Why is kerberos not being used when connecting to a CIFS server by IP?
Applies to
- ONTAP
- Service Principal Name (SPN)
- Storage Virtual Machine (SVM)
- Active Directory (AD)
- Kerberos
Answer
- To use Kerberos, the client has to obtain a Kerberos ticket based on the SPN (Service Principal Name) for the SVMs machine account in Active Directory.
- As the SPN is based on the server name, a Kerberos ticket cannot (normally) be obtained if connecting by IP.
- Beginning with Windows 10 version 1507 and Windows Server 2016, Kerb clients can be configured to support IPv4 and IPv6 hostnames in SPNs
- External link (Microsoft Learn) - configuring-kerberos-over-ip
Additional Information
You can use e.g. ADSI Edit to find the servicePrincipalName property for the machine account.
