Enabling Kerberos on a data LIF fails when using Red Hat Identity Management KDC
Applies to
- ONTAP 9
- Red Hat Identity Management (IdM)
- Key Distribution Center (KDC)
Issue
Error displayed after enabling NFS Kerberos on a data LIF:
Error: NFS Kerberos bind SPN procedure failed
[ 0 ms] Creating account in Unix KDC
[ 29] Successfully connected to ip 10.10.10.10, port 749 using
TCP
**[ 133] FAILURE: Unexpected state: Error 1142 at
** file:src/utils/secd_kadmin_utils.cpp
** func:createVifKrbAccountUsingKadmin line:227
**[ 133] FAILURE: spn already exists. Failed to reuse spn
** 'nfs/nfs/demo-ipa.centos-ldap.local@CENTOS-LDAP.LOCAL' using admin spn
** 'kadmin/admin@CENTOS-LDAP.LOCAL', error: Unknown code 0
[ 134] Uncaptured failure while creating account
Error: command failed: Failed to enable NFS Kerberos on LIF "demo-ipa".
Failed to bind service principal name on LIF "demo-ipa". cifs smb kadmin error.