[SSSD-users] Re: sssd id getent and secondary groups in active directory

2018-07-09 Thread Ratliff, John
On Fri, 2018-07-06 at 10:55 +0200, Sumit Bose wrote: > > this makes SSSD assume that the user is not a member of any group. > > Please try to set 'ldap_use_tokengroups=False' (see man sssd-ldap for > details) and check if the group memberships are reported more > reliable. > > Afaik the issue wi

[SSSD-users] Re: sssd id getent and secondary groups in active directory

2018-07-06 Thread Ratliff, John
On Fri, 2018-07-06 at 10:55 +0200, Sumit Bose wrote: > On Thu, Jul 05, 2018 at 08:09:55PM +0000, Ratliff, John wrote: > > > > (Thu Jul 5 16:04:42 2018) [sssd[be[ads.iu.edu]]] [sdap_print_server] > (0x2000): Searching 134.68.239.131:389 > (Thu Jul 5 16:04:42 2018

[SSSD-users] sssd id getent and secondary groups in active directory

2018-07-05 Thread Ratliff, John
I'm using SSSD and realmd to join a machine to active directory. When I run id on my user, I only get the primary group. If I run getent group "groupname", it works...sometimes. Other times, it returns blank. This is on a CentOS 7 machine (sssd 1.16.0) $ id jdratlif uid=752603752(jdratlif) gid=1