<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NFS authentication problem in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/NFS-authentication-problem/m-p/460287#M44906</link>
    <description>&lt;P&gt;&lt;SPAN class=""&gt;My NetApp (FAS2720 running ONTAP 9.13.1P8) is receiving this authetication error roughly every two hours. I think, but I haven't yet been able to confirm, that the request is coming from a Solaris system. It looks like, under the hood, the NetApp is mapping its *NIX login to a Windows user for the purpose of domain authentication and that it's getting most of the way there but then failing at the end (bold text).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Does anyone know how to resolve this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the error text (personal info redacted):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Severity: LOG_ERR&lt;BR /&gt;&lt;BR /&gt;Message: secd.nfsAuth.noCifsCred: vserver (svmfile01) NFS authorization&lt;BR /&gt;cannot retrieve CIFS credentials. Error: Get user credentials procedure failed&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; 0 ms] Determined UNIX id 65534 is UNIX user 'pcuser'&lt;BR /&gt;&lt;/SPAN&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 25] UNIX user 'pcuser' mapped to Windows user 'EXAMPLE\guest'&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 26] Successfully connected to ip 192.168.1.5, port 445 using TCP&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 32] Successfully authenticated with DC dc1.example.com&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 41] Encountered NT error (NT_STATUS_PENDING) for SMB command Read&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 45] Found Windows name 'EXAMPLE\guest'&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 49] Successfully connected to ip 10.1.1.5, port 88 using TCP&lt;BR /&gt;&lt;STRONG&gt;**[&amp;nbsp; &amp;nbsp; 59] FAILURE: Could not get credentials via S4U2Self based on full Windows&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;STRONG&gt;user name 'guest@EXAMPLE.COM'. Access denied.&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 59] Could not get credentials for Windows user 'guest' or SID&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;STRONG&gt;'[SID]'&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Description: This message occurs when an NFS authorization attempt fails because&lt;BR /&gt;of the inability of the system to retrieve a matching CIFS credential for use in&lt;BR /&gt;multi-protocol security operations.&lt;BR /&gt;&lt;BR /&gt;Action: Examine the failure details to determine corrective action. This failure&lt;BR /&gt;usually occurs because the system is unable to communicate with Active&lt;BR /&gt;Directory.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Apr 2025 16:15:57 GMT</pubDate>
    <dc:creator>HUX20002000</dc:creator>
    <dc:date>2025-04-23T16:15:57Z</dc:date>
    <item>
      <title>NFS authentication problem</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFS-authentication-problem/m-p/460287#M44906</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;My NetApp (FAS2720 running ONTAP 9.13.1P8) is receiving this authetication error roughly every two hours. I think, but I haven't yet been able to confirm, that the request is coming from a Solaris system. It looks like, under the hood, the NetApp is mapping its *NIX login to a Windows user for the purpose of domain authentication and that it's getting most of the way there but then failing at the end (bold text).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Does anyone know how to resolve this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the error text (personal info redacted):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Severity: LOG_ERR&lt;BR /&gt;&lt;BR /&gt;Message: secd.nfsAuth.noCifsCred: vserver (svmfile01) NFS authorization&lt;BR /&gt;cannot retrieve CIFS credentials. Error: Get user credentials procedure failed&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; 0 ms] Determined UNIX id 65534 is UNIX user 'pcuser'&lt;BR /&gt;&lt;/SPAN&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 25] UNIX user 'pcuser' mapped to Windows user 'EXAMPLE\guest'&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 26] Successfully connected to ip 192.168.1.5, port 445 using TCP&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 32] Successfully authenticated with DC dc1.example.com&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 41] Encountered NT error (NT_STATUS_PENDING) for SMB command Read&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 45] Found Windows name 'EXAMPLE\guest'&lt;BR /&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 49] Successfully connected to ip 10.1.1.5, port 88 using TCP&lt;BR /&gt;&lt;STRONG&gt;**[&amp;nbsp; &amp;nbsp; 59] FAILURE: Could not get credentials via S4U2Self based on full Windows&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;STRONG&gt;user name 'guest@EXAMPLE.COM'. Access denied.&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&amp;nbsp; [&amp;nbsp; &amp;nbsp; 59] Could not get credentials for Windows user 'guest' or SID&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;STRONG&gt;'[SID]'&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Description: This message occurs when an NFS authorization attempt fails because&lt;BR /&gt;of the inability of the system to retrieve a matching CIFS credential for use in&lt;BR /&gt;multi-protocol security operations.&lt;BR /&gt;&lt;BR /&gt;Action: Examine the failure details to determine corrective action. This failure&lt;BR /&gt;usually occurs because the system is unable to communicate with Active&lt;BR /&gt;Directory.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 16:15:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFS-authentication-problem/m-p/460287#M44906</guid>
      <dc:creator>HUX20002000</dc:creator>
      <dc:date>2025-04-23T16:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: NFS authentication problem</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFS-authentication-problem/m-p/460299#M44907</link>
      <description>&lt;P&gt;hello:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;Use the command `vserver export-policy check-access -vserver &amp;lt;vserver&amp;gt; -volume &amp;lt;volume&amp;gt; -client-ip &amp;lt;clientIP&amp;gt; -auth &amp;lt;auth_type&amp;gt; -proto &amp;lt;proto&amp;gt; -access-type &amp;lt;type&amp;gt;` to check if there is an export rule that allows the client to obtain access rights. This link can help you quickly troubleshoot the problem.&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb-cn.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/secd_nfsAuth_noCifsCred_error_when_accessing_an_NTFS_secured_volume_via_NFS_in_ONTAP" target="_blank" rel="noopener"&gt;https://kb-cn.netapp.com/on-prem/ontap/da/NAS/NAS-KBs/secd_nfsAuth_noCifsCred_error_when_accessing_an_NTFS_secured_volume_via_NFS_in_ONTAP&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2025 06:06:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFS-authentication-problem/m-p/460299#M44907</guid>
      <dc:creator>chenguanghui</dc:creator>
      <dc:date>2025-04-24T06:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: NFS authentication problem</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/NFS-authentication-problem/m-p/460313#M44911</link>
      <description>&lt;P&gt;A few things here...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- If the UNIX user attempting access is 65534 on the client, then that translates to the default UNIX user pcuser, which will not map to a valid Windows user in most cases&lt;/P&gt;&lt;P&gt;- The UNIX user 65534 can sometimes be a case of the export policy rule squashing root access to anonymous. Check your rules to see how they handle root. If you want root to be root, set superuser to "any."&lt;/P&gt;&lt;P&gt;- If this happens every two hours, there's likely a scheduled job running. The client IP address should be in the error being sent, so check the client for what it is doing.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2025 15:28:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/NFS-authentication-problem/m-p/460313#M44911</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2025-04-24T15:28:08Z</dc:date>
    </item>
  </channel>
</rss>

