<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SVM unable to join CIFS to Windows Server 2003 AD in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/SVM-unable-to-join-CIFS-to-Windows-Server-2003-AD/m-p/457990#M44588</link>
    <description>&lt;P&gt;Thanks for getting back liu. However, AES isn't supported in Windows Server 2003, which is why i disabled it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As Netapp Ontap only supports DES , therefore I have configured “SupportedEncType” to 3 in Windows Registry to support&amp;nbsp;DES-CBC-MD5 and DES-CBC-CRC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’ve checked Secd.log , &amp;nbsp;Windows event logs and found that DES encryption is successfully reflected during Netapp SVM CIFS attempt to join Windows server 2003. I am also unable to join my Netapp Ontap Network LIFS to Windows server 2003 active directory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the secd.log , I found the message&amp;nbsp;“&lt;STRONG&gt;master kdc tgs request result -1765328370 kdc has no support for encryption type”.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’ve also configured the below settings for “CIFS Security” before attempting to join my SVM to Windows Server 2003 Directory.&lt;BR /&gt;&lt;BR /&gt;-Disabled SMB Signing for &lt;SPAN&gt;incoming SMB&lt;/SPAN&gt; Traffic&lt;/P&gt;&lt;P&gt;-Disabled Use start-TLS for AD LDAP&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Disabled AES Encryption&amp;nbsp;&lt;/P&gt;&lt;P&gt;-LM compatibility level :&amp;nbsp;ntlm-ntlmv2-krb&lt;/P&gt;&lt;P&gt;-Enabled SMB1 (Due to Windows server 2003 supporting only SMB1)&lt;/P&gt;&lt;P&gt;-Is-aes-encryption-enabled :False&lt;/P&gt;&lt;P&gt;-session-security-for-ad-ldap : None&lt;/P&gt;&lt;P&gt;-smb1-enabled-for-dc-connections : True&lt;/P&gt;&lt;P&gt;-smb2-enabled-for-dc-connections : False&lt;/P&gt;&lt;P&gt;-referral-enabled-for-ad-ldap : False&lt;/P&gt;&lt;P&gt;-use-ldaps-for-ad-ldap : False&lt;/P&gt;&lt;P&gt;-encryption-required-for-dc-connections: False&lt;/P&gt;&lt;P&gt;-aes-enabled-for-netlogon-channel : False&lt;/P&gt;&lt;P&gt;-try-channel-binding-for-ad-ldap : False&lt;/P&gt;&lt;P&gt;-advertised-enc-types : DES&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any settings that I have missed out on or misconfigured? I have tried all possible configurations in NetApp Ontap and Windows server 2003 side and it does not work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried configuring Windows Keytab and SVM realm too but it doesn't work.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jan 2025 03:01:08 GMT</pubDate>
    <dc:creator>jeffrey24</dc:creator>
    <dc:date>2025-01-23T03:01:08Z</dc:date>
    <item>
      <title>SVM unable to join CIFS to Windows Server 2003 AD</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SVM-unable-to-join-CIFS-to-Windows-Server-2003-AD/m-p/457419#M44414</link>
      <description>&lt;P&gt;Dear all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been facing Netapp Ontap Storage VM issues of joining CIFS to Windows server 2003 AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am on Netapp ontap 9.14.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that Windows Server 2003 cannot support AES and can only support&amp;nbsp; SMB1 authentication. Therefore disabled AES 128 and 256 under:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-vserver cifs security modify :&amp;nbsp;&lt;SPAN&gt;-advertised-enc-types {DES,RC4}&lt;BR /&gt;--aes-enabled-for-netlogon-channel{false}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--encryption-required-for-dc-connections {false}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-use-ldaps-for-ad-ldap {false}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-smb2-enabled-for-dc-connections{false}&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-smb1-enabled-for-dc-connections{true}&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I managed to add the Windows server 2003 DNS to my SVM. Despite trying all methods, I am still getting the error KRB5KDC_ERR_ETYPE_NOSUPP when i add my SVM CIFS to Windows server 2003 active directory. Will appreciate any help on this, thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Jeff&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 09:22:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SVM-unable-to-join-CIFS-to-Windows-Server-2003-AD/m-p/457419#M44414</guid>
      <dc:creator>jeffrey24</dc:creator>
      <dc:date>2024-12-17T09:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: SVM unable to join CIFS to Windows Server 2003 AD</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SVM-unable-to-join-CIFS-to-Windows-Server-2003-AD/m-p/457432#M44418</link>
