cluster and Vserver administrators at the admin privilege level.

    Description

    The vserver nfs kerberos interface show command displays information about Kerberos configurations for NFS. The command output depends on the parameters specified with the command. If you do not specify any parameters, the command displays the following information about all Kerberos configurations for NFS:

    • Vserver name

    • Logical interface name

    • Logical interface IP address

    • Whether Kerberos is enabled or disabled

    • The Kerberos service principal name (SPN)

    • The permitted encryption types

    You can specify additional parameters to display only information that matches those parameters. For instance, to display information only about Kerberos configurations for NFS that are enabled, run the command with the -kerberos enabled parameter.

    Parameters

    { [-fields <fieldname>,…​]

    If you specify the -fields <fieldname>, …​ parameter, the command output also includes the specified field or fields. You can use '-fields ?' to display the fields to specify.

    | [-instance ] }

    If you specify the -instance parameter, the command displays detailed information about all fields.

    [-vserver <vserver name>] - Vserver

    If you specify this parameter and the -lif parameter, the command displays information only about the Kerberos configuration or configurations for NFS that are associated with the specified Vserver and logical interface.

    [-lif <text>] - Logical Interface

    If you specify this parameter and the -vserver parameter, the command displays information only about the Kerberos configuration or configurations for NFS that are associated with the specified logical interface and Vserver.

    [-address <IP Address>] - IP Address

    If you specify this parameter, the command displays information only about the Kerberos configurations for NFS that are associated with the specified logical-interface IP address.

    [-kerberos {enabled|disabled}] - Kerberos Enabled

    If you specify this parameter, the command displays information only about the Kerberos configurations for NFS that match the specified value.

    [-spn <text>] - Service Principal Name

    If you specify this parameter, the command displays information only about the Kerberos configuration or configurations for NFS that match the specified SPN.

    [-permitted-enc-types <NFS Kerberos Encryption Type>,…​] - Permitted Encryption Types

    If you specify this parameter, the command displays information only about the Kerberos configuration for NFS that matches the specified encryption types.

    [-machine-account <text>] - Machine Account Name

    If you specify this parameter, the command displays information only about the Kerberos configuration for NFS that matches the specified machine account.

    Examples

    The following example displays information about the Kerberos configuration for NFS associated with the Vserver vs0 and the logical interface datalif1:

    vs1::> vserver nfs kerberos interface show -vserver vs0 -lif datalif1
                       Vserver: vs1
             Logical Interface: datalif1
                    IP Address: 192.0.2.130
              Kerberos Enabled: enabled
        Service Principal Name: nfs/sec.example.com@AUTH.SEC.EXAMPLE.COM
    Permitted Encryption Types: des,des3,aes-128,aes-256
    Top of Page