# SSSD Help!

**URL:** <https://forums.suse.com/t/sssd-help/27579>\
**Category:** SLES Configure-Administer\
**Created:** [November 2, 2015, 9:25pm UTC](https://forums.suse.com/t/sssd-help/27579 "2015-11-02T21:25:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ruination](https://avatars.discourse-cdn.com/v4/letter/r/a9adbd/32.png) [@ruination](https://forums.suse.com/u/ruination)\
**Post date:** [November 2, 2015, 9:25pm UTC](https://forums.suse.com/t/sssd-help/27579/1 "2015-11-02T21:25:02Z")

</div>

Does anyone out there have sssd working on SLES 12-SP0?

This is a frightening post to me: [http://put.hk/article/nntp.novell.com/opensuse.org.help.network-internet/61232.html](http://put.hk/article/nntp.novell.com/opensuse.org.help.network-internet/61232.html)

We have a Server 2012R2 AD domain. We want to use AD provider and leverage Kerberos auth. I have an open SR with Novell in an attempt to get a working config for sssd.conf including PAM/NSS accordingly. I have had no luck to date. Does anyone have a sssd.conf that works with their AD domain (preferably 2012R2) and changes to /etc/pam.d files and /etc/nsswitch.conf, /etc/krb5.conf and/or anything else I am missing? Here are the “sssd” packages I currently have installed:

sssd-1.11.5.1-5.20.x86\_64  
sssd-ad-1.11.5.1-5.20.x86\_64  
sssd-krb5-common-1.11.5.1-5.20.x86\_64  
sssd-proxy-1.11.5.1-5.20.x86\_64  
sssd-32bit-1.11.5.1-5.20.x86\_64  
sssd-tools-1.11.5.1-5.20.x86\_64  
sssd-ldap-1.11.5.1-5.20.x86\_64  
sssd-krb5-1.11.5.1-5.20.x86\_64

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![ab1](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@ab1](https://forums.suse.com/u/ab1)\
**Post date:** [November 4, 2015, 1:10am UTC](https://forums.suse.com/t/sssd-help/27579/2 "2015-11-04T01:10:23Z")

</div>

I’ve forwarded this on to the SSSD guru I know, so hopefully he’ll drop in  
and answer soon. In the meantime, it may be worthwhile to include more  
details on the docs followed, steps taken, etc. If you happen to be at  
SUSECon, I can introduce you to him and he can probably give you some  
materials or have you join in on a class he’s giving on the topic to  
dozens of other attendees.

–  
Good luck.

If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below…

---

<div class="post-metadata">

**Author:** ![Lawrence1](https://avatars.discourse-cdn.com/v4/letter/l/e56c9b/32.png) [@Lawrence1](https://forums.suse.com/u/Lawrence1)\
**Post date:** [November 6, 2015, 1:19pm UTC](https://forums.suse.com/t/sssd-help/27579/3 "2015-11-06T13:19:23Z")

</div>

ruination, ab referenced me to you and I can certainly help! I am currently at SUSECON with an expiring laptop battery and as soon as I sort it I will be back online and will help in painful detail. ab will explain .

– lawrence

---

<div class="post-metadata">

**Author:** ![Lawrence1](https://avatars.discourse-cdn.com/v4/letter/l/e56c9b/32.png) [@Lawrence1](https://forums.suse.com/u/Lawrence1)\
**Post date:** [November 9, 2015, 5:23am UTC](https://forums.suse.com/t/sssd-help/27579/4 "2015-11-09T05:23:00Z")

</div>

ruination,

Note the following instructions, especially concerning whether you are reading posix attributes from AD or generating them dynamically.

- Configure the hostname on the linux server to be used for the computer object in AD.

- Provision forward and reverse lookup DNS records in the DNS service used by the target Windows domain using the configured hostname.

- Verify DNS and time sync sources for the linux box are the same as used for the target Windows domain and are both working properly (extremely important!). Kerberos operations and the AD autodiscovery and DNS features of the AD provider will benefot greatly from both working crrectly/

- Install the kerberos client, samba and SSSD packages:

krb5  
krb5-32bit  
krb5-client

samba  
samba-32bit  
samba-client  
samba-client-32bit

Technically the kerberos and samba (samba is only required for domain joining really) are not required but assist in troubleshooting kerberos, AD connectivity and GSSAPI issues out of band from SSSD.

sssd  
sssd-ad  
python-sssd-config  
sssd-tools (recommended)

- Configure the kerberos and samba clients manually and join the server to the domain. Although YaST can be used to perform all of these tasks, if the right options are not chosen YaST will also configure and implement the pam\_krb5, pam\_ldap, possibly the winbind module and their related PAM configurations. None of which are required when the SSSD AD provider is used.

