RHEL clients fail to set NFSv4 ACL on volumes for special UNIX group
Applies to
- ONTAP 9
- NFSv4 ACL (Access Control List)
- Windows Active Directory integrated LDAP
- RHEL (Red Hat Enterprise Linux)
- SSSD (System Security Services Daemon )
Issue
Using Active Directory as an Identity Provider for SSSD, the RHEL client fails to set NFSv4 ACL for groups on files with following error message:
[root@]# nfs4_editfacl /mnt/nfsv4vol
## Editing NFSv4 ACL for directory: /mnt/nfsv4vol
A:fdg:aaa@bbb.com@xxx.yyy:rwaDxtTnNcCy
Failed setxattr operation: Invalid argument
Note: group name is aaa@bbb.com from AD LDAP and domain name is xxx.yyy.