Clients using NTLM when Kerberos is expected in ONTAP
Applies to
- ONTAP 9 (all versions)
- CIFS / SMB
- Windows Active Directory with Kerberos authentication
- AFF / FAS systems
Issue
Clients are using authentication style NTLM when Kerberos is expected. This includes the following scenarios:
- A client-side packet trace shows
KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN - Windows clients receive access failures after Group Policy Object (GPO) is configured to block NTLM and enforce Kerberos authentication
kliston the Windows client shows no Kerberos ticket is obtained for the CIFS server- Event Viewer logs NTLM fallback blocked or Kerberos negotiation failure events for the NetApp CIFS server
- Network drive mappings continue failing even after SPN-related GPO changes are applied
