AD域服务帐户间歇性身份验证失败
适用场景
- ONTAP 9
- CIFS
问题描述
某个特定域用户的ONTAP管理员访问域身份验证间歇性失败
- EMS日志:
secd.cifsAuth.problem: vserver (svm1) General CIFS authentication problem. Error: Ontap admin cifs authentication basic procedure failed
- SecD日志:
.------------------------------------------------------------------------------.
| !!! NOTE: The logging below contains a SERIOUS ISSUE. !!! |
| Check for entries of type: CRIT, ALERT, or EMERG. |
| The RPC may or may not have failed. |
.------------------------------------------------------------------------------.
| RPC FAILURE: |
| secd_rpc_ontap_admin_cifs_auth_basic has failed |
| Result = 0, RPC Result = 6940 |
| RPC received at Wed Oct 4 10:02:05 2023 |
|------------------------------------------------------------------------------'
Failure Summary:
Error: Ontap admin cifs authentication basic procedure failed
[ 34 ms] Successfully connected to ip 10.xxx.x.4, port 88 using TCP
[ 60] Successfully connected to ip 10.xxx.x.4, port 88 using TCP
[ 68] Matching credential not found (KRB5_CC_NOTFOUND)
[ 68] Kerberos authentication failed. Trying NTLM
[ 68] Login attempt by domain user 'domain\user' using NTLMv2 style security
[ 109] Successfully connected to ip 10.xxx.x.4, port 445 using TCP
[ 117] Successfully connected to ip 10.xxx.x.4, port 88 using TCP
[ 163] Unknown error: 39756032
[ 163] Kerberos authentication failed with result: 7556.
[ 163] Unable to connect to NetLogon service on dc1.domain.local (Error: RESULT_ERROR_SECD_NO_CONNECTIONS_AVAILABLE)
[ 167] Successfully connected to ip 10.xxx.x.1, port 445 using TCP
[ 171] Successfully connected to ip 10.xxx.x.4, port 88 using TCP
[ 199] Unknown error: 39756032
[ 199] Kerberos authentication failed with result: 7556.
[ 200] Unable to connect to NetLogon service on dc2.domain.local (Error: RESULT_ERROR_SECD_NO_CONNECTIONS_AVAILABLE)
[ 201] Successfully connected to ip 10.xxx.x.2, port 445 using TCP
[ 209] Successfully connected to ip 10.xxx.x.4, port 88 using TCP
[ 238] Unknown error: 39756032
[ 238] Kerberos authentication failed with result: 7556.
[ 238] Unable to connect to NetLogon service on s0002.domain.local (Error: RESULT_ERROR_SECD_NO_CONNECTIONS_AVAILABLE)
[ 238] No servers available for MS_NETLOGON, vserver: 3, domain: domain.local.
**[ 238] FAILURE: Unable to make a connection (NetLogon:domain.LOCAL), result: 6940
[ 240] Ontap-admin-login-cifs failed