<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIFS server can't join AD in Simulator Discussions</title>
    <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/134917#M2239</link>
    <description>&lt;P&gt;Unfortunately the options &lt;STRONG&gt;-smb1-enable-for-dc-connections&lt;/STRONG&gt; and &lt;STRONG&gt;-smb2-enabled-for-dc-connections&lt;/STRONG&gt; are not available on the version I use (NetApp Release 8.3.1P2)&lt;/P&gt;</description>
    <pubDate>Mon, 02 Oct 2017 09:32:03 GMT</pubDate>
    <dc:creator>SjorsH</dc:creator>
    <dc:date>2017-10-02T09:32:03Z</dc:date>
    <item>
      <title>CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107594#M1598</link>
      <description>&lt;P&gt;I know this has probably been answered somewhere...but I can't find it. &amp;nbsp;I'm new to NetApp and though this simulator would be a great way to learn since our company is considering their solutions. &amp;nbsp;I have the initial cluster setup, aggregate, subnet, and vserver. &amp;nbsp;but when I try to create the CIFS server and join it to my lab DC, I get this error about the LSA service&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Data ONTAP API Failed :Failed to create the Active Directory machine account "CIFS". Reason: SecD Error: no server available Details: Error: Machine account creation procedure failed [ 105] Loaded the preliminary configuration. [ 121] Created a machine account in the domain [ 121] Connecting to LSA server netappdc.netapp.loc (192.168.111.5) [ 123] Cluster and Domain Controller times differ by more than the configured clock skew (KRB5KRB_AP_ERR_TKT_NYV) [ 123] Failed to initiate Kerberos authentication. Trying NTLM. [ 124] Successfully authenticated with DC netappdc.netapp.loc **[ 125&lt;FONT color="#000000"&gt;]&lt;STRONG&gt; FAILURE: Unable to connect to LSA service on&lt;/STRONG&gt; *&lt;/FONT&gt;* netappdc.netapp.loc (Error: ** RESULT_ERROR_CIFS_SMB_ACCESS_DENIED) [ 125] No servers available for MS_LSA, vserver: 3, domain: netapp.loc. [ 125] Could not find Windows SID 'S-1-5-21-3619059543-1436041144-4270238130-512' [ 128] Deleted existing account 'CN=CIFS,CN=Computers,DC=netapp,DC=loc' . (Error: 13001)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any help is seriously appreciated...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2015 05:53:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107594#M1598</guid>
      <dc:creator>ddrougeau</dc:creator>
      <dc:date>2015-07-23T05:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107595#M1599</link>
      <description>You need to synchronize time between servers that are part of Windows domain (actually, Kerberos realm). It has really nothing to do with NetApp.</description>
      <pubDate>Thu, 23 Jul 2015 06:05:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107595#M1599</guid>
      <dc:creator>aborzenkov</dc:creator>
      <dc:date>2015-07-23T06:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107596#M1600</link>
      <description>Thanks for responding. I only have one server and it's the DC so there isn't anything to sync on the windows side. The cluster is showing the correct time, but the time zone is etc/utc which isn't correct since I'm in Seattle. When I change the time zone to US/Pacific on system manager, the time is off by several hours.</description>
      <pubDate>Thu, 23 Jul 2015 06:32:38 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107596#M1600</guid>
      <dc:creator>ddrougeau</dc:creator>
      <dc:date>2015-07-23T06:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107597#M1601</link>
      <description>NetApp is just a server from Windows point of view and must have correct time that match domain controller.</description>
      <pubDate>Thu, 23 Jul 2015 08:10:40 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107597#M1601</guid>
      <dc:creator>aborzenkov</dc:creator>
      <dc:date>2015-07-23T08:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107598#M1602</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you tried setting your timezone to closest city to you listed in the link below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="https://library.netapp.com/ecmdocs/ECMP1368852/html/GUID-48AD434D-433B-4208-8D9E-C3696707E20C.html" href="https://library.netapp.com/ecmdocs/ECMP1368852/html/GUID-48AD434D-433B-4208-8D9E-C3696707E20C.html" target="_blank"&gt;https://library.netapp.com/ecmdocs/ECMP1368852/html/GUID-48AD434D-433B-4208-8D9E-C3696707E20C.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before you can join the vserver to the domain you first need to set the date\time and timezone to ensure the systems time is within 5 minutes of your domain controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To check the time on your DC you can use the net time command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\&amp;gt;net time \\testdc01&lt;BR /&gt;Current time at \\testdc01 is 23/07/2015 6:26:37 PM&lt;BR /&gt;&lt;BR /&gt;The command completed successfully.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then set the date on your cluster:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cluster1&amp;gt; system date modify -dateandtime 201507231826.48&lt;/P&gt;&lt;P&gt;cluster1&amp;gt; system date show&lt;BR /&gt;Node&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Date&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Time zone&lt;BR /&gt;--------- ------------------------- -------------------------&lt;BR /&gt;node1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7/23/2015 18:26:53 +10:00 Australia/Sydney&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Then set your timezone&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;cluster1&amp;gt; timezone America/Vancouver&lt;BR /&gt;1 entry modified&lt;BR /&gt;&lt;BR /&gt;cluster1&amp;gt; system date show&lt;BR /&gt;Node&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Date&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Time zone&lt;BR /&gt;--------- ------------------------- -------------------------&lt;BR /&gt;node1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7/23/2015 01:27:12 -07:00 America/Vancouver&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also it's worth mentioning that you will need to enter credentials of an Active Directory user account during the cifs setup process that has permissions in Active Directory to create the computer object and join the vserver to the domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The minimum required Active Directory permissions for computer objects in your organizational unit are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="http://support.microsoft.com/kb/932455" href="http://support.microsoft.com/kb/932455" target="_blank"&gt;http://support.microsoft.com/kb/932455&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create Computer Objects&lt;/P&gt;&lt;P&gt;Reset Password&lt;/P&gt;&lt;P&gt;Read and write Account Restrictions&lt;/P&gt;&lt;P&gt;Validated write to DNS host name&lt;/P&gt;&lt;P&gt;Validated write to service principal name&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/matt&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2015 08:39:38 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107598#M1602</guid>
