CIFS サーバ アカウントのパスワードが Active Directory に格納されているパスワードと一致しません(KRB5KDC_ERR_PREAUTH_FAILED)
環境
- ONTAP 9
- CIFS / SMB
問題
- クライアントが
\\svm_ip、\\svm_ip\share_name、または\\fqdn経由でSMB/CIFS共有にアクセスできない

注: スクリーンショットにエラーが表示されます:Windows cannot access \\hostname\sharename
- EMS ログ エラー:
Wed Sep 27 02:50:49 +0000 [node-01: secd: secd.cifsAuth.problem:error]: vserver (svm_name) General CIFS authentication problem.
[ 3398] CIFS server account password does not match password stored in Active Directory (KRB5KDC_ERR_PREAUTH_FAILED)
Wed Sep 27 02:50:40 +0000 [node-01: secd: secd.kerberos.preauth:error]: Kerberos pre-authentication failure due to out-of-sync machine account password for vserver (svm_name).
secd.conn.auth.failure:error: Vserver (SVM01) could not authenticate over the network to server (Server01)
注:
- セキュリティーデーモンの secd ログ:
00000008.005bdd68 0493a463 Wed Sep 27 2023 02:50:49 +00:00 [kern_secd:info:88xx] | [002.382.xxx] info : [krb5 context 087D0xxx] Received error from KDC: -17653xxxxx/Additional pre-authentication required
- パスワード変更の失敗(
vserver cifs domain password change): - CLI応答
Error: Password update failed. Reason: Kerberos Error: Invalid credentials were given.
- EMS
mgwd: cifs.domainpwd.not.updated:error]: An attempt to update the domain account password for Vserver X failed during password change with the following error: Password update failed. Reason: Kerberos Error: Invalid credentials were given