Red Hat Identity Management KDCの使用時にデータLIFでKerberosを有効にできない
環境
- ONTAP 9
- Red Hat Identity Management(IDM)
- キー配布センター(KDC)
問題
データLIFでNFS Kerberosを有効にしたあとに表示されるエラー:
Error: NFS Kerberos bind SPN procedure failed
[ 0 ms] Creating account in Unix KDC
[ 29] Successfully connected to ip 10.10.10.10, port 749 using
TCP
**[ 133] FAILURE: Unexpected state: Error 1142 at
** file:src/utils/secd_kadmin_utils.cpp
** func:createVifKrbAccountUsingKadmin line:227
**[ 133] FAILURE: spn already exists. Failed to reuse spn
** 'nfs/nfs/demo-ipa.centos-ldap.local@CENTOS-LDAP.LOCAL' using admin spn
** 'kadmin/admin@CENTOS-LDAP.LOCAL', error: Unknown code 0
[ 134] Uncaptured failure while creating account
Error: command failed: Failed to enable NFS Kerberos on LIF "demo-ipa".
Failed to bind service principal name on LIF "demo-ipa". cifs smb kadmin error.