Skip to main content
NetApp Knowledge Base

ONTAP LDAP Authentication Fails with UNIX Identities Using Windows AD

Views:
85
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

Applies to

  • LDAP authentication with Windows Active Directory (AD) as LDAP server
  • UNIX identities for login (SSH, HTTP, ONTAP GUI)
  • ONTAP 9

Issue

ONTAP configures to use Windows AD as an LDAP server for UNIX identity authentication failed to allow users to log in via SSH or GUI, despite successful user lookups. The following symptoms and log messages were observed:

  • User lookup works, but login fails:
    ::*> getxxbyyy getpwbyname -node node-01 -vserver svm -username user1
    pw_name: user1
    pw_passwd:
    pw_uid: 432214
    pw_gid: 999
    pw_gecos: user1
    pw_dir: /users/user1
    pw_shell: /bin/bash
  • Event log shows authentication failure:
    ALERT security.invalid.login: Failed to authenticate login attempt to Vserver: svm, username: user1, application: http.BR
  • Security login entries exist but authentication fails:
    ::*> security login show -vserver svm -user-or-group-name user1
    Vserver: svm
    User/Group Name   Application   Authentication Method   Role Name
    --------------------------------------------------------------------------
    user1          http          nsswitch                admin
    user1          ontapi        nsswitch                admin
    user1          ssh           nsswitch                admin
  • In some cases, EMS logs show:
    [secd: secd.unexpectedFailure:error]: Unexpected SecD failure in Vserver "admin". Details: Error: LdapGetfulluserinfo procedure failed[0ms] No servers available for LDAP_NIS_AND_NAME_MAPPING, vserver:-1, domain:.

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.