The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Show SSSD versionsssd --versionView examples
List configured domainssssctl domain-listView examples
Check domain healthsudo sssctl domain-status --all example.comView examples
Validate configurationsudo sssctl config-checkView examples
Check secret-file permissionsstat -c '%a %U:%G %n' /etc/sssd/sssd.confView examples
Trace a user lookupsudo sssctl user-checks alice@example.comView examples
Resolve through NSSgetent passwd 'alice@example.com'View examples
Resolve groupsid 'alice@example.com'View examples
Evaluate access policysudo sssctl user-checks -a acct -s sshd \ 'alice@example.com'View examples
Discover a realmrealm discover example.comView examples
List realm configurationrealm listView examples
Join a realm interactivelysudo realm join --user=join-operator example.comView examples
Leave a realmsudo realm leave example.comView examples
List host principalssudo klist -k /etc/krb5.keytabView examples
Query LDAP discovery recordsdig +short SRV _ldap._tcp.example.comView examples
Query Kerberos recordsdig +short SRV _kerberos._tcp.example.comView examples
Expire one cached usersudo sss_cache --user 'alice@example.com'View examples
Expire one domain cachesudo sss_cache --domain example.comView examples
Read service logsjournalctl -u sssd.service --since '-15 minutes' \ --no-pagerView examples
Analyze recent requestssudo sssctl analyze request listView examples

SSSD connects NSS and PAM consumers to remote identity, authentication, and authorization providers while maintaining local caches. Directory integration is a security boundary: wrong DNS, time, TLS, keytabs, ID mapping, or access-provider policy can lock out users or grant unintended access. Preserve a tested local break-glass account, protect sssd.conf and keytabs, and never clear caches casually because cached identities and offline credentials affect availability.

Step by step

Detailed examples

01

Identify the provider, domain, and configuration owner

SSSD can use AD, IPA, LDAP, Kerberos, proxy, and other providers, each with different discovery and access behavior. realmd, ipa-client-install, authselect, or distribution tools may own generated settings. Record versions, enabled domains, NSS/PAM integration, and realm state before editing.

Capture integration inventory
sssd --version
sssctl domain-list
realm list
grep -E '^(passwd|group|shadow|netgroup|sudoers|automount):' /etc/nsswitch.conf
systemctl status sssd.service --no-pager
Back to quick reference ↑
02

Protect and validate sssd.conf

sssd.conf can hold LDAP bind passwords and other sensitive values and normally must be root-owned mode 0600. config-check catches many syntax and option problems but cannot validate remote schema, certificates, DNS, or authorization. Use include snippets only where supported and never publish unredacted configuration.

Validate without exposing values
sudo stat -c '%a %U:%G %n' /etc/sssd/sssd.conf
sudo sssctl config-check
sudo systemd-analyze security sssd.service
# Do not paste sssd.conf or debug logs without secret review.
Back to quick reference ↑
03

Verify DNS, time, and server discovery before blaming credentials

AD and IPA integrations depend heavily on DNS SRV records, canonical hostnames, reachable domain controllers, and synchronized clocks. Pinning one server can remove failover; autodiscovery can fail with split DNS or site errors. A domain marked offline may continue serving cached data while fresh users fail.

Check discovery and current provider
hostname --fqdn
timedatectl status
dig +short SRV _ldap._tcp.example.com
dig +short SRV _kerberos._tcp.example.com
sudo sssctl domain-status --all example.com
Back to quick reference ↑
04

Test the complete NSS identity path

getent proves NSS integration while sssctl can isolate SSSD. Fully qualified names avoid collisions across local, primary, and trusted domains; enabling short names without a domain-resolution policy can resolve the wrong identity. UID/GID mapping changes can silently change file ownership and must not be toggled after deployment without migration.

Compare SSSD and NSS views
sudo sssctl user-show 'alice@example.com'
getent passwd 'alice@example.com'
id 'alice@example.com'
getent group 'linux-admins@example.com'
Back to quick reference ↑
05

Distinguish lookup, authentication, and host access

Seeing an identity does not mean the user can authenticate or is authorized to log in. access_provider may enforce AD GPO, IPA HBAC, LDAP filters, simple lists, or permit-all behavior. Fail-open changes can broaden access across the fleet; test allow and deny cases against the exact PAM service.

Evaluate an SSH account check
sudo sssctl user-checks 'alice@example.com'
sudo sssctl user-checks -a acct -s sshd 'alice@example.com'
sshd -T | grep -Ei '^(usepam|allowusers|allowgroups|denyusers|denygroups)'
Back to quick reference ↑
06

Join and leave domains as controlled identity changes

realm join creates or uses a computer account, obtains host credentials, writes keytabs, and changes identity configuration. Use a delegated join operator rather than a domain administrator, prompt for secrets, confirm DNS and time first, and understand OU and naming policy. realm leave can immediately remove directory access and requires console recovery.

Review prerequisites before enrollment
realm discover example.com
host -t SRV _ldap._tcp.example.com
timedatectl status
# Enrollment is a privileged external change:
# sudo realm join --user=join-operator example.com
Back to quick reference ↑
07

Protect host keys and require authenticated transport

The host keytab is a machine credential and should never be copied into tickets or normal backups without encryption and access controls. LDAP integrations should use StartTLS or LDAPS with required certificate validation, but not both for one URI. Kerberos failures commonly reflect DNS, SPNs, key version drift, or time skew.

Inspect credential metadata only
sudo stat -c '%a %U:%G %n' /etc/krb5.keytab
sudo klist -k /etc/krb5.keytab
timedatectl status
# Never run klist with key-display options in captured output.
Back to quick reference ↑
08

Treat caches as availability and security state

SSSD caches identities and may cache offline credentials when configured. Offline access can preserve logins during directory outages but delays revocation until policy and credential expiry. sss_cache expires entries; deleting cache databases loses state and can cause load spikes, UID surprises, or total directory-login failure while offline.

Expire the narrowest cache entry
sudo sssctl domain-status --online example.com
sudo sssctl user-show 'alice@example.com'
# Prefer targeted invalidation after confirming provider availability:
# sudo sss_cache --user 'alice@example.com'
Back to quick reference ↑
09

Use bounded diagnostics and sanitize identity data

Start with domain status, one user lookup, service logs, and the SSSD analyzer available in the installed release. High debug levels can expose usernames, group memberships, server topology, LDAP filters, and credential workflow details while consuming disk. Enable them for a short reproduction and restore the previous setting.

Collect scoped evidence
sudo sssctl config-check
sudo sssctl domain-status --all example.com
sudo sssctl user-checks 'alice@example.com'
journalctl -u sssd.service --since '-15 minutes' --no-pager
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. SSSD ProjectSSSD Introductionsssd.io
  2. SSSD ProjectSSSD Quick Start Guidesssd.io
  3. SSSD ProjectSSSD Active Directory Provider Setupsssd.io
  4. SSSD ProjectSSSD Troubleshooting Basicssssd.io
  5. SSSD ProjectSSSD Architecturesssd.io
  6. SSSD ProjectSSSD AD Providersssd.io

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback