Users report that they are unable to connect to home directories stored on a NetApp cluster. You are using
Active Directory-based Kerberos authentication.
Which two actions would correct the problem? (Choose two.)

A.
Verify that the CIFS server in running in the SVM.
B.
Verify that the Network Time Protocol service is in sync.
C.
Verify that an Active Directory domain admin account is configured in ONTAP.
D.
Verify that domain tunneling is configured in ONTAP.
Explanation:
Kerberized NFS in Cluster-Mode for use with Active Directory Pre-requisites include:
Domain admin access to a domain controller (for initial setup).
vServer with data LIFs, NFS and CIFS servers created
Note: The CIFS server is not required for basic NFS Kerberos access, but is required for multiprotocol access
or when using AD as an LDAP server for name mappings.https://kb.netapp.com/support/s/article/ka31A0000000uYJQAY/how-to-set-up-kerberized-nfs-incluster-mode-with-active-directory?language=en_US
I would favor answer B instead of A. In my opinion the chance that there is a clock skew between netapp and ad domain controller is bigger then cifs protocol not configured or started.
0
0
A and B is correct.
You don“t need a AD domain admin account configured in ONTAP
You need a AD computer account for the CIFS SVM
0
0
maximum timeskew is 5min for AD DC
1
0
True. so true.
0
0