跳转到主内容

迁移后 XCP SMB 验证返回无法获取安全描述符错误

Views:
35
Visibility:
Public
Votes:
0
Category:
fas-systems
Specialty:
nas
Last Updated:

适用于

  • XCP SMB
  • ONTAP 9

问题描述

  • 使用 XCP SMB 工具在 CIFS 共享之间复制数据后,运行 xcp verify 命令对所有文件产生 failed to get security descriptor 错误
示例:

C:\xcp\windows>xcp verify -loglevel debug \\storage_ip\cifs01 \\storage_ip\des01
XCP SMB 1.9.4P1; (c) 2025 NetApp, Inc.

57 scanned, 0 compared, 0 same, 0 different, 0 missing, 0 errors, 7s
failed to get security descriptor for "\\storage_ip\cifs01\all_source_files
failed to get security descriptor for "\\storage_ip\cifs01\all_target_files

57 scanned, 56 compared, 56 same, 0 different, 0 missing, 0 errors, 43s
xcp verify -loglevel debug \\storage_ip\cifs01 \\storage_ip\des01
57 scanned, 56 compared, 56 same, 0 different, 0 missing, 0 errors
Total Time : 43s
STATUS : PASSED

  • Everyone 组应用于源卷及其基础数据
  • 源卷的安全样式设置为 ntfs
  • xcp copy 已完成,没有任何问题
  • xcp copy 之后,目标数据还继承了 Everyone 组的 ACL。
  • 为 XCP 配置的 CIFS 用户具有足够的权限
cluster::*>vserver cifs users-and-groups local-group show-members -vserver svm01
Vserver     Group Name          Members
-------------- ---------------------------- ------------------------
svm01      BUILTIN\Administrators    CIFS\Administrator
CIFS\cifs_user
 
cluster::*>diag secd authentication show-creds -vserver svm01 -win-name cifs_user
UNIX UID: pcuser <> Windows User: CIFS\cifs_user (Windows Local User)
 
GID: pcuser
Supplementary GIDs:
pcuser
 
Primary Group SID: CIFS\None (Windows Domain group)
 
Windows Membership:
User is also a member of Everyone, Authenticated Users, and Network Users
 
Privileges (0x201f):
SeTcbPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeTakeOwnershipPrivilege
SeSecurityPrivilege
SeChangeNotifyPrivilege
 
cluster::*> vserver cifs users-and-groups privilege show -vserver svm01
Vserver     User or Group Name      Privileges
-------------- ---------------------------- -------------------
svm01      CIFS\cifs_user           SeBackupPrivilege
SeChangeNotifyPrivilege
SeRestorePrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeTcbPrivilege

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.