/etc/krb5.conf:

[libdefaults]  
default\_realm = \<WINDOWS\_DOMAIN\_FQDN\>  
clockskew = 300

[realms]  
[DVC.DARKVIXEN.COM](http://DVC.DARKVIXEN.COM) = {  
kdc = \<Windows\_KDC\_server.something.com\>  
default\_domain = \<windows\_domain\_fqdn\>  
admin\_server = \<Windows\_ADMIN/KDC\_server.something.com\>  
}

[logging]  
kdc = FILE:/var/log/krb5/krb5kdc.log  
admin\_server = FILE:/var/log/krb5/kadmind.log  
default = SYSLOG:NOTICE:DAEMON

[domain\_realm]  
.dvc.darkvixen.com = [DVC.DARKVIXEN.COM](http://DVC.DARKVIXEN.COM)

[appdefaults]  
pam = {  
ticket\_lifetime = 1d  
renew\_lifetime = 1d  
forwardable = true  
proxiable = false  
minimum\_uid = 10000  
clockskew = 300  
external = sshd  
use\_shmem = sshd  
}

\*\* “minimum\_uid =” depends on the SSSD id mapping settings used (see more info below) and the settings used by Identity Management for Unix configuration for the AD instance. If this does not apply, omit the directive.

/etc/samba/smb.conf:

Modify the [GLOBAL] section as described.

[global]  
workgroup = \<COMPUTER\_WORKGROUP\>  
passdb backend = tdbsam  
printing = cups  
printcap name = cups  
printcap cache time = 750  
cups options = raw  
map to guest = Bad User  
include = /etc/samba/dhcp.conf  
logon path = \\%L\profiles\.msprofile  
logon home = \\%L\%U\.9xprofile  
logon drive = P:  
usershare allow guests = No  
kerberos method = secrets and keytab  
realm = \<WINDOWS\_DOMAIN\_FQDN\>  
security = ADS  
client use spnego = yes  
template homedir = /home/%D/%U

Initiate a kerberos connection using an account that can perform the domain joining operations and join the domain:

kinit \<PRIVELEDGED\_ACCOUNT\>

View that a kerberos ticket granting ticket was granted:

klist

Join the domain and create a keytab file

net ads join -k

Verify the join and AD connectivity

net ads testjoin  
net ads info

- Invoke the YaST authentication client module

yast auth-client

Add a new SSSD domain using the FQDN of the target domain for the name and select ad as the identity and authentication provider. The resultant /etc/sssd/sssd.conf will be very basic but should work if you are using dynamic id mapping. Meaning that the posix attributes are not being read from AD.

If the posix attributes are to be read from AD implement a sssd.conf file similar to the one below, delete the cache files in the /var/lib/sss/db directory and restart the daemon.

If you start with a id mapping configuration, which is the default, you will have to delete the cache files before the new configuration that disables id mapping will work.

[sssd]  
config\_file\_version = 2  
services = nss, pam  
domains = \<WINDOWS\_DOMAIN\_FQDN\>

[nss]  
filter\_users = root  
filter\_groups = root

[pam]  
reconnection\_retries = 3

[domain/\<WINDOWS\_DOMAIN\_FQDN\>]  
cache\_credentials = True

id\_provider = ad  
auth\_provider = ad

ldap\_id\_mapping = False

This is a basic config should get you up and going. If home directories will be used it is recommended to implement them using a new path, like /home/\<WINDOWS\_DOMAIN\_FQDN\> and include the following directive in the domain configuration stanza:

override\_homedir = /home/%d/%u

After creating the /home/\<WINDOWS\_DOMAIN\_FQDN\> path this will redirect home directories to the new path.

Be sure to enable home directory creation on user login by issuing the following command as root:

pam-config --query --mkhomedir

Host level access control using group membership can be accomplished by adding the following directives to the domain configuration stanza:

access\_provider = ad

ad\_access\_filter = DOM:\<WINDOWS\_DOMAIN\_FQDN\>:(memberOf=\<GROUP\_LDAP\_FDN\>)

To ensure the kerberos, ldap and winbind PAM modules are not being loaded disable them with the following commands:

pam-config --delete --ldap  
pam-config --delete --krb5  
pam-config --delete --winbind

Hope this helps and let me if I can assist further,

– lawrence
