SSSD does not update any attributes on its own. Are you sure the users are not 
logging in with e.g. ssh public key which would bypass AD DCs during 
authentication completely?

> On 3 Aug 2018, at 17:15, Galen Johnson <galen.john...@sas.com> wrote:
> 
> Hey,
> 
> I'm wondering if SSSD might not be updating some of the logon attributes in 
> AD.  We recently were directed to use updated DCs and some attributes no 
> longer seem to be getting updated; for example, logonCount and lastLogon.  In 
> some cases, the attribute is non-existant.  I'm leaning towards it being a DC 
> issue since it was gettting updated with the previous controllers but wanted 
> to see if anyone was aware of any reason SSSD could be at issue.
> 
> thanks
> 
> =G=
> 
> _______________________________________________
> sssd-users mailing list -- sssd-users@lists.fedorahosted.org
> To unsubscribe send an email to sssd-users-le...@lists.fedorahosted.org
> Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives: 
> https://lists.fedoraproject.org/archives/list/sssd-users@lists.fedorahosted.org/message/J5WOQKQDJRAHTYISIYXNTBROKXVTRKGO/
_______________________________________________
sssd-users mailing list -- sssd-users@lists.fedorahosted.org
To unsubscribe send an email to sssd-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/sssd-users@lists.fedorahosted.org/message/WJ7DFXQVKNZSQJWQGUVMLRF5BGLQA5S4/

Reply via email to