secd.kerberos.preauth errors due to unreachable LDAP servers
Applies to
- ONTAP 9
- LDAP client
Issue
- Warning event in EMS
secd.kerberos.preauth: A Kerberos pre-authentication failure occurred for SVM "svm1" due to invalid credentials for SVM1$@DOMAIN.LOCAL.
secd.conn.auth.failure: Vserver (svm1) could not authenticate over the network to server (ldap01). Error: Can't contact LDAP server (Service: LDAP (NIS & Name Mapping), Operation: Check LDAP Config).
- SecD logs
info : TCP connection to ip 10.20.30.122, port 636 failed: Connection refused. { in _connect() at src/connection_manager/secd_connection_shim.cpp:594 }
- Packet trace
10.20.30.123 → 10.20.30.122 TCP 74 60655 → 636 [SYN] Seq=0 Win=65535 Len=0 MSS=1460 WS=256 SACK_PERM TSval=1868178423 TSecr=0
10.20.30.122 → 10.20.30.123 TCP 54 636 → 60655 [RST, ACK] Seq=1 Ack=1 Win=0 Len=0