Got it

No Permission to Open a Folder After a CIFS Share Is Mounted to a Domain Name

262 0 1 0 0

Hello, everyone!

Do you know how to solve no permission to open a folder after a CIFS share is mounted to a domain name? Don't worry, the post will share with you!

Symptoms

After a Windows client added to the AD domain mounts a CIFS share using the domain name, an error message is displayed indicating that the user does not have the permission to open the folder. The folder has the read and write permissions of the local AD domain group. When the share is mounted, the domain user who logs in to the folder has been added to the local AD domain group.

Cause

Resource SID Compression in Windows Server 2012 may cause Authorization problems on devices that don't support Resource SID compression. For details, see. https://support.microsoft.com/en-us/kb/2774190

Analysis

1. The AD domain controller runs Windows 2012 R2.

2. The storage version is V300R006C00SPC100 or earlier.

3. Check whether the AD domain user joins a local AD domain group as shown in the following figure.

0102

Solution

Method 1

After OceanStor V3 is added to the AD domain, log in to the AD domain controller.

1. Open Task Manager on the taskbar and click ADSI Edit in Tools.

03

2. Find the organization unit that stores the OceanStor V3 machine account and clicks the properties of the machine account.

04

3. In the attribute list of the machine account, find the msDS-SupportedEncryptionTypes field, set the field value to 524319, and confirm the setting.

05

06

4. After the properties are modified, run the klist purge command in the Windows client CLI to refresh the Kerberos authentication cache. Then, mount the share again. The corresponding folder is opened successfully.

07

Method 2

Install the V300R006C00SPH102 hot patch or upgrade the V300R006C00SPH102 version.

This is my solution, how about yours? Go ahead and share it with us!

Comment

You need to log in to comment to the post Login | Register

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.