<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active directory SID translation slow in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Active-directory-SID-translation-slow/m-p/108592#M22473</link>
    <description>&lt;P&gt;I have two sites both with different clustermode (6210 and 8060) hardware but on the same domain.&amp;nbsp;&amp;nbsp; These FAS clusters house our company SHARE and HOME drives.&amp;nbsp;&amp;nbsp;&amp;nbsp;Over&amp;nbsp;the last 6 months SID resolution&amp;nbsp;has been&amp;nbsp;getting slower&amp;nbsp;to now what I would consider&amp;nbsp;painfully slow for some security groups.&amp;nbsp;&amp;nbsp; Via windows&amp;nbsp;file explorer it sometimes takes 5 minutes to resolve the sids.&amp;nbsp; Manually trying to resolve sometimes fails&amp;nbsp;but if I wait a minute or two it will then resolve.&amp;nbsp; We have increased the size of the&amp;nbsp;cache dedicated to holding the SIDs 5x with no effect.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NETAPP: diag secd authentication translate -node DIX-NETAPP-01 -vserver DIX-P-INFNAS-01 -sid S-1-5-21-2019431095-1834360568-1243820751-149394&lt;/P&gt;&lt;P&gt;Error: command failed: RPC call to SecD failed. RPC: "secd_rpc_auth_sid_to_name_1".&amp;nbsp; Reason: "translateSidToName: RPC: Timed out; ct = 0x827c16b40 rem_addr = 127.0.0.1:670".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NETAPP::*&amp;gt; diag secd authentication translate -node DIX-NETAPP-01 -vserver DIX-P-INFNAS-01 -sid S-1-5-21-2019431095-1834360568-1243820751-149394&lt;BR /&gt;SHOESD01\NAS_FULLCTRL_LL (Domain group)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else run into something similar?&amp;nbsp; I have been considering flushing the cache but I'm not sure doing that on a production server is a good idea.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Aug 2015 15:19:14 GMT</pubDate>
    <dc:creator>EVILUTION</dc:creator>
    <dc:date>2015-08-13T15:19:14Z</dc:date>
    <item>
      <title>Active directory SID translation slow</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Active-directory-SID-translation-slow/m-p/108592#M22473</link>
      <description>&lt;P&gt;I have two sites both with different clustermode (6210 and 8060) hardware but on the same domain.&amp;nbsp;&amp;nbsp; These FAS clusters house our company SHARE and HOME drives.&amp;nbsp;&amp;nbsp;&amp;nbsp;Over&amp;nbsp;the last 6 months SID resolution&amp;nbsp;has been&amp;nbsp;getting slower&amp;nbsp;to now what I would consider&amp;nbsp;painfully slow for some security groups.&amp;nbsp;&amp;nbsp; Via windows&amp;nbsp;file explorer it sometimes takes 5 minutes to resolve the sids.&amp;nbsp; Manually trying to resolve sometimes fails&amp;nbsp;but if I wait a minute or two it will then resolve.&amp;nbsp; We have increased the size of the&amp;nbsp;cache dedicated to holding the SIDs 5x with no effect.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NETAPP: diag secd authentication translate -node DIX-NETAPP-01 -vserver DIX-P-INFNAS-01 -sid S-1-5-21-2019431095-1834360568-1243820751-149394&lt;/P&gt;&lt;P&gt;Error: command failed: RPC call to SecD failed. RPC: "secd_rpc_auth_sid_to_name_1".&amp;nbsp; Reason: "translateSidToName: RPC: Timed out; ct = 0x827c16b40 rem_addr = 127.0.0.1:670".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NETAPP::*&amp;gt; diag secd authentication translate -node DIX-NETAPP-01 -vserver DIX-P-INFNAS-01 -sid S-1-5-21-2019431095-1834360568-1243820751-149394&lt;BR /&gt;SHOESD01\NAS_FULLCTRL_LL (Domain group)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else run into something similar?&amp;nbsp; I have been considering flushing the cache but I'm not sure doing that on a production server is a good idea.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2015 15:19:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Active-directory-SID-translation-slow/m-p/108592#M22473</guid>
      <dc:creator>EVILUTION</dc:creator>
      <dc:date>2015-08-13T15:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Active directory SID translation slow</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Active-directory-SID-translation-slow/m-p/132289#M28837</link>
      <description>I am experiencing the same. Seems to coincide around the same time we ran our wannacry patches and making SMB changes to our Windows servers.</description>
      <pubDate>Tue, 27 Jun 2017 21:21:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Active-directory-SID-translation-slow/m-p/132289#M28837</guid>
      <dc:creator>Tvoyce</dc:creator>
      <dc:date>2017-06-27T21:21:04Z</dc:date>
    </item>
  </channel>
</rss>

