跳转到主内容

CIFS创建失败、并显示LDAP错误用户没有足够的访问权限

Views:
21
Visibility:
Public
Votes:
4
Category:
ontap-9
Specialty:
nas<a>2010004411</a>
Last Updated:

适用场景

  • ONTAP 9
  • CIFS

问题描述

  • CIFS创建失败、并显示以下错误
::*> cifs server create -vserver svm1 -cifs-server cifs1 -domain domain.com -ou CN=Computers
In order to create an Active Directory machine account for the CIFS server, you must supply the name and password of a Windows account with sufficient privileges to add computers to the "CN=Computers" container within the "domain.com" domain.
Enter the user name: user
Enter the password:
Error: Machine account creation procedure failed
[ 16507] Loaded the preliminary configuration.
[ 16849] Created a machine account in the domain
[ 16850] SID to name translations of Domain Users and Admins completed successfully
[ 16872] Successfully connected to ip 10.x.x.x, port 88 using TCP
[ 16917] Successfully connected to ip 10.x.x.x, port 464 using TCP
[ 16961] Kerberos password set for 'cifs$@domain' succeeded
[ 16961] Set initial account password
**[ 17017] FAILURE: Unable to set machine account attribute**'msDS-SupportedEncryptionTypes': Insufficient access
[ 17059] Deleted existing account 'CN=cifs,CN=Computers,DC=domain,DC=com'
Error: command failed: Failed to create the Active Directory machine account "cifs". Reason: LDAP Error: The user has insufficient access rights.
  • Packet trace c已 收集显示创建CIFS后修改"MDS-Supported加密 类型"时DC正在使用不充分的访问权限进行重新寻道。
No Source Destination Proto Info
1  10.x.x.x 10.y.y.y LDAP modifyRequest(9) "CN=cifs,CN=Computers,DC=domain,DC=com" 
protocolOp: modifyRequest (6)
   modifyRequest
     object: CN=cifs,CN=Computers,DC=domain,DC=com
     modification: 1 item
       modification item
         operation: replace (2)
         modification msDS-SupportedEncryptionTypes
           type: msDS-SupportedEncryptionTypes
           vals: 1 item
             AttributeValue: 30
2 10.y.y.y 10.x.x.x LDAP modifyResponse(9) insufficientAccessRights (00002098: SecErr: DSID-031514B3, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0\n) 

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.