<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic It seems that RC4 doesn't work for CIFS connections in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/It-seems-that-RC4-doesn-t-work-for-CIFS-connections/m-p/442765#M41956</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We have FAS8040 with ONTAP 9.5 with a CIFS server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It has the following security settings:&lt;/P&gt;&lt;P&gt;Vserver: SVM_CIFS&lt;/P&gt;&lt;P&gt;Kerberos Clock Skew: 5 minutes&lt;BR /&gt;Kerberos Ticket Age: 10 hours&lt;BR /&gt;Kerberos Renewal Age: 7 days&lt;BR /&gt;Kerberos KDC Timeout: 3 seconds&lt;BR /&gt;Is Signing Required: false&lt;BR /&gt;Is Password Complexity Required: true&lt;BR /&gt;Use start_tls for AD LDAP connection: false&lt;BR /&gt;Is AES Encryption Enabled: false&lt;BR /&gt;LM Compatibility Level: lm-ntlm-ntlmv2-krb&lt;BR /&gt;Is SMB Encryption Required: false&lt;BR /&gt;Client Session Security: -&lt;BR /&gt;SMB1 Enabled for DC Connections: system-default&lt;BR /&gt;SMB2 Enabled for DC Connections: system-default&lt;BR /&gt;LDAP Referral Enabled For AD LDAP connections: false&lt;BR /&gt;Use LDAPS for AD LDAP connection: false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After we've changed&amp;nbsp;msDS-SupportedEncryptionTypes of SVM_CIFS in AD from 6 to 28 authentification via Kerberos ceased to work. I can see from the settings that AES is not enables but as far as I understood, RC4 is enabled always.&lt;/P&gt;&lt;P&gt;Taking into account that RC4 is present in 6 and 28 and it works with 6 but not with 28 I can make a conclusion that only DES can be used by NetApp in our case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any explanations why it could happen? Any ideas on how to debug it?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;msDS-SupportedEncryptionTypes:&lt;BR /&gt;6 (DES_CBC_MD5 | RC4_HMAC_MD5)&lt;BR /&gt;28 (RC4_HMAC_MD5 | AES128_CTS_HMAC_SHA1_96 | AES256_CTS_HMAC_SHA1_96)&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 09:51:23 GMT</pubDate>
    <dc:creator>AlexeyF</dc:creator>
    <dc:date>2025-06-04T09:51:23Z</dc:date>
    <item>
      <title>It seems that RC4 doesn't work for CIFS connections</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/It-seems-that-RC4-doesn-t-work-for-CIFS-connections/m-p/442765#M41956</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We have FAS8040 with ONTAP 9.5 with a CIFS server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It has the following security settings:&lt;/P&gt;&lt;P&gt;Vserver: SVM_CIFS&lt;/P&gt;&lt;P&gt;Kerberos Clock Skew: 5 minutes&lt;BR /&gt;Kerberos Ticket Age: 10 hours&lt;BR /&gt;Kerberos Renewal Age: 7 days&lt;BR /&gt;Kerberos KDC Timeout: 3 seconds&lt;BR /&gt;Is Signing Required: false&lt;BR /&gt;Is Password Complexity Required: true&lt;BR /&gt;Use start_tls for AD LDAP connection: false&lt;BR /&gt;Is AES Encryption Enabled: false&lt;BR /&gt;LM Compatibility Level: lm-ntlm-ntlmv2-krb&lt;BR /&gt;Is SMB Encryption Required: false&lt;BR /&gt;Client Session Security: -&lt;BR /&gt;SMB1 Enabled for DC Connections: system-default&lt;BR /&gt;SMB2 Enabled for DC Connections: system-default&lt;BR /&gt;LDAP Referral Enabled For AD LDAP connections: false&lt;BR /&gt;Use LDAPS for AD LDAP connection: false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After we've changed&amp;nbsp;msDS-SupportedEncryptionTypes of SVM_CIFS in AD from 6 to 28 authentification via Kerberos ceased to work. I can see from the settings that AES is not enables but as far as I understood, RC4 is enabled always.&lt;/P&gt;&lt;P&gt;Taking into account that RC4 is present in 6 and 28 and it works with 6 but not with 28 I can make a conclusion that only DES can be used by NetApp in our case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any explanations why it could happen? Any ideas on how to debug it?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;msDS-SupportedEncryptionTypes:&lt;BR /&gt;6 (DES_CBC_MD5 | RC4_HMAC_MD5)&lt;BR /&gt;28 (RC4_HMAC_MD5 | AES128_CTS_HMAC_SHA1_96 | AES256_CTS_HMAC_SHA1_96)&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:51:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/It-seems-that-RC4-doesn-t-work-for-CIFS-connections/m-p/442765#M41956</guid>
      <dc:creator>AlexeyF</dc:creator>
      <dc:date>2025-06-04T09:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: It seems that RC4 doesn't work for CIFS connections</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/It-seems-that-RC4-doesn-t-work-for-CIFS-connections/m-p/442771#M41958</link>
      <description>&lt;P&gt;Different protocols have their own method of interaction with Kerberos services, hence all encryption types &lt;EM&gt;are not mutually supported&lt;/EM&gt; across protocols. As a best practice, AES should be used by default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What Kerberos Encryption Types are&lt;STRONG&gt; supported&lt;/STRONG&gt; with NAS protocols for &lt;STRONG&gt;ONTAP 9&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/What_Kerberos_Encryption_Types_are_supported_with_NAS_protocols_for_ONTAP_9" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/What_Kerberos_Encryption_Types_are_supported_with_NAS_protocols_for_ONTAP_9&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the impact of setting is-aes-encryption-enabled to TRUE?&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/What_is_the_impact_of_setting_is-aes-encryption-enabled_to_TRUE" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/What_is_the_impact_of_setting_is-aes-encryption-enabled_to_TRUE&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 20:50:17 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/It-seems-that-RC4-doesn-t-work-for-CIFS-connections/m-p/442771#M41958</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-03-24T20:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: It seems that RC4 doesn't work for CIFS connections</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/It-seems-that-RC4-doesn-t-work-for-CIFS-connections/m-p/442783#M41965</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/73493"&gt;@Ontapforrum&lt;/a&gt;&amp;nbsp;thanks for the link !&lt;/P&gt;&lt;P&gt;I'm surprised to find out that RC4 is not in the list of supported algorithms.&amp;nbsp;&lt;/P&gt;&lt;P&gt;because of this KB I understood that it was used for Kerberos authentication &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Can_RC4_encryption_for_Kerberos-based_communication_be_disabled" target="_blank"&gt;Can RC4 encryption for Kerberos-based communication be disabled - NetApp Knowledge Base&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 10:09:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/It-seems-that-RC4-doesn-t-work-for-CIFS-connections/m-p/442783#M41965</guid>
      <dc:creator>AlexeyF</dc:creator>
      <dc:date>2023-03-27T10:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: It seems that RC4 doesn't work for CIFS connections</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/It-seems-that-RC4-doesn-t-work-for-CIFS-connections/m-p/442789#M41966</link>
      <description>&lt;P&gt;Yes, that kb can be confusing due to its wording. In any case, I think due to number of vulnerabilities associated with RC4 Ciphers, NetApp strongly recommends AES.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 10:37:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/It-seems-that-RC4-doesn-t-work-for-CIFS-connections/m-p/442789#M41966</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-03-27T10:37:58Z</dc:date>
    </item>
  </channel>
</rss>

