CIFS password change fails silently leading to secd: secd.kerberos.preauth:error after Microsoft April 2022 Hotfixes
Applies to
- ONTAP 9
- ONTAP 9.10.1P2 and earlier
- ONTAP 9.9.1P8 and earlier
- ONTAP 9.8P11 and earlier
- ONTAP 9.7P18 and earlier
- ONTAP 9.6P17 and earlier
cifs domain password schedule
enabled- CIFS
- Kerberos
- Active Directory
- CVE-2021-42287
Issue
- When the
vserver cifs domain password schedule
is enabled, it silently failsevent log show
indicates the followingSat Apr 16 03:00:00 +0800 [cluster1-01: secd: secd.kerberos.preauth:error]: Kerberos pre-authentication failure due to out-of-sync machine account password for vserver (svm1).
- CIFS client access fails with
secd.log
errorKRB5KDC_ERR_PREAUTH_FAILED