LDAP returned 0 results for attribute tokenGroups
Applies to
- ONTAP 9
- Active Directory
- NFS
- NTFS security style volume
Issue
- When doing Authentication, LDAP returns 0 results for attribute tokenGroups, causing Authentication to fail
- The root user from NFS clients fails to access the NTFS security volume with the error
permission denied - EMS reports
secd.nfsAuth.noCifsCredfor the mapping Windows user - Name mapping configuration shows an explicit mapping that maps the root user to a Windows domain service account
- SecD shows
RESULT_ERROR_SECD_LDAP_ATTRIBUTE_MISSINGandRESULT_ERROR_SECD_CIFS_CRED_LOOKUP_FAILED - The command to show user credentials fails on the Windows service account with
SecD Error: LDAP attribute missing::> set advanced::>vserver services access-check authentication show-creds -node node1 -vserver svm1 -win-name <winuser> - The command succeeds for regular Windows domain users
