CIFS创建失败、并显示错误"证书验证失败"
适用场景
- ONTAP 9
- CIFS
- LDAPS
- 证书SSL
问题描述
- 无法使用LDAPS加入SVM、并显示证书验证失败错误
cluster1::> vserver cifs security show -vserver svm1 -fields use-ldaps-for-ad-ldap
vserver use-ldaps-for-ad-ldap
------- ---------------------
svm1 true
cluster1::> vserver cifs create -vserver svm1 -cifs-server cifs01 -domain example.com
Error: Machine account creation procedure failed
[ 26699] Successfully connected to ip 192.168.0.20, port 636 using TCP
[ 27040] Required certificate with CA Certificate1 Racine is not installed
[ 27042] Unable to start LDAPS: Can't contact LDAP server
[ 27042] Additional info: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
[ 27042] Unable to connect to LDAP (Active Directory) service on dc.example.com (Error: Can't contact LDAP server)
[ 27042] FAILURE: Unable to make a connection (LDAP (ActiveDirectory):EXAMPLE.COM), result: 7642
Secd
日志:
debug: LDAP TLS Alert generated is 'fatal:unknown CA'