Kerberos CIFS authentication fails for users with many groups
Applies to
- ONTAP 9
- CIFS/SMB
- Kerberos
Issue
- Users with a large number of groups are unable to connect to CIFS shares via FQDN (kerberos). Able to connect via IP (NTLMv2).
- EMS shows:
SECD.CIFSAUTH.PROBLEM:VSERVER General CIFS authentication problem. Error: User authentication procedure failed CIFS SMB2 Share mapping – Client IP = xxx.xxx.xxx.xxx (3 ms) Could not decode user claims information in Kerberos ticket.
- Windows Client shows:
A ticket to the service cifs/"DC Name"/"DomainName" is issued for account "AccountName"@"DomainName". The size of the encrypted part of this ticket is 22648 bytes, which is close or greater than the configured ticket size threshold (15000 bytes)