CIFS環境では'RODCのみでKerberos通信が機能しません
環境
- ONTAP 9
- CIFS
- Domain Controller(DC;ドメイン コントローラ)
- ReadOnlyDC(RODC)
- ReadWriteDC(RWDC)
- Kerberos
- 非武装地帯(DMZ)
問題
- CIFS環境では'RODCのみでKerberos通信が機能しません
secd: secd.unexpectedFailure:debug: vserver (<vserver>) Unexpected failure. Error: Lookup of CIFS account SID procedure failed
Successfully connected to ip <rodc>, port 445 using TCP
Improper format of Kerberos configuration file (KRB5_CONFIG_BADFORMAT)
Failed to initiate Kerberos authentication. Trying NTLM.
Encountered NT error (NT_STATUS_MORE_PROCESSING_REQUIRED) for SMB command SessionSetup
Successfully authenticated with DC <rodc>
Could not find Windows SID '<sid>'
FAILURE: SID lookup failed