Skip to main content
NetApp Knowledge Base

Should SPNs per data SVM be added to the cluster machine account for Kerberos?

Views:
56
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

Applies to

  • ONTAP 9
  • Kerberos
  • CIFS
  • NFS

Answer

No, each storage virtual machine (SVM) must have its own machine account in the Kerberos Realm. Multiple SVMs cannot own the same machine account.

Note: However, outside of this scenario, multiple SPNs can be added to a single machine/computer account

Example:

VMware NFS and Kerberos: Add multiple SPNs matching the FQDN of each NFS LIF for an SVM to be able to target which LIF to mount from and still mount with Kerberos authentication.

Additional Information

 

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.