ONTAP is unable to authenticate CIFS users
Applies to
- ONTAP 9
- CIFS
Issue
- CIFS users are unable to connect to a share due to netlogon authentication failure with domain controller
- secd logs
info : Cannot contact any KDC for requested realm (KRB5_KDC_UNREACH)
Failed to initiate Kerberos authentication. Trying NTLM.
ERR : SMB2 response has NT error 0xc0000016 { in ParseSmb2HeaderResponse()
ERR : Encountered NT error (NT_STATUS_AUTH_LOGON_FAILURE) for SMB command SessionSetup
ERR : SMB2 response has NT error 0xc000006d
debug: Connected but failed to authenticate with DC <dc_name>
info : Unable to connect to LSA service on <dc_name>
- Wireshark Capture:
Microsoft Network Logon, NetrServerAuthenticate2 Return code: STATUS_ACCESS_DENIED (0xc0000022)
- secd logs