Skip to main content
NetApp Knowledge Base

ONTAP System Manager and SSH using domain authentication extremely slow due to suboptimal domain controller selection

Views:
23
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

Applies to

  • Ontap 9
  • Domain tunnel authentication
  • Environments using Active Directory (AD) for authentication

Issue

  • Significant slowness experienced when logging into ONTAP System Manager (GUI) and via SSH using Active Directory (AD) domain accounts
  • Local account access works normally 

Secd logs : 

[kern_secd:info:13058] .------------------------------------------------------------------------------.
[kern_secd:info:13058] |                              RPC TOOK TOO LONG:                              |
[kern_secd:info:13058] |                       RPC used 24 seconds (max is 23)                        |
[kern_secd:info:13058] |                   and likely caused the client to timeout                    |
[kern_secd:info:13058] .------------------------------------------------------------------------------.
[kern_secd:info:13058] |                                 RPC SUCCESS:                                 |
[kern_secd:info:13058] |              secd_rpc_ontap_admin_cifs_auth_basic has succeeded              |
[kern_secd:info:13058] |                          Result = 0, RPC Result = 0                          |
[kern_secd:info:13058] |                   RPC received at Tue Jun 16 18:40:13 2026                   |
[kern_secd:info:13058] |------------------------------------------------------------------------------'
[kern_secd:info:13058] | [000.000.010]  debug:  Worker Thread 34510793472 processing RPC 155:secd_rpc_ontap_admin_cifs_auth_basic(caller: MGMT_PAM) with request ID:65063 which sat in the queue for 0 seconds.  { in run() at src/server/secd_rpc_server.cpp:2477 }
[kern_secd:info:13058] | [000.000.020]  debug:  Setting thread context. VServerId = 3 (name='SVM1'), Protocol = CIFS, lifId = 0  { in setThreadContext() at src/utils/secd_thread_data_manager.cpp:415 }
[kern_secd:info:13058] | [000.000.027]  debug:  secd_rpc_ontap_admin_cifs_auth_basic_1_svc called with vserver = SVM1, domain = hxxp, user = 4XX2-8X  { in secd_rpc_ontap_admin_cifs_auth_basic_1_svc_secd() at src/authentication/secd_rpc_auth.cpp:2151 }
[kern_secd:info:13058] | [000.000.043]  debug:  netbiosName = SVM1 domainName = hxxp realmName = hxxp.AD.HXXC  { in tryKerberosAuthentication() at src/authentication/secd_rpc_auth.cpp:1972 }
[kern_secd:info:13058] | [000.000.047]  debug:  userName = 4XX2-8X, joinUserPrincipal = 4XX2-8X@hxxp.AD.HXXC  { in tryKerberosAuthentication() at src/authentication/secd_rpc_auth.cpp:2011 }
.
[kern_secd:info:13058] | [011.052.829]  ERR  :  Could not authenticate as '4XX2-8X@hxxp.AD.HXXC': Cannot contact any KDC for requested realm (KRB5_KDC_UNREACH) { in doKerberosAuthForUser() at src/utils/secd_krb_utils.cpp:251 }
[kern_secd:info:13058] | [011.052.881]  info :  Kerberos authentication failed. Trying NTLM { in secd_rpc_ontap_admin_cifs_auth_basic_1_svc_secd() at src/authentication/secd_rpc_auth.cpp:2162 }
[kern_secd:info:13058] | [011.052.940]  info :  Login attempt by domain user 'hxxp\4XX2-8X' using NTLMv2 style security
[kern_secd:info:13058] | [011.052.955]  debug:  Looking for NetLogon cache (key: "hxxp.AD.HXXC") in vserver 3  { in getConnectionCache() at src/connection_manager/secd_connection_cache.cpp:702 }
.
[kern_secd:info:13058] | [023.668.976]  debug:  Connected to new NetLogon service on gXX33.hxxp.AD.HXXC  { in makeConnectionAttempt() at src/connection_manager/secd_connection_manager.cpp:1060 }
[kern_secd:info:13058] | [023.669.073]  debug:  Attempting pass-through auth with DC GXX33.  { in doAuthenticateWithDC() at src/authentication/secd_seclibglue.cpp:1118 }
[kern_secd:info:13058] | [024.056.193]  info :  User 'hxxp\4XX2-8X' authenticated using NTLMv2 security { in journalAuthenticationSummary() at src/authentication/secd_rpc_auth.cpp:374 }
[kern_secd:info:13058] | [024.056.219]  debug:  Admin authentication succeeded with NTLM  { in secd_rpc_ontap_admin_cifs_auth_basic_1_svc_secd() at src/authentication/secd_rpc_auth.cpp:2193 }
[kern_secd:info:13058] | [024.056.224]  debug:  SecD RPC Server sending reply to RPC 155: secd_rpc_ontap_admin_cifs_auth_basic  { in secdSendRpcResponse() at src/server/secd_rpc_server.cpp:2289 }
[kern_secd:info:13058] |------------------------------------------------------------------------------.
[kern_secd:info:13058] |                  RPC completed at Tue Jun 16 18:40:37 2026                   |
[kern_secd:info:13058] |      End of log for succeeded RPC secd_rpc_ontap_admin_cifs_auth_basic       |
[kern_secd:info:13058] '------------------------------------------------------------------------------'

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.