<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kerberized NFS access from macOS Sierra to 8.2.4P6 7-Mode in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132921#M8828</link>
    <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't write the product docs but will pass this feedback on.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jul 2017 19:56:42 GMT</pubDate>
    <dc:creator>parisi</dc:creator>
    <dc:date>2017-07-19T19:56:42Z</dc:date>
    <item>
      <title>Kerberized NFS access from macOS Sierra to 8.2.4P6 7-Mode</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132794#M8819</link>
      <description>&lt;P&gt;We have a FAS 3220 filer, recently upgraded to 8.2.4P6 7-Mode. It is part of an Active Directory domain running at domain functional level Windows Server 2008 R2. We use the CIFS domain setup also for Kerberized NFS, but sadly this only gives us arcfour-hmac encryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have so far been unable to NFS mount from macOS Sierra 10.12.5. The reason for this is a lack of compatible encryption types between the three systems involved:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;macOS Sierra NFS RPCSEC_GSS now supports aes128-cts-hmac-sha1-96 and aes256-cts-hmac-sha1-96, as does Active Directory domain functional level Windows Server 2008 R2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the Active Directory server is still unwilling to issue AES tickets for this 8.2.4P6 7-Mode filer:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;linux-client$ kvno -e aes128-cts-hmac-sha1-96 nfs/filer.dept.cam.ac.uk@DOMAIN.DEPT.CAM.AC.UK&lt;BR /&gt;kvno: KDC has no support for encryption type while getting credentials for nfs/filer.dept.cam.ac.uk@DOMAIN.DEPT.CAM.AC.UK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It only issues tickets using the old arcfour-hmac encryption type, which is outdated and not supported by macOS NFS RPCSEC_GSS:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;linux-client$ klist -e&lt;/P&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;P&gt;14/07/17 09:16:28 14/07/17 19:16:28 nfs/filer.dept.cam.ac.uk@DOMAIN.DEPT.CAM.AC.UK&lt;BR /&gt;Etype (skey, tkt): arcfour-hmac, arcfour-hmac&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have already tried on the filer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;cifs terminate&lt;BR /&gt;[delete filer's Computers entry on Active Directory]&lt;BR /&gt;cifs setup&lt;BR /&gt;nfs setup&lt;/PRE&gt;&lt;P&gt;in order to make sure that the filer creates a fresh Kerberos key and related metadata on the Active Directory domain controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this still did not result in the AD KDC issuing AES session keys to the filer, which would be required for macOS Sierra NFS RPCSEC_GSS compatibility.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have noticed that when the filer creates during "cifs setup" a new server entry for itself on the domain controller, it does *not* set the attribute&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; msDS-SupportedEncryptionTypes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe it ought to set it to something like&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; msDS-SupportedEncryptionTypes = 28 = 0x1C =&amp;nbsp; RC4-HMAC | AES128-CTS-HMAC-SHA1-96 | AES256-CTS-HMAC-SHA1-96&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to tell the KDC what encryption types it supports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does 8.2.4P6 7-Mode support Kerberized NFS with AES encryption types?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is 8.2.4P6 7-Mode Kerberized NFS compatible with macOS Sierra in a Windows Server 2008 R2 domain?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 14:51:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132794#M8819</guid>
      <dc:creator>markus_kuhn</dc:creator>
      <dc:date>2025-06-04T14:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberized NFS access from macOS Sierra to 8.2.4P6 7-Mode</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132868#M8824</link>
      <description>&lt;P&gt;try this&amp;nbsp;kb?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://kb.netapp.com/support/s/article/ka31A0000000wP5QAI/how-to-set-up-kerberized-nfs-access-for-a-unix-client-in-an-active-directory-kdc" target="_blank"&gt;https://kb.netapp.com/support/s/article/ka31A0000000wP5QAI/how-to-set-up-kerberized-nfs-access-for-a-unix-client-in-an-active-directory-kdc&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jeff&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 07:07:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132868#M8824</guid>
      <dc:creator>Jeff_Yao</dc:creator>
      <dc:date>2017-07-18T07:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberized NFS access from macOS Sierra to 8.2.4P6 7-Mode</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132883#M8825</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;SPAN class="test-id__field-value slds-form-element__static slds-grow"&gt;That KB does not help: it merely demonstrates how to set up Kerberized NFS with&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;SPAN class="test-id__field-value slds-form-element__static slds-grow"&gt;the old "ArcFour with HMAC/md5&lt;/SPAN&gt;" encryption type. We have used this for many years from Linux.&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;However, &lt;SPAN class="test-id__field-value slds-form-element__static slds-grow"&gt;"ArcFour with HMAC/md5&lt;/SPAN&gt;" was never supported by Apple.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Since Apple disabled Single-DES in OS X Yosemite, the only Kerberos encryption types&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;compatible with both Active Directory and macOS Sierra have been 128-bit AES and 256-bit AES.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;AES is what we have not managed to get to work under 7-mode.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 14:20:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132883#M8825</guid>
      <dc:creator>markus_kuhn</dc:creator>
      <dc:date>2017-07-18T14:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberized NFS access from macOS Sierra to 8.2.4P6 7-Mode</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132889#M8826</link>
      <description>&lt;P&gt;There will be no AES support for 7-Mode. For AES, use ONTAP 8.3 or later.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 19:23:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132889#M8826</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2017-07-18T19:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberized NFS access from macOS Sierra to 8.2.4P6 7-Mode</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132899#M8827</link>
      <description>&lt;P&gt;Thanks for the clarification. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; In that case, you should probably review/revise&lt;/P&gt;&lt;P&gt;all mention of AES in the 7-mode documentation, for example in&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Data ONTAP® 8.2&lt;BR /&gt;&amp;nbsp; File Access and Protocols Management Guide&lt;BR /&gt;&amp;nbsp; For 7-Mode&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;A href="https://library.netapp.com/ecm/ecm_download_file/ECMP1401220" target="_blank"&gt;https://library.netapp.com/ecm/ecm_download_file/ECMP1401220&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the /etc/krb5.conf example file on page 30 the lines&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; default_tgs_enctypes = aes128-cts-hmac-sha1-96&lt;BR /&gt;&amp;nbsp; default_tkt_enctypes = aes128-cts-hmac-sha1-96&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and in the command-line examples on page 31 the use of the option&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; -e "aes128-cts-hmac-sha1-96:normal"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These examples (and feedback from a support contractor) had given&lt;/P&gt;&lt;P&gt;us hope that AES would be supported in 8.2 7-mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;None of the above options make sense if the server does not actually&lt;/P&gt;&lt;P&gt;support any AES encryption types. (In that case, their presence may&lt;/P&gt;&lt;P&gt;actually prevent NFS (RPCSEC_GSS) authentication from succeeding,&lt;/P&gt;&lt;P&gt;by restricting the enctype to one that the server doesn't implement.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 11:30:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132899#M8827</guid>
      <dc:creator>markus_kuhn</dc:creator>
      <dc:date>2017-07-19T11:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberized NFS access from macOS Sierra to 8.2.4P6 7-Mode</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132921#M8828</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't write the product docs but will pass this feedback on.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 19:56:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Kerberized-NFS-access-from-macOS-Sierra-to-8-2-4P6-7-Mode/m-p/132921#M8828</guid>
      <dc:creator>parisi</dc:creator>
      <dc:date>2017-07-19T19:56:42Z</dc:date>
    </item>
  </channel>
</rss>

