CIFS AES enable fails when machine account is missing
Applies to
- ONTAP 9
- CIFS/SMB Protocol
- Advanced Encryption Standard (AES) encryption
Issue
- Enabling CIFS AES encryption on one SVM requests AD domain credentials:
cluster01::> vserver cifs security modify -vserver svm_cifs01 -is-aes-encryption-enabled trueInfo: In order to enable CIFS AES encryption, the password for the CIFS server machine account must be reset. Enter the username and password for the CIFS domain "EXAMPLE.COM".Enter your user ID: domain_adminEnter your password:Error: command failed: Password update failed. Reason: SecD Error:machine account does not exist.- The same setting can be modified on other SVMs without requesting domain credentials.
- AutoSupport data shows all discovered domain controllers as unavailable for the affected SVM.
Example:
node01 svm_cifs01 example.com MS-DC dc01 adequate 192.0.2.10 unavailable UNKNOWN false
node01 svm_cifs01 example.com MS-DC dc02 adequate 192.0.2.11 unavailable UNKNOWN false
