What is the impact of enabling AES for Kerberos in ONTAP
Applies to
- ONTAP 9
- Cloud Volumes ONTAP (CVO)
- Kerberos
- CIFS/SMB
Answer
- Enabling AES encryption changes the encryption methods used during new Kerberos authentication attempts
- There should be no detrimental impact if the Vserver is in a healthy state
- There will be no detrimental impact to CIFS clients that are currently connected to the SVM through existing CIFS sessions
Existing CIFS sessions are already authenticated, so there is no immediate need to perform a new authentication with the new encryption type
- Enabling AES encryption for a specific protocol (e.g. NFS) will not affect other protocols (e.g. CIFS)
