<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: connection with kerberos authentication suddenly denide in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/connection-with-kerberos-authentication-suddenly-denide/m-p/443254#M42027</link>
    <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/73493"&gt;@Ontapforrum&lt;/a&gt;&amp;nbsp;Thank you again for your advice!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually I haven't set an ntp server for kerberos authentication at all. Because we didn't block internet in our studio, I thought it would be ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess the time set originally in ontap skewed ever since then.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After I set up the ntp server, everything is back to working!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Apr 2023 07:33:25 GMT</pubDate>
    <dc:creator>yb</dc:creator>
    <dc:date>2023-04-07T07:33:25Z</dc:date>
    <item>
      <title>connection with kerberos authentication suddenly denide</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/connection-with-kerberos-authentication-suddenly-denide/m-p/443233#M42024</link>
      <description>&lt;P&gt;I have a Freeipa server, that also runs LDAP and DNS. Our Ontap uses the information to verify kerberos user credential.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It has worked well for me 3 month or so.&lt;BR /&gt;&lt;BR /&gt;But today, all nfs clients using kerberos authentication denied to access to the ontap storage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found this error message that has raised since 1am today.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;secd.ldap.noServers: None of the LDAP servers configured for Vserver (vs1) are currently accessible via the network for LDAP service type (Service: LDAP (NIS &amp;amp; Name Mapping), Operation: GetUserInfoFromName).&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I believe they are related. Unfortunately, I don't know why it happened and how can I recover from it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From ssh shell in Ontap, I checked with this command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ldap check -vserver {vserver}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the very first time it gave me an error. I ran 'ldapsearch' from our Freeipa server and it raise "GSSAPI" error.&lt;/P&gt;&lt;P&gt;I ran 'kinit admin' on the idm server. After that 'ldapsearch' successfully returns ldap information, and 'ldap check' returns normal status again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But still got the above error once an hour. Still kerberos user cannot access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please give me some light. Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:51:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/connection-with-kerberos-authentication-suddenly-denide/m-p/443233#M42024</guid>
      <dc:creator>yb</dc:creator>
      <dc:date>2025-06-04T09:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: connection with kerberos authentication suddenly denide</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/connection-with-kerberos-authentication-suddenly-denide/m-p/443238#M42025</link>
      <description>&lt;P&gt;Could you check the following kbs, I don't know which one is relevant to your issue but as you said - it suddenly stopped so there must be something that has caused it. I am hoping the clock is in sync, b'cos Kerberos is time-sensitive. So ensure your NTP, FreeIPA client and Storage is within 5 mnt offset.&lt;BR /&gt;&lt;BR /&gt;Unable to authenticate to Cluster using FreeIPA LDAP:&lt;BR /&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/da/NAS/Unable_to_authenticate_to_Cluster_using_FreeIPA_LDAP" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/da/NAS/Unable_to_authenticate_to_Cluster_using_FreeIPA_LDAP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;secd.ldap.noServers: None of the LDAP servers configured for Vserver (vs1) are currently accessible via the network for LDAP service type&lt;BR /&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/da/NAS/secd.ldap.noServers%3A_None_of_the_LDAP_servers_configured_for_Vserver_seen_in_the_log#:~:text=Preferred%20LDAP%20servers%20are%20configured%20and%20reachable%20in,%28Service%3A%20LDAP%20%28NIS%20%26%20Name%20Mapping%29%2C%20Operation%3A%20MapNameWindowsToUnix%29" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/da/NAS/secd.ldap.noServers%3A_None_of_the_LDAP_servers_configured_for_Vserver_seen_in_the_log#:~:text=Preferred%20LDAP%20servers%20are%20configured%20and%20reachable%20in,%28Service%3A%20LDAP%20%28NIS%20%26%20Name%20Mapping%29%2C%20Operation%3A%20MapNameWindowsToUnix%29&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;secd.ldap.noServers messages every 4 hours during domain discovery&lt;BR /&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/da/NAS/secd.ldap.noServers_messages_every_4_hours_during_domain_discovery" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/da/NAS/secd.ldap.noServers_messages_every_4_hours_during_domain_discovery&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"secd.ldap.noServers" in EMS when using SSL/TLS&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/onprem/ontap/da/NAS/%22secd.ldap.noServers%22_in_EMS_when_using_SSL%2F%2F%2F%2FTLS" target="_blank"&gt;https://kb.netapp.com/onprem/ontap/da/NAS/%22secd.ldap.noServers%22_in_EMS_when_using_SSL%2F%2F%2F%2FTLS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://whyistheinternetbroken.wordpress.com/2020/03/24/nfs-kerberos-ontap-freeipa/" target="_blank"&gt;https://whyistheinternetbroken.wordpress.com/2020/03/24/nfs-kerberos-ontap-freeipa/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 14:25:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/connection-with-kerberos-authentication-suddenly-denide/m-p/443238#M42025</guid>
      <dc:creator>Ontapforrum</dc:creator>
      <dc:date>2023-04-06T14:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: connection with kerberos authentication suddenly denide</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/connection-with-kerberos-authentication-suddenly-denide/m-p/443254#M42027</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/73493"&gt;@Ontapforrum&lt;/a&gt;&amp;nbsp;Thank you again for your advice!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually I haven't set an ntp server for kerberos authentication at all. Because we didn't block internet in our studio, I thought it would be ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess the time set originally in ontap skewed ever since then.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After I set up the ntp server, everything is back to working!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 07:33:25 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/connection-with-kerberos-authentication-suddenly-denide/m-p/443254#M42027</guid>
      <dc:creator>yb</dc:creator>
      <dc:date>2023-04-07T07:33:25Z</dc:date>
    </item>
  </channel>
</rss>

