無効な情報を含むPTRにより、secd.conn.auth.failureまたはsecd.ldap.noServers:EMERGENCYエラーが発生します
環境
- ONTAP 9
- DNS
問題
- LDAP署名および/またはシーリングで保護されたLDAPサーバ
- EMSログのエラー: secd.conn.auth.failure:notice または secd.ldap.noServers:EMERGENCY
- サイトディスカバリ:
- EMS:
[secd: secd.ldap.noServers:EMERGENCY]: None of the LDAP servers configured for Vserver <VServer Name> are currently accessible via the network
- SECD:
[auth_secd:notice] GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)
- GPO処理:
SECD
.------------------------------------------------------------------------------.
RPC FAILURE:
secd_rpc_gpo_get_list has failed
Result = 0, RPC Result = 6940
RPC received at Thu Feb 13 09:51:42 2020
------------------------------------------------------------------------------'
FAILURE: Unable to SASL bind to LDAP server using GSSAPI: Local error
Additional info: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Server not found in Kerberos database)
Unable to connect to LDAP (Active Directory) service on dc1.demo.netapp.com (Error: Local error)
No servers available for MS_LDAP_AD, vserver: 3, domain: demo.netapp.com.
Unable to make a connection (LDAP (Active Directory):DEMO.NETAPP.COM), result: 6940
Details for this error state SPN (ldap/gc.demo.netapp.com) is incorrect (dc1.demo.netapp.com:
info : [krb5 context 0991DC00] ccselect can't find appropriate cache for server principal ldap/gc.demo.netapp.com@
注: パケットトレースでは TGS-REQ
エラーを返します KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN