跳转到主内容

CIFS Kerberos 的 ONTAP 要求

Views:
78
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

适用场景

  • ONTAP 9
  • Microsoft Windows
  • CIFS/SMB
  • Kerberos

问题解答

  1. 按照 映射DNS服务器 操作步骤上的SMB服务器进行操作。
  2. [1] 使用 setspn -l 带有 SVM SMB Server Name的windows命令确认UNC的服务器名部分中用于访问SMB共享的主机名、别名、完全限定域名(Fqdne)或IP地址。  如果 未返回与所用的Service VNAME匹配的条目,请按照 How to Set an SPN(如何设置SPN)进行操作。

C:\>setspn -l svm1
Registered ServicePrincipalNames for CN=SVM1,CN=Computers,DC=domain,DC=local:
     HOST/svm1.domain.local
     HOST/SVM1

  1. 对于 ONTAP和Active Directory,ONTAP与Active Directory域控制器之间的时间差不超过默认值5分钟 [2]
  2. 如果 已在所有域控制器上禁用对Kerberos的RC4支持 ,则 为CIFS SVM的基于Kerberos的通信启用AES加密

 

 

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.