Kerberos Authentication Fails Due to AES Encryption Reversion on Azure NetApp Files SVM
Applies to
AFF
AFF-A700S
9.18.1 CLUSTER-MODE
Issue
- Kerberos authentication for NFSv4.1 and/or SMB fails on an Azure NetApp Files Storage Virtual Machine (SVM). Clients are unable to access data, and authentication-related commands fail with Kerberos encryption errors.
- Common symptoms include:
- NFS mount operations hanging or failing when using sec=krb5*
- SMB access failures using Kerberos authentication
- LDAP or CIFS domain checks reporting authentication errors
- Failure when enabling Kerberos on an NFS LIF
- Observed error messages may include:
KDC has no support for encryption type (KRB5KDC_ERR_ETYPE_NOSUPP)
- Kerberos-related logs may show that only RC4 or DES encryption types are being negotiated, even though AES is required by Active Directory.
