使用Red Hat Identity Management KDC时、在数据LIF上启用Kerberos失败
适用场景
- ONTAP 9
- Red Hat身份管理(IdM)
- 密钥分发中心(KDC)
问题描述
在数据LIF上启用NFS Kerberos后显示错误:
Error: NFS Kerberos bind SPN procedure failed
[ 0 ms] Creating account in Unix KDC
[ 29] Successfully connected to ip 10.10.10.10, port 749 using
TCP
**[ 133] FAILURE: Unexpected state: Error 1142 at
** file:src/utils/secd_kadmin_utils.cpp
** func:createVifKrbAccountUsingKadmin line:227
**[ 133] FAILURE: spn already exists. Failed to reuse spn
** 'nfs/nfs/demo-ipa.centos-ldap.local@CENTOS-LDAP.LOCAL' using admin spn
** 'kadmin/admin@CENTOS-LDAP.LOCAL', error: Unknown code 0
[ 134] Uncaptured failure while creating account
Error: command failed: Failed to enable NFS Kerberos on LIF "demo-ipa".
Failed to bind service principal name on LIF "demo-ipa". cifs smb kadmin error.