Sujet : sssd
-
Joining a Linux host to Active Directory with realmd and SSSD
realm discover and realm join hand the detailed Kerberos, LDAP and SSSD configuration to realmd so an agent does not have to hand-edit sssd.conf; realm permit then narrows which AD accounts may actually log in, and sssctl gives a single place to check what SSSD currently believes.
-
Tracing which identity source answers for a user: getent, id, nsswitch.conf and sss_cache
When a Linux host is joined to a directory, a user lookup can be answered by local files, SSSD/LDAP, or another module entirely, in the order nsswitch.conf lists them. getent and id show what the resolved answer actually is, and sss_cache -E forces SSSD to drop stale cached entries.
Lisible par machine : JSON