Assimilation Fails with a NEG_TOKEN_INIT Mechtype Error
Applies to: Hammerspace 5.2 and later.
Symptom
You are assimilating a volume with Include SMB/AD metadata during assimilation selected, and it fails with an error like this:
Failure while validating SMB server 'nas.asgard.loc' and share 'home'.
Make sure server and share are correct. Reason returned by server:
[errorCode=5000: INTERNAL_SERVER_ERROR, args=[Status: 500,
Output: SPNEGO(gse_krb5) creating NEG_TOKEN_INIT for cifs/nas.asgard.loc
failed (next[(null)]): NT_STATUS_INVALID_PARAMETER
SPNEGO: Could not find a suitable mechtype in NEG_TOKEN_INIT]]
Cause
Hammerspace requires certain service principal names on the Active Directory computer object of any NAS it assimilates.
Here, the computer object for nas.asgard.local has no CIFS/nas.asgard.local service principal name. The same error appears if you use the single-label hostname nas without a matching cifs/nas entry.
Resolution
| Take care editing Active Directory objects. Mistakes can break client access. |
Add the service principal name in either of two ways. In these examples the computer account name is nas.
Using setspn
Requires administrative access.
Command:
setspn -s CIFS/nas.asgard.local nas
The syntax is setspn -s service/name hostname.
Using Active Directory Users and Computers
Requires administrative access, and Advanced Features enabled from the View menu.
-
Browse to the computer object — do not search for it.
-
Right-click it and select Properties.
-
Open the Attribute Editor tab.
-
Scroll to
servicePrincipalNameand click Edit. -
Enter
CIFS/nas.asgard.localin Value to add and click Add. -
Click OK.