CIFS password reset fails with KDC unreachable error due to KDC timeouts
Applies to
- ONTAP 9
- CIFS
Issue
- CIFS password reset fails with error: KDC unreachable.
::> vserver cifs domain password reset -vserver VS1Enter your user ID: User1Enter your password:Error: command failed: Password update failed. Reason: Kerberos Error: KDC Unreachable.- EMS logs report following errors:
secd.kerberos.preauth: A Kerberos pre-authentication failure occurred for SVM "VS1" due to out-of-sync machine account password
"vserver cifs security show"command indicates that the Kerberos KDC timeout has been set to 3 seconds.
::> vserver cifs security showVserver: vs1Kerberos Clock Skew: 3 minutesKerberos Ticket Age: 8 hoursKerberos Renewal Age: 7 daysKerberos KDC Timeout: 3 seconds