Skip to main content

Enable S3 protocol access to NAS data

Contributors netapp-lenida netapp-dbagwell netapp-mwallis netapp-aherbin

Enabling S3 protocol access consists of ensuring that a NAS-enabled SVM meets the same requirements as an S3-enabled server, including adding an object store server, and verifying networking and authentication requirements.

For new ONTAP installations, it is recommended that you enable S3 protocol access to an SVM after configuring it to serve NAS data to clients. To learn about NAS protocol configuration, see:

Before you begin

The following must be configured before enabling the S3 protocol:

  • The S3 protocol and the desired NAS protocols - NFS, SMB, or both - are licensed.

  • An SVM is configured for the desired NAS protocols.

  • NFS and/or SMB servers exist.

  • DNS and any other required services are configured.

  • NAS data is being exported or shared to client systems.

About this task

A Certificate Authority (CA) certificate is required to enable HTTPS traffic from S3 clients to the S3-enabled SVM. CA certificates from three sources can be used:

  • A new ONTAP self-signed certificate on the SVM.

  • An existing ONTAP self-signed certificate on the SVM.

  • A third-party certificate.

You can use the same data LIFs for the S3/NAS bucket that you use for serving NAS data. If specific IP addresses are required, see Create data LIFs. An S3 service data policy is required to enable S3 data traffic on LIFs; you can modify the SVM’s existing service policy to include S3.

When you create the S3 object server, you should be prepared to enter the S3 server name as a Fully Qualified Domain Name (FQDN), which clients will use for S3 access. The S3 server FQDN must not begin with a bucket name.

  1. Enable S3 on a storage VM with NAS protocols configured.

    1. Click Storage > Storage VMs, select a NAS-ready storage VM, click Settings, and then click Actions icon under S3.

    2. Select the certificate type. Whether you select system-generated certificate or one of your own, it will be required for client access.

    3. Enter the network interfaces.

  2. If you selected the system-generated certificate, you see the certificate information when the new storage VM creation is confirmed. Click Download and save it for client access.

    • The secret key will not be displayed again.

    • If you need the certificate information again: click Storage > Storage VMs, select the storage VM, and click Settings.