Deletion of machine account of the cifs server caused its ability to authenticate to the DC
Applies to
- ONTAP 9
- Active Directory
Issue
- Failure to authenticate against active directory when using an SVM for which the machine account has been removed from AD
- Multiple symptoms possible:
- Unable to create CIFS sessions for share access
- Domain based authentication fails for access to the CLI or System Manager
svm-01 ERROR secd.cifsAuth.problem: vserver (svm-01) General CIFS authentication problem. Error: Ontap admin cifs authentication basic procedure failed
- EMS:
[ 1042] Encountered NT error (NT_STATUS_AUTH_LOGON_FAILURE) for SMB command SessionSetup
[ 1042] Unable to connect to NetLogon service on xyz.abc.net (Error: RESULT_ERROR_SECD_NO_CONNECTIONS_AVAILABLE)
[ 1157] Successfully connected to ip 1.2.x.135, port 445 using TCP
[ 1290] Successfully connected to ip 1.3.x.167, port 88 using TCP
[ 1305] Unknown user (KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN)
[ 1305] Failed to initiate Kerberos authentication. Trying NTLM.
[ 1414] Encountered NT error (NT_STATUS_MORE_PROCESSING_REQUIRED) for SMB command SessionSetup
[ 1522] Encountered NT error (NT_STATUS_AUTH_LOGON_FAILURE) for SMB command SessionSetup
[ 1522] Unable to connect to NetLogon service on xyz.abc.net (Error: RESULT_ERROR_SECD_NO_CONNECTIONS_AVAILABLE)
[ 3525] TCP connection to ip 1.4.x.137, port 445 failed: Operation timed out.
[ 3525] Unable to connect to NetLogon service on xyz.abc.net (Error: RESULT_ERROR_SPINCLIENT_UNABLE_TO_RESOLVE_SERVER)
[ 5535] TCP connection to ip 129.103.17.139, port 445 failed: Operation timed out.
[ 5535] Unable to connect to NetLogon service on xyz.abc.net (Error: RESULT_ERROR_SPINCLIENT_UNABLE_TO_RESOLVE_SERVER)
[ 7552] TCP connection to ip 1.4.x.141, port 445 failed: Operation timed out.
[ 7552] Unable to connect to NetLogon service on 1.5.x.net (Error: RESULT_ERROR_SPINCLIENT_UNABLE_TO_RESOLVE_SERVER)
[ 9573] TCP connection to ip 1.6.x.180, port 445 failed: Operation timed out.
[ 9573] Unable to connect to NetLogon service on deerlahc03a.ad005.onehc.net (Error: RESULT_ERROR_SPINCLIENT_UNABLE_TO_RESOLVE_SERVER)
**[ 9573] FAILURE: Unable to make a connection (NetLogon:XYZ.ABC.NET)...[Please refer to secd log for more detail!]