Dell Unity:Kerberos 令牌超过 16 KB 时 SMB/CIFS 共享访问失败
Summary: 在 Unity OE 5.2.0.0.5.173 中,具有大于 16 KB 的 Kerberos 令牌的用户可能无法访问托管在 Unity NAS 服务器上的 SMB/CIFS 共享。当 SMB 身份验证使用 Kerberos 时会出现此问题,并且问题是由 SMB 会话设置过程中的缺陷导致的,该过程中错误地返回大型 Kerberos 令牌的STATUS_INVALID_PARAMETER错误。此问题已在 Unity OE 5.2.1.0.5.013 (5.2 SP1) 中得到解决。在可以执行升级之前,受影响的用户可能会减少其 Kerberos 令牌大小、使用 NTLM 身份验证或故障切换到 Unity OE 5.1.x 阵列(如果可用)。 ...
Acest articol se aplică pentru
Acest articol nu se aplică pentru
Acest articol nu este legat de un produs specific.
Acest articol nu acoperă toate versiunile de produs existente.
Symptoms
将 Unity 系统升级到 OE 5.2.0.0.5.173 后,具有 大于 16 KB 的 Kerberos 身份验证令牌的用户 可能无法访问托管在 Unity NAS 服务器上的 SMB/CIFS 共享。当尝试连接到共享时,用户可能会收到 Windows 错误,指示无法访问网络路径,即使 NAS 服务器和共享可用也是如此。
示例错误:
Windows cannot access \\nasservername\share
Check the spelling of the name. Otherwise, there might be a problem with your network.
To try to identify and resolve network problems, click Diagnose.Cause
仅当满足 以下所有 条件时,才会出现此问题:
- Unity 阵列正在运行
Unity OE 5.2.0.0.5.173. - SMB 文件访问配置为使用 Kerberos 身份验证。
- 受影响用户的 Kerberos 令牌大于 16 KB。
此问题是由 Unity OE 5.2.0.0.5.173 中引入的代码更改引起的,该更改影响了 SMB 会话设置处理。在身份验证过程中,如果 Kerberos 令牌超过 16 KB,Unity 会错误地返回 STATUS_INVALID_PARAMETER 错误。
此版本中添加的额外验证检查在确定是否应跨多个会话设置请求处理 Kerberos 令牌之前执行参数验证。因此,过大 Kerberos 令牌会过早被拒绝,从而导致 SMB 身份验证失败并阻止对共享的访问。
Resolution
修复
此问题已在 Unity OE 5.2.1.0.5.013 中得到解决。升级到此版本或更高版本可永久解决此问题。
解决方法
如果无法立即升级,请考虑以下解决方法之一:
- 通过删除不必要的 Active Directory 组成员身份和清理未使用的 SIDHistory 条目来减小 Kerberos 令牌大小。
- 使用 NTLM 身份验证 进行 SMB 访问,例如通过使用其 IP 地址连接到 SMB 服务器。
- 故障切换到运行 Unity OE 5.1.x 的灾难恢复 (DR) 阵列(如果此类环境可用)。
这些解决方法可以帮助恢复 SMB 共享访问,直到阵列可以升级到固定的 Unity OE 版本。
Produse afectate
Dell EMC Unity, Dell EMC Unity Family |Dell EMC Unity All Flash, Dell EMC Unity HybridProprietăți articol
Article Number: 000200086
Article Type: Solution
Ultima modificare: 22 Jul 2026
Version: 16
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.