Unable to disable Kerberos from a data LIF because the KDC is unreachable
Applies to
- ONTAP 9
- NFS
- Kerberos
Issue
The following error is received when trying to disable Kerberos from a data LIF:
cluster1::> vserver nfs kerberos interface disable -vserver-lif
Error: Failed to disable NFS Kerberos on LIF. Failed to delete the account associated with the Kerberos service principal name.Reason: SecD Error: server create fail join user auth.
SECD logs will show:
00000059.042931cb 0ef88989 Mon Jul 14 2025 14:51:44 -05:00 [kern_secd:info:12805] [ 0 ms] TCP connection to ip DNS_IP,port 88 failed: Network is unreachable.
00000059.042931cc 0ef88989 Mon Jul 14 2025 14:51:44 -05:00 [kern_secd:info:12805] **[ 0] FAILURE: Could not authenticaas'user@user@domain.local domain': Cannot contact any KDC for requested realm (KRB5_KDC_UNREACH)
