Hello everybody, 

In an  Idm setup with replica and AD trust , I noticed that on few clients only 
some  of the groups are resolved to names (on the IPA servers they are 
correctly resolved) . If I remove caches on IPA server, remove the cache in 
/var/lib/sss/db , I make it eventually work, although it seems quite random 
(and obviously not a solution in a production setup). 

Does anyone have any idea what might be the cause of such behaviour ? 

I have read almost anything I could find about troubleshooting sssd, and I have 
to admit that clearing caches and all that stuff is still trial and error and 
still something which probably either needs to be done better, either to be 
documented better . So far, from what I experienced in my setup, sssd and 
handling caches seems one of the biggest sources of trouble and a major 
roadblock in migrating to IPA. 
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to