<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vserver active-directory create RPC timeouts in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/vserver-active-directory-create-RPC-timeouts/m-p/139582#M30820</link>
    <description>&lt;P&gt;The answer to this appears to have been to create the vserver with the "-ns-switch ldap" flag via CLI.&amp;nbsp; I had&amp;nbsp;previously created the&amp;nbsp;vserver from the GUI and this setting defaulted to NIS, which explains why the account was added to AD but OnTap was unable to recieve the acknowledgement of success, and thus timed out. &amp;nbsp;I never had this problem doing the same with OnTap 9+.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't understand the ins and outs of why this worked, but&amp;nbsp;AD authentication for cluster admins works&amp;nbsp;great now and CIFS is still&amp;nbsp;unlicensed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hopefully someone finds this helpful someday!&amp;nbsp; Cheers&lt;/P&gt;</description>
    <pubDate>Sat, 14 Apr 2018 00:22:29 GMT</pubDate>
    <dc:creator>BenCoughtry</dc:creator>
    <dc:date>2018-04-14T00:22:29Z</dc:date>
    <item>
      <title>vserver active-directory create RPC timeouts</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/vserver-active-directory-create-RPC-timeouts/m-p/139069#M30695</link>
      <description>&lt;P&gt;Hi all, I I'm trying to setup an AD connection in order to domain authenticate cluster admins and I have 2x CDOT 8.2.2 clusters which&amp;nbsp;time out when on the command 'vserver active-directory create'.&amp;nbsp; CIFS is not licensed so I cannot use a CIFS vserver.&amp;nbsp;&amp;nbsp;The commands I'm using (below) work perfectly on other clusters running newer versions of OnTap (9.1 or 9.2).&amp;nbsp; Since the&amp;nbsp;same commands exist on 8.2.2 I'm assuming this&amp;nbsp;is supposed to work, but not sure what the problem is.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After I run the command, AD logs confirm the connection without errors and in fact show the new account in the Computers OU.&amp;nbsp; If I run the command a second time OnTap tells me that the account already exists and asks if I want to reuse it, but then upon&amp;nbsp;answering YES the command still times again with the same error.&amp;nbsp; Thus, I know the cluster is talking to&amp;nbsp;the&amp;nbsp;local domain controller and I don't know why it is failing.&amp;nbsp; Any advice would be appreciated - thanks!&amp;nbsp; See CLI output below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;san901-cluster::&amp;gt; domain-tunnel show&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; (security login domain-tunnel show)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Tunnel Vserver: ldap_svm&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;san901-cluster::&amp;gt; vserver active-directory create -vserver ldap_svm -domain xxx.xxxx -account-name san901-cluster&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;In order to create an Active Directory machine account, you must supply the name and password of a Windows account with sufficient privileges to add computers to the "CN=Computers" container within the&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;"xxxx" domain.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Enter the user name: xxxxx&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Enter the password:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Warning: An account by this name already exists in Active Directory at CN=SAN901-CLUSTER,CN=Computers,DC=xxx,DC=xxxx&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt; Ok to reuse this account? {y|n}: y&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Error: command failed: Failed to create the Active Directory machine account "SAN901-CLUSTER". Reason: ad_machine_account_create: RPC: Timed out; ct = 0x826104800 rem_addr = 127.0.0.1:655.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;san901-cluster::&amp;gt; vserver active-directory show&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;This table is currently empty.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 13:53:41 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/vserver-active-directory-create-RPC-timeouts/m-p/139069#M30695</guid>
      <dc:creator>BenCoughtry</dc:creator>
      <dc:date>2025-06-04T13:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: vserver active-directory create RPC timeouts</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/vserver-active-directory-create-RPC-timeouts/m-p/139582#M30820</link>
      <description>&lt;P&gt;The answer to this appears to have been to create the vserver with the "-ns-switch ldap" flag via CLI.&amp;nbsp; I had&amp;nbsp;previously created the&amp;nbsp;vserver from the GUI and this setting defaulted to NIS, which explains why the account was added to AD but OnTap was unable to recieve the acknowledgement of success, and thus timed out. &amp;nbsp;I never had this problem doing the same with OnTap 9+.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't understand the ins and outs of why this worked, but&amp;nbsp;AD authentication for cluster admins works&amp;nbsp;great now and CIFS is still&amp;nbsp;unlicensed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hopefully someone finds this helpful someday!&amp;nbsp; Cheers&lt;/P&gt;</description>
      <pubDate>Sat, 14 Apr 2018 00:22:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/vserver-active-directory-create-RPC-timeouts/m-p/139582#M30820</guid>
      <dc:creator>BenCoughtry</dc:creator>
      <dc:date>2018-04-14T00:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: vserver active-directory create RPC timeouts</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/vserver-active-directory-create-RPC-timeouts/m-p/139750#M30875</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Refer KB&amp;nbsp;&lt;A href="https://kb.netapp.com/app/answers/answer_view/a_id/1027853/loc/en_US" target="_blank"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1027853/loc/en_US&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 04:48:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/vserver-active-directory-create-RPC-timeouts/m-p/139750#M30875</guid>
      <dc:creator>Sahana</dc:creator>
      <dc:date>2018-04-23T04:48:35Z</dc:date>
    </item>
  </channel>
</rss>