      <dc:creator>mbeattie</dc:creator>
      <dc:date>2015-07-23T08:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107603#M1603</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;you first need to set the date\time and timezone to ensure the systems time is within 5 minutes of your domain controller&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Time zone is irrelevant; but quite a lot of people confuse computer time with wall clock time. This is true only as long as time zones are set identically indeed. All servers must have the same time when converted to UTC. IOW if server A is 3 hours east of Greenwich and has time 7pm and server B is 3 hours west of Greenwich and has time 1pm then both servers actually have the &lt;STRONG&gt;same&lt;/STRONG&gt; time (4pm UTC time). Of course if someone now tries to "correct" time on server B by setting it to 7pm it becomes totally wrong.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2015 09:14:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107603#M1603</guid>
      <dc:creator>aborzenkov</dc:creator>
      <dc:date>2015-07-23T09:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107622#M1604</link>
      <description>&lt;P&gt;if this is simulator have a look at the Time Settings on the ESXi host and then ssh to the ESXI host and run the date command and verify they are the same. If the are different the simulator is most liley picking up the incorrect time.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2015 13:49:25 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107622#M1604</guid>
      <dc:creator>RPHELANIN</dc:creator>
      <dc:date>2015-07-23T13:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107633#M1605</link>
      <description>&lt;P&gt;Thanks mbeattie and everyone for the responses. &amp;nbsp;Once I changed the timezone/time it joined the domain immediately. &amp;nbsp;I'm new to Data ONTAP CLI so I was missing the syntax for this. &amp;nbsp;Interestingly I had to change the zone first, then the time or it would throw the time off by 7 hours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-duane&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2015 15:26:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107633#M1605</guid>
      <dc:creator>ddrougeau</dc:creator>
      <dc:date>2015-07-23T15:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107637#M1606</link>
      <description>&lt;P&gt;I guess it all makes sense. &amp;nbsp;UTC to the simulator is my desktop system's time so changing the time zone on the cluster was in reference to my system time...throwing it off several hours.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2015 16:20:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/107637#M1606</guid>
      <dc:creator>ddrougeau</dc:creator>
      <dc:date>2015-07-23T16:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/132501#M2173</link>
      <description>&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;If you have disabled SMBv1 on your domain controllers&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;you need to make sure you have your SVM set to use SMB2 for Domain Controller Connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We disabled SMBv1 across the organisation in order to prevent any potential issues with the recent ransomeware exploits of SMBv1 (Petya and WannaCry)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Run the following command sets the SVM to use SMB2 and disable SMB1, and you will be able to join the AD domain with SMBv1 disabled on the domain controller.&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;(you must be in advanced privelege mode to run this command [set advanced])&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cifs security modify -vserver &amp;lt;SVM-Name&amp;gt; -smb1-enabled-for-dc-connections false -smb2-enabled-for-dc-connections true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this saves someone else the several hours i spent pulling my hair out today trying to resolve.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 08:34:20 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/132501#M2173</guid>
      <dc:creator>BradStoltzTA</dc:creator>
      <dc:date>2017-07-05T08:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/134689#M2231</link>
      <description>&lt;P&gt;Wow - thank you! &amp;nbsp;I've been messing with this issue for a while now.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2017 17:10:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/134689#M2231</guid>
      <dc:creator>DCGozer</dc:creator>
      <dc:date>2017-09-22T17:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/134917#M2239</link>
      <description>&lt;P&gt;Unfortunately the options &lt;STRONG&gt;-smb1-enable-for-dc-connections&lt;/STRONG&gt; and &lt;STRONG&gt;-smb2-enabled-for-dc-connections&lt;/STRONG&gt; are not available on the version I use (NetApp Release 8.3.1P2)&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 09:32:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/134917#M2239</guid>
      <dc:creator>SjorsH</dc:creator>
      <dc:date>2017-10-02T09:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: CIFS server can't join AD</title>
      <link>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/141649#M2363</link>
      <description>&lt;P&gt;Thanks.. this solved my problems.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As Windows AD 2016 seems to have SMB1 disabled by default our customer got alot of problems after updating the AD servers..&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/60935"&gt;@BradStoltzTA&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;If you have disabled SMBv1 on your domain controllers&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;you need to make sure you have your SVM set to use SMB2 for Domain Controller Connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We disabled SMBv1 across the organisation in order to prevent any potential issues with the recent ransomeware exploits of SMBv1 (Petya and WannaCry)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Run the following command sets the SVM to use SMB2 and disable SMB1, and you will be able to join the AD domain with SMBv1 disabled on the domain controller.&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;(you must be in advanced privelege mode to run this command [set advanced])&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cifs security modify -vserver &amp;lt;SVM-Name&amp;gt; -smb1-enabled-for-dc-connections false -smb2-enabled-for-dc-connections true&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this saves someone else the several hours i spent pulling my hair out today trying to resolve.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 11:51:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Simulator-Discussions/CIFS-server-can-t-join-AD/m-p/141649#M2363</guid>
      <dc:creator>connoisseur</dc:creator>
      <dc:date>2018-07-23T11:51:18Z</dc:date>
    </item>
  </channel>
</rss>