      <description>&lt;P&gt;Usually in this kind of problem secd.log can provide more information on what is going on&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure there is a way to have it working&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 15:35:28 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SVM-unable-to-join-CIFS-to-Windows-Server-2003-AD/m-p/457432#M44418</guid>
      <dc:creator>CristianoRossi</dc:creator>
      <dc:date>2024-12-17T15:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: SVM unable to join CIFS to Windows Server 2003 AD</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SVM-unable-to-join-CIFS-to-Windows-Server-2003-AD/m-p/457450#M44422</link>
      <description>&lt;P&gt;&lt;SPAN&gt;AES is not enabled on the Vserver&amp;nbsp;&amp;nbsp;&lt;A href="https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/CIFS_authentication_error__KRB5KDC_ERR_ETYPE_NOSUPP" target="_blank"&gt;CIFS authentication error: KRB5KDC_ERR_ETYPE_NOSUPP - NetApp Knowledge Base&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Check the Windows/UNIX KDC&amp;nbsp; configuration, If the error is noticed during the filer cifs setup, then the machine account for the server name specified is inconsistent and it needs to be reset at Windows KDC&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/Kerberos_EMS_error_descriptions" target="_blank"&gt;Kerberos EMS error descriptions - NetApp Knowledge Base&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 06:37:36 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SVM-unable-to-join-CIFS-to-Windows-Server-2003-AD/m-p/457450#M44422</guid>
      <dc:creator>liu</dc:creator>
      <dc:date>2024-12-18T06:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: SVM unable to join CIFS to Windows Server 2003 AD</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/SVM-unable-to-join-CIFS-to-Windows-Server-2003-AD/m-p/457990#M44588</link>
      <description>&lt;P&gt;Thanks for getting back liu. However, AES isn't supported in Windows Server 2003, which is why i disabled it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As Netapp Ontap only supports DES , therefore I have configured “SupportedEncType” to 3 in Windows Registry to support&amp;nbsp;DES-CBC-MD5 and DES-CBC-CRC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’ve checked Secd.log , &amp;nbsp;Windows event logs and found that DES encryption is successfully reflected during Netapp SVM CIFS attempt to join Windows server 2003. I am also unable to join my Netapp Ontap Network LIFS to Windows server 2003 active directory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the secd.log , I found the message&amp;nbsp;“&lt;STRONG&gt;master kdc tgs request result -1765328370 kdc has no support for encryption type”.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’ve also configured the below settings for “CIFS Security” before attempting to join my SVM to Windows Server 2003 Directory.&lt;BR /&gt;&lt;BR /&gt;-Disabled SMB Signing for &lt;SPAN&gt;incoming SMB&lt;/SPAN&gt; Traffic&lt;/P&gt;&lt;P&gt;-Disabled Use start-TLS for AD LDAP&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Disabled AES Encryption&amp;nbsp;&lt;/P&gt;&lt;P&gt;-LM compatibility level :&amp;nbsp;ntlm-ntlmv2-krb&lt;/P&gt;&lt;P&gt;-Enabled SMB1 (Due to Windows server 2003 supporting only SMB1)&lt;/P&gt;&lt;P&gt;-Is-aes-encryption-enabled :False&lt;/P&gt;&lt;P&gt;-session-security-for-ad-ldap : None&lt;/P&gt;&lt;P&gt;-smb1-enabled-for-dc-connections : True&lt;/P&gt;&lt;P&gt;-smb2-enabled-for-dc-connections : False&lt;/P&gt;&lt;P&gt;-referral-enabled-for-ad-ldap : False&lt;/P&gt;&lt;P&gt;-use-ldaps-for-ad-ldap : False&lt;/P&gt;&lt;P&gt;-encryption-required-for-dc-connections: False&lt;/P&gt;&lt;P&gt;-aes-enabled-for-netlogon-channel : False&lt;/P&gt;&lt;P&gt;-try-channel-binding-for-ad-ldap : False&lt;/P&gt;&lt;P&gt;-advertised-enc-types : DES&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any settings that I have missed out on or misconfigured? I have tried all possible configurations in NetApp Ontap and Windows server 2003 side and it does not work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried configuring Windows Keytab and SVM realm too but it doesn't work.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 03:01:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/SVM-unable-to-join-CIFS-to-Windows-Server-2003-AD/m-p/457990#M44588</guid>
      <dc:creator>jeffrey24</dc:creator>
      <dc:date>2025-01-23T03:01:08Z</dc:date>
    </item>
  </channel>
</rss>

