Sun Microsystems, Inc.  Sun System Handbook - ISO 4.1 October 2012 Internal/Partner Edition
   Home | Current Systems | Former STK Products | EOL Systems | Components | General Info | Search | Feedback

Asset ID: 1-71-1402313.1
Update Date:2012-06-26
Keywords:

Solution Type  Technical Instruction Sure

Solution  1402313.1 :   Sun Storage 7000 Unified Storage System: ZFS Storage Appliance unable to join/reconnect to Active Directory Domain after upgrade to 2011.1  


Related Items
  • Sun Storage 7310 Unified Storage System
  •  
  • Sun Storage 7410 Unified Storage System
  •  
  • Sun ZFS Storage 7120
  •  
  • Sun ZFS Storage 7420
  •  
  • Sun ZFS Storage 7320
  •  
  • Sun Storage 7110 Unified Storage System
  •  
  • Sun Storage 7210 Unified Storage System
  •  
Related Categories
  • PLA-Support>Sun Systems>DISK>NAS>SN-DK: 7xxx NAS
  •  
  • .Old GCS Categories>Sun Microsystems>Storage - Disk>Unified Storage
  •  




In this Document
Goal
Fix
References


Applies to:

Sun Storage 7310 Unified Storage System - Version Not Applicable to Not Applicable [Release N/A]
Sun Storage 7210 Unified Storage System - Version Not Applicable to Not Applicable [Release N/A]
Sun Storage 7410 Unified Storage System - Version Not Applicable to Not Applicable [Release N/A]
Sun ZFS Storage 7420 - Version Not Applicable to Not Applicable [Release N/A]
Sun ZFS Storage 7120 - Version Not Applicable to Not Applicable [Release N/A]
7000 Appliance OS (Fishworks)

Goal

This document describes issues that could prevent ZFS Storage Appliances from connecting to an Active Directory domain after upgrade to the 2011.1 software release, and potential solutions.

To discuss this information further with Oracle experts and industry peers, we encourage you to review, join or start a discussion in the My Oracle Support Community - 7000 Series ZFS Appliances

Fix

As of the 2011.1 release, the ZFS Storage Appliance uses a new method for outbound SMB connections with the Active Directory Domain Controller. This change can cause two potential problems.

First, it may simply be necessary to navigate to the

Configuration - Services - Active Directory - Join Domain

screen within the BUI and re-enter the administrative credentials. This is simply to re-initialize the connection with the new method.

The second potential problem is a compatibility issue with the NtlmMinServerSec registry setting (HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\NtlmMinServerSec). If this setting is configured to anything other than the default of zero, the appliance will not be able to negotiate a connection with the Domain Controller.

To resolve the issue, set the registry setting back to the default, or contact Oracle Support to determine whether a workaround or fix is available. Detailed information on this setting from Microsoft can be found here.

The details on the workaround and the related bug can be found on the support wiki here.

If it is intended to use the proposed workaround that modifies the service properties, pay careful attention to the note at the end of the wiki article on compatibility with an upcoming fix for Server 2008 and NTLMv2.

 

Back to <Document 1402353.1> Sun Storage 7000 Unified Storage System: How to Troubleshoot Active Directory Issues.

References

MS NtlmMinServerSec Doc: http://technet.microsoft.com/en-us/library/cc759681%28WS.10%29.aspx
@Support wiki CR 7126542 workaround: https://stbeehive.oracle.com/teamcollab/wiki/AmberRoadSupport:Workaround+for+CR+7126542+-+after+update+to+2011.1.1+appliance+unable+to+join+AD+domain
<NOTE:1402353.1> - Sun Storage 7000 Unified Storage System: How to Troubleshoot Active Directory Issues

Attachments
This solution has no attachment
  Copyright © 2012 Sun Microsystems, Inc.  All rights reserved.
 Feedback