You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When Kerberos authentication is required for Vscan servers, each SVM data LIF must have a unique DNS name registered as PTR-Record and Host-A entry. This DNS name must also be registered as a server principal name (SPN) in SVMs computer account within the Windows Active Directory. On scan servern running windows server 2016 and newer it is also possible to register the IPv4 addresses as SPN and enable Kerberos over IP on the scanserver by running following command on a elevatet shell.
netapp-aherbin
added
documentation
Improvements or additions to documentation
and removed
Triage
Item is being researched and will be assigned when more information is gathered
labels
Feb 16, 2024
Page URL
https://docs.netapp.com/us-en/ontap/antivirus/install-ontap-antivirus-connector-task.html
Page title
Install ONTAP Antivirus Connector
Summary
When Kerberos authentication is required for Vscan servers, each SVM data LIF must have a unique DNS name registered as PTR-Record and Host-A entry. This DNS name must also be registered as a server principal name (SPN) in SVMs computer account within the Windows Active Directory. On scan servern running windows server 2016 and newer it is also possible to register the IPv4 addresses as SPN and enable Kerberos over IP on the scanserver by running following command on a elevatet shell.
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters" /v TryIPSPN /t REG_DWORD /d 1 /f
https://learn.microsoft.com/en-us/windows-server/security/kerberos/configuring-kerberos-over-ip
Public issues must not contain sensitive information
The text was updated successfully, but these errors were encountered: