由于 Kerberos 身份验证问题,导致 secd.cifsAuth.problem 错误
适用于
- ONTAP 9
- CIFS/SMB
- Kerberos
问题描述
- 频繁记录错误
KRB5KDC_ERR_PREAUTH_FAILED的 CIFS 身份验证事件:
[node-01: secd: secd.cifsAuth.problem:error]: vserver (svm1) General CIFS authentication problem. Error: Ontap admin cifs authentication basic procedure failed [ 27 ms] Successfully connected to ip 10.xx.xx.xx, port 88 using TCP [ 214] Successfully connected to ip 10.yy.yy.yy, port 88 using TCP **[ 283] FAILURE: Could not authenticate as 'USER.DOMAIN': Invalid Credentials (KRB5KDC_ERR_PREAUTH_FAILED). [ 285] Kerberos authentication failed. Skipping NTLM [ 285] Ontap-admin-login-cifs failed- 在域上,Windows
event 4771已登录:
LogName=SecurityEventCode=4771EventType=0SourceName=Microsoft Windows security auditing.Type=InformationRecordNumber=19229734798Keywords=Audit FailureTaskCategory=Kerberos Authentication ServiceOpCode=InfoMessage=Kerberos pre-authentication failed.- AIQUM 系统每 1 至 5 分钟使用错误的用户/密码频繁执行 zapi 请求:

- 最终用户未报告任何功能问题