Alert 2289 on DC "Client performed a SASL bind without signing"
Applies to
- ONTAP 9
- CIFS
- AD (DC/LDAP)
Issue
- Alerts are seen on the DC
The client performed a SASL (Negotiate/Kerveros/NTLM/Digest) LDAP bind without requesting signing (integrity verification), or performed a simple bimnd over clear text
- Secd Error:
ERR : Could not authenticate as 'USER@test': Cannot find KDC for requested realm (KRB5_REALM_UNKNOWN)