<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Max token size Kerberos in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Max-token-size-Kerberos/m-p/59793#M14025</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've got a customer who complains one of his users can't reach a series of vFilers anymore.&lt;/P&gt;&lt;P&gt;After searching for a possible cause, we stripped all memberships of Active Directory groups, for a particular server.&lt;/P&gt;&lt;P&gt;We added him to 1 Ad group. In this situation it is possible to reach the vfilers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We suspect that the Kerberos Token Size of this particular user is rather big due to extensive group nesting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a command I can issue to see the max token size setting for vFiler?&lt;/P&gt;&lt;P&gt;I read in &lt;BR /&gt;&lt;A href="https://kb.netapp.com/support/index?page=content&amp;amp;id=3012217" target="_blank"&gt;NetApp Knowledgebase - What is maximum Kerberos token size that Data ONTAP 7G can process?&lt;/A&gt;&lt;BR /&gt;that max token size is 12K but can be set to max 64K, the problem is I can't find where to set this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mentioned filers are still running on OnTap 7 versions so we are in the process of starting an upgrade project, but that will take a while.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jun 2025 06:10:04 GMT</pubDate>
    <dc:creator>PJRINZEMA</dc:creator>
    <dc:date>2025-06-05T06:10:04Z</dc:date>
    <item>
      <title>Max token size Kerberos</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Max-token-size-Kerberos/m-p/59793#M14025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've got a customer who complains one of his users can't reach a series of vFilers anymore.&lt;/P&gt;&lt;P&gt;After searching for a possible cause, we stripped all memberships of Active Directory groups, for a particular server.&lt;/P&gt;&lt;P&gt;We added him to 1 Ad group. In this situation it is possible to reach the vfilers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We suspect that the Kerberos Token Size of this particular user is rather big due to extensive group nesting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a command I can issue to see the max token size setting for vFiler?&lt;/P&gt;&lt;P&gt;I read in &lt;BR /&gt;&lt;A href="https://kb.netapp.com/support/index?page=content&amp;amp;id=3012217" target="_blank"&gt;NetApp Knowledgebase - What is maximum Kerberos token size that Data ONTAP 7G can process?&lt;/A&gt;&lt;BR /&gt;that max token size is 12K but can be set to max 64K, the problem is I can't find where to set this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mentioned filers are still running on OnTap 7 versions so we are in the process of starting an upgrade project, but that will take a while.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:10:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Max-token-size-Kerberos/m-p/59793#M14025</guid>
      <dc:creator>PJRINZEMA</dc:creator>
      <dc:date>2025-06-05T06:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Max token size Kerberos</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Max-token-size-Kerberos/m-p/59796#M14027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got a response from IBM support, thought I'd share&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM style="color: red; font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;"I'm not aware of any settings which can be done on the filer.&lt;BR /&gt; I assume you refer to the kb-id3012217 for the limits.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt; &lt;A href="https://kb.netapp.com/support/index?page=content&amp;amp;id=3012217" target="_blank"&gt;https://kb.netapp.com/support/index?page=content&amp;amp;id=3012217&lt;/A&gt;.&lt;BR /&gt; . &lt;BR /&gt; This confirms the filer can handle up to 64K in 7-mode, so any changes&amp;nbsp; &lt;BR /&gt; from default 12k on client needs to be done on client and not on the filer"&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM style="color: red; font-size: 12.0pt; font-family: 'Times New Roman','serif';"&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2013 12:38:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Max-token-size-Kerberos/m-p/59796#M14027</guid>
      <dc:creator>PJRINZEMA</dc:creator>
      <dc:date>2013-02-18T12:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Max token size Kerberos</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Max-token-size-Kerberos/m-p/59801#M14031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are encountering this problem with our ClusterMode NetApp environment.&amp;nbsp; The issue doesn't seem to be limited to tokens that are very big or very small but rather "OF SPECIFIC SIZES".&amp;nbsp;&amp;nbsp; Adding or removing groups can reset the token resolving the issue OR recreating the issue for an individual client.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;A href="http://support.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=677927" target="_blank"&gt;http://support.netapp.com/NOW/cgi-bin/bol?Type=Detail&amp;amp;Display=677927&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far the only way to detect the problem is by the user complaining about lack of connectivity.&amp;nbsp;&amp;nbsp; There are no logs that can be monitored to identify which users are encountering the issue.&amp;nbsp; If fact we had to run a workstation wireshark trace to actually capture the kerberos failure to identify the problem.&amp;nbsp;&amp;nbsp; This is a user specific problem so if follows the user around from machine to machine.&amp;nbsp; No registry or GPO fix can be applied at the AD group level. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Considering we have thousands of clients attempting to attach to this NAS,&amp;nbsp; domain membership chainging mulitiple times a day and no way to forever fix the problem this bug is preventing us from moving forward with additional migrations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Apr 2013 15:13:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Max-token-size-Kerberos/m-p/59801#M14031</guid>
      <dc:creator>EVILUTION</dc:creator>
      <dc:date>2013-04-25T15:13:49Z</dc:date>
    </item>
  </channel>
</rss>

