RPC accept GSS token procedure failed (Decrypt integrity check failed)
Applies to
- ONTAP 9
- NFS
- Kerberos
Issue
- EMS:
Sat Jun 01 23:48:16 +0200 [node-01: secd: secd.nfsAuth.problem:error]: vserver (svm1) General NFS authorization problem. Error: RPC accept GSS token procedure failed [ 0 ms] Using the NFS service credential for logical interface 1048 (SPN='nfs/svm1.domain.com@DOMAIN.COM') from cache. **[ 0] FAILURE: Failed to accept the context: Unspecified GSS failure. Minor code may provide more information (minor: Decrypt integrity check failed).
- Packet traces revealed a single client sending continuously RPSEC_GSS_INIT trying to authenticate to the NFS server
74 2022-05-11 11:26:08.327805 xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx NFS RPCSEC_GSS_INIT V4 NULL Call
75 2022-05-11 11:26:08.328866 xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx NFS V4 NULL Reply
- The reply from the server contains the errors as seen in the EMS logs
Frame 75:
...
Network File System
[Program Version: 4]
[V4 Procedure: NULL (0)]
GSS Context
GSS Major Status: 851968
GSS Minor Status: 2529638943
GSS Sequence Window: 128
GSS Token: 00000000