CIFS Kerberos outage after modifying msDS-SupportedEncryptionTypes with AD Attribute Editor
Applies to
- ONTAP 9
- CIFS/SMB
- Kerberos
- Active Directory
Issue
- Used Active Directory Attribute Editor to change CIFS server's machine account's attribute
msDS-SupportedEncryptionTypesto a value (e.g.30) that indicates AES is enabled - Afterwards, CIFS clients that navigate to
\\hostnamecannot access data because Kerberos authentication fails - CIFS clients that navigate to
\\1.2.3.4can access data because NTLM authentication succeeds cifs sec show -fields adverindicates that that AES encryption is not enabled in ONTAP
