2014-02-26 02:21 PM
I'm working on a new workflow for cDOT using "Setup CIFS service" command. I've encountered several errors (bad login, errors in some fields...) but right now I'm getting this one : Failed to create the Active Directory machine account "TESTWFA7". Reason: Kerberos Error: Unknown error.
If I do the cifs setup manually (with CLI) it works fine.
Anybody could give me some hints ? I don't know where I should look for. I would like to get some other logs than "Unknown error"
Thanks a lot for your help !
Solved! SEE THE SOLUTION
2014-02-26 06:33 PM
What version of WFA are you using?
Can you send me the logs.
Navigate to administration>LogViewer.
Attach the server.log file here.
Also, can you tell me the exact steps you followed to set it up manually from the CLI?
2014-02-27 02:27 AM
The version is : 18.104.22.168.4RC1
Please find the serverlog enclosed. My last test was with a SVM called TestWFA11. So, the Service CIFS setup failed with the kerberos error. I tried to setup the cifs service with CLI and System Manager on that SVM: It works perfectly.
On CLI :
|cOT-demofr::vserver cifs> create -vserver TestWFA11 -cifs-server TestWFA11 -domain demofr.netapp.fr -ou CN=Computers -default-site "DEMOFR Paris"|
2014-02-27 03:19 AM
Have you made sure the requirements for the command have been met before executing the command?
1. DNS should be configured properly for this command to succeed. The cluster or Storage Virtual Machine should be able to ping the domain FQDN.
2. WFA credentials should be created for the FQDN of the domain. These credentials need to be of a domain user that has the ability to add the CIFS server configured on the Storage Virtual Machine to the target organizational unit.
2014-02-27 03:30 AM
1) The cluster and the SVM are able to ping the domain FQDN (I guess with CLI and System Manager this requirement is the same)
2) I'm logged on WFA console with the same admin domain user used with CLI to setup the CIFS. The account is the same.
2014-02-27 08:50 AM
Below is the screenshot of how it should be. Does your AD Credential looking similar in WFA?