跳转到主内容

CONTP-80033:由于Netlogon RPC密封的强制实施、NTLM身份验证失败

Views:
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

问题描述

  • 无法使用CIFS服务器IP地址访问CIFS共享
  • 使用NTLM进行CIFS域身份验证失败
    示例:
  • secd.cifsAuth.problem
  • failure:传递身份验证失败。(NT状态:NT_STATUS NO_LOGON_SERVERS (0xc000005e))

  • Windows域控制器(DC)日志

日志名称:系统
来源:Netlogon
日期:222/2023下午3:17:28
事件ID:5838
任务类别:无
级别:错误
关键字:经典
用户:不适用
计算机:dc1.demo NetApp。Local问题描述:
Netlogon服务遇到客户端使用RPC签名而不是RPC密封。


计算机名称名称:CIFSSERVERNAME
  • Kerberos身份验证正在运行
  • 为使用NTLMv1或NTLMv2进行域身份验证 而配置的ONTAP功能(例如、CIFS、Vscan、RBAC、域通道等)会受到影响:::>set advanced
    ::::
    *和gt;vserver cifs session show -vserver &t;vserver>-field auth-mol机制、地址、windows-user节点Svserver ssession ID connection -id address auth-mol机制windows-user

    • ----------------
      显示NetApp <vserver> 17134789207261194186 2550496605 10.62.125.88 NTLMv2 demo\user6 NetApp <vserver> 17134789207261194188 2550496606
      10.216.29.42 Kerberos demo\Administrator
      2条目。

注意:如果Kerberos身份验证尝试失败、则 默认 回退为NTLM (NTLMv1或NTLMv2)。

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.