Skip to main content
NetApp Knowledge Base

SVM is unable to join Windows 2012 domain using LDAPS (Unable to start TLS)

Views:
842
Visibility:
Public
Votes:
0
Category:
data-ontap-8
Specialty:
nas
Last Updated:

Applies to

Data ONTAP 8.X CIFS

Issue

  • After upgrading the user domain to Windows 2012 and installing new certificates, clustered Data ONTAP SVMs are unable to join the AD domain using LDAPS.
  • Similar error messages appear as a result of creating the CIFS server over the SVM:

    [ 107] Unable to start TLS: Connect error
    [ 107] Additional info: TLS: unable to get CN from peer certificate
    **[ 109] FAILURE: Failed to find a domain controller Error: command failed: Failed to create the Active Directory machine account "XXXXXX".
    Reason: LDAP Error: Cannot establish a connection to the server.

  • Collecting packet traces shows that the certificate negotiated from the server (the Windows 2012) has an empty subject field while the CN information is stored in the SubjectAlternateName (SAN) field.
        Use the example trace below to help determine if you are experiencing this issue.
        Select the Server Hello packet and look for the following clues:
  1. In the Certificate () field, note that there is nothing between the parenthesis. This is because Wireshark cannot find anything within the Subject field
  2. The Subject field has 0 items listed
  3. The name of the LDAP server shows up under the extensions fields, specifically the subjectAltName field

                                       Cert.png

 

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.
Scan to view the article on your device