LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 12-01-2019, 12:05 AM   #1
gfrair
LQ Newbie
 
Registered: Jan 2005
Posts: 22

Rep: Reputation: 0
Angry SSSD (Centos 7) - Active Directory Users Randomly are Missing Group Associations


Hi All,

Been banging my head against the wall with this one and desperate for some help!

We have an issue occurring across many servers using SSSD for authentication/integration with Active Directory during which the user is denied access to something they've been granted. When we perform an "id -Gn <username>" on the server, a group association is missing. I discovered that it appears (from what I can interpret) SSSD finds the group in AD and begins making the assoication, but expects the group to be in the ldb cache (which it isn't apparently) and because it can't find it, doesn't associate the group. The following is an example of the debug log (username has been replaced by <username>, while group name has been replaced with <groupname>):

(Fri Nov 29 16:16:05 2019) [sssd[be[ENT.AD.MRE]]] [save_rfc2307bis_user_memberships] (0x2000): Updating memberships for <username>@ent.ad.mre
(Fri Nov 29 16:16:05 2019) [sssd[be[ENT.AD.MRE]]] [ldb] (0x4000): start ldb transaction (nesting: 2)
(Fri Nov 29 16:16:05 2019) [sssd[be[ENT.AD.MRE]]] [sss_domain_get_state] (0x1000): Domain ENT.AD.MRE is Active
(Fri Nov 29 16:16:05 2019) [sssd[be[ENT.AD.MRE]]] [ldb] (0x4000): start ldb transaction (nesting: 3)
(Fri Nov 29 16:16:05 2019) [sssd[be[ENT.AD.MRE]]] [ldb] (0x4000): Added timed event "ltdb_callback": 0x555d730e5140
(Fri Nov 29 16:16:05 2019) [sssd[be[ENT.AD.MRE]]] [ldb] (0x4000): Entry not found (name=<group_name>@ent.ad.mre,cn=groups,cn=ENT.AD.MRE,cn=sysdb)
(Fri Nov 29 16:16:05 2019) [sssd[be[ENT.AD.MRE]]] [ldb] (0x4000): cancel ldb transaction (nesting: 3)
(Fri Nov 29 16:16:05 2019) [sssd[be[ENT.AD.MRE]]] [sysdb_mod_group_member] (0x0080): ldb_modify failed: [No such object](32)[ldb_wait from ldb_modify with LDB_WAIT_ALL: No such object (32)]
(Fri Nov 29 16:16:05 2019) [sssd[be[ENT.AD.MRE]]] [sysdb_mod_group_member] (0x0400): Error: 2 (No such file or directory)

I'm at a loss for why this is occurring, and randomly with different users differnt servers. Especially given they all have the same configuration (as far as I can tell).

Any assistance would be greatly appreciated.

Regards,

Greg
 
Old 12-05-2019, 12:47 PM   #2
gfrair
LQ Newbie
 
Registered: Jan 2005
Posts: 22

Original Poster
Rep: Reputation: 0
I figured this out for all those that may encounter a similar issue.... someone added "krb5_validate=True" in our SSSD.conf. I had to remove this setting and force a deletion/rebuild of the cache. There were some other issues, but this appears to be the most widespread.

Regards,
 
  


Reply

Tags
active directory, centos7, sssd



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] sssd: Benign local domain sssd.conf needed boxyzzy Linux - Server 1 10-06-2016 01:31 PM
Samba, SSSD, Active Directory 2008 R2 and ACLs on Windows clients HowellBP Linux - Server 2 10-07-2013 02:37 PM
SSO SSSD/Kerberos/LDAP with Active Directory yuanjunliang Linux - Server 1 09-13-2013 02:59 PM
Winbind / KRB / SSSD / Active Directory Howto? rrue Linux - Server 2 10-11-2012 12:48 PM
File associations in Gnome Commander vs. associations in Nautilus taylorkh Linux - Software 0 01-01-2010 05:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 06:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration