对具有多个组的用户进行Kerberos CIFS身份验证失败
适用场景
- ONTAP 9
- CIFS/SMB
- Kerberos
问题描述
- 具有大量组的用户无法通过FQDN (Kerberos)连接到CIFS共享。能够通过IP (NTLMv2)进行连接。
- EMS显示:
SECD.CIFSAUTH.PROBLEM:VSERVER General CIFS authentication problem. Error: User authentication procedure failed CIFS SMB2 Share mapping – Client IP = xxx.xxx.xxx.xxx (3 ms) Could not decode user claims information in Kerberos ticket.
- Windows客户端显示:
A ticket to the service cifs/"DC Name"/"DomainName" is issued for account "AccountName"@"DomainName". The size of the encrypted part of this ticket is 22648 bytes, which is close or greater than the configured ticket size threshold (15000 bytes)