Hello,
We've got a customer who complains one of his users can't reach a series of vFilers anymore.
After searching for a possible cause, we stripped all memberships of Active Directory groups, for a particular server.
We added him to 1 Ad group. In this situation it is possible to reach the vfilers.
We suspect that the Kerberos Token Size of this particular user is rather big due to extensive group nesting.
Is there a command I can issue to see the max token size setting for vFiler?
I read in
NetApp Knowledgebase - What is maximum Kerberos token size that Data ONTAP 7G can process?
that max token size is 12K but can be set to max 64K, the problem is I can't find where to set this.
Mentioned filers are still running on OnTap 7 versions so we are in the process of starting an upgrade project, but that will take a while.