<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CDOT and Kerberos in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-and-Kerberos/m-p/154725#M34730</link>
    <description>&lt;P&gt;Uhh, thanks,&amp;nbsp;&lt;SPAN&gt;Mjizzini, but &amp;nbsp;I already have a working Kerberos config. &amp;nbsp;I'm asking about the&amp;nbsp;possibility of&amp;nbsp;configuring&amp;nbsp;in a "secondary" KDC server in an Active Directory environment (since they would effectively be the same trust "zone").&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Mar 2020 15:55:55 GMT</pubDate>
    <dc:creator>Brett_Monroe</dc:creator>
    <dc:date>2020-03-04T15:55:55Z</dc:date>
    <item>
      <title>CDOT and Kerberos</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-and-Kerberos/m-p/154704#M34721</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems that, when setting up a Kerberos realm in CDOT, in the case where the KDC is really Active Directory, I can not include a second(ary) Domain Controller into the realm as a potential failover. &amp;nbsp;Am I mistaken or is this not really a concern?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;--Brett&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 11:17:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-and-Kerberos/m-p/154704#M34721</guid>
      <dc:creator>Brett_Monroe</dc:creator>
      <dc:date>2025-06-04T11:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: CDOT and Kerberos</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-and-Kerberos/m-p/154708#M34724</link>
      <description>&lt;P&gt;Configuring a Kerberos Realm&lt;BR /&gt;A Kerberos realm is needed so that the cluster knows how to format Kerberos ticket requests. Doing so is similar to configuring /etc/krb5.conf on NFS clients.&lt;BR /&gt;To create a Kerberos realm, use the following example as a guide for the command to run on the SVM hosting the NFS server:&lt;/P&gt;
&lt;DIV class="page" title="Page 17"&gt;
&lt;DIV class="section"&gt;
&lt;DIV class="layoutArea"&gt;
&lt;DIV class="column"&gt;
&lt;P&gt;&lt;SPAN&gt;cluster::&amp;gt; kerberos-realm create -configname REALM -realm DOMAIN.xxxxx.COM -kdc-vendor Microsoft -kdc-ip x.x.x.x -kdc-port 88 -clock-skew 5 -adminserver-ip x.x.x.x -adminserver-port 749 -passwordserver-ip x.x.x.x -passwordserver-port 464 -adserver-name WIN2K8-DC -adserver- ip x.x.x.x&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;BR /&gt;Note: The IP addresses specified in the Kerberos-realm commands are used only during creation of the machine account object or SPN; &lt;BR /&gt;these IP addresses are not used for actual Kerberized NFS traffic. Therefore, there is no need to worry about failover or DNS aliases for these commands. &lt;BR /&gt;KDC failover for Kerberized traffic is handled using DNS SRV records. For more information, see the section “Domain Controller Redundancy and Replication.”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Referencing tr-4073 "&amp;nbsp;&lt;SPAN style="font-family: inherit;"&gt;Secure Unified Authentication"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.netapp.com/us/media/tr-4073.pdf" target="_blank"&gt;https://www.netapp.com/us/media/tr-4073.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 04:31:10 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-and-Kerberos/m-p/154708#M34724</guid>
      <dc:creator>Mjizzini</dc:creator>
      <dc:date>2020-03-04T04:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: CDOT and Kerberos</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-and-Kerberos/m-p/154725#M34730</link>
      <description>&lt;P&gt;Uhh, thanks,&amp;nbsp;&lt;SPAN&gt;Mjizzini, but &amp;nbsp;I already have a working Kerberos config. &amp;nbsp;I'm asking about the&amp;nbsp;possibility of&amp;nbsp;configuring&amp;nbsp;in a "secondary" KDC server in an Active Directory environment (since they would effectively be the same trust "zone").&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 15:55:55 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-and-Kerberos/m-p/154725#M34730</guid>
      <dc:creator>Brett_Monroe</dc:creator>
      <dc:date>2020-03-04T15:55:55Z</dc:date>
    </item>
  </channel>
</rss>

