vserver nfs kerberos interface enable disable commands fail with krb5 realm mismatch
Applies to
- ONTAP
- NFS
- Kerberos
- Active Directory
Issue
vserver nfs kerberos interface enable
anddisable
fail with cifs smb krb5 realm mismatch- vserver nfs kerberos realm and CIFS domain are a match
Example:
cluster1::> vserver nfs kerberos interface enable -lif svm1_cifs_nfs_lif1 -vserver svm1 -spn nfs/host1.domain.local@DOMAIN.LOCAL
Username: administrator@domain.local
Password:
Error: NFS Kerberos bind SPN procedure failed
**[ 1] FAILURE: Unexpected state: Error 1138 at
** file:src/nfs_kerberos/secd_nfs_krbkey.cpp
** func:secd_rpc_nfs_krb_bind_spn_1_svc_secd line:562
**[ 1] FAILURE: Uncaptured failure while creating account
Error: command failed: Failed to enable NFS Kerberos on LIF "svm1_cifs_nfs_lif1". Failed to bind service principal name on LIF "svm1_cifs_nfs_lif1". cifs smb krb5 realm mismatch.