The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Show SSSD version | sssd --version | View examples |
| List configured domains | sssctl domain-list | View examples |
| Check domain health | sudo sssctl domain-status --all example.com | View examples |
| Validate configuration | sudo sssctl config-check | View examples |
| Check secret-file permissions | stat -c '%a %U:%G %n' /etc/sssd/sssd.conf | View examples |
| Trace a user lookup | sudo sssctl user-checks alice@example.com | View examples |
| Resolve through NSS | getent passwd 'alice@example.com' | View examples |
| Resolve groups | id 'alice@example.com' | View examples |
| Evaluate access policy | sudo sssctl user-checks -a acct -s sshd \
'alice@example.com' | View examples |
| Discover a realm | realm discover example.com | View examples |
| List realm configuration | realm list | View examples |
| Join a realm interactively | sudo realm join --user=join-operator example.com | View examples |
| Leave a realm | sudo realm leave example.com | View examples |
| List host principals | sudo klist -k /etc/krb5.keytab | View examples |
| Query LDAP discovery records | dig +short SRV _ldap._tcp.example.com | View examples |
| Query Kerberos records | dig +short SRV _kerberos._tcp.example.com | View examples |
| Expire one cached user | sudo sss_cache --user 'alice@example.com' | View examples |
| Expire one domain cache | sudo sss_cache --domain example.com | View examples |
| Read service logs | journalctl -u sssd.service --since '-15 minutes' \
--no-pager | View examples |
| Analyze recent requests | sudo sssctl analyze request list | View examples |
SSSD connects NSS and PAM consumers to remote identity, authentication, and authorization providers while maintaining local caches. Directory integration is a security boundary: wrong DNS, time, TLS, keytabs, ID mapping, or access-provider policy can lock out users or grant unintended access. Preserve a tested local break-glass account, protect sssd.conf and keytabs, and never clear caches casually because cached identities and offline credentials affect availability.
Step by step
Detailed examples
Identify the provider, domain, and configuration owner
SSSD can use AD, IPA, LDAP, Kerberos, proxy, and other providers, each with different discovery and access behavior. realmd, ipa-client-install, authselect, or distribution tools may own generated settings. Record versions, enabled domains, NSS/PAM integration, and realm state before editing.
sssd --version
sssctl domain-list
realm list
grep -E '^(passwd|group|shadow|netgroup|sudoers|automount):' /etc/nsswitch.conf
systemctl status sssd.service --no-pager Protect and validate sssd.conf
sssd.conf can hold LDAP bind passwords and other sensitive values and normally must be root-owned mode 0600. config-check catches many syntax and option problems but cannot validate remote schema, certificates, DNS, or authorization. Use include snippets only where supported and never publish unredacted configuration.
sudo stat -c '%a %U:%G %n' /etc/sssd/sssd.conf
sudo sssctl config-check
sudo systemd-analyze security sssd.service
# Do not paste sssd.conf or debug logs without secret review. Verify DNS, time, and server discovery before blaming credentials
AD and IPA integrations depend heavily on DNS SRV records, canonical hostnames, reachable domain controllers, and synchronized clocks. Pinning one server can remove failover; autodiscovery can fail with split DNS or site errors. A domain marked offline may continue serving cached data while fresh users fail.
hostname --fqdn
timedatectl status
dig +short SRV _ldap._tcp.example.com
dig +short SRV _kerberos._tcp.example.com
sudo sssctl domain-status --all example.com Test the complete NSS identity path
getent proves NSS integration while sssctl can isolate SSSD. Fully qualified names avoid collisions across local, primary, and trusted domains; enabling short names without a domain-resolution policy can resolve the wrong identity. UID/GID mapping changes can silently change file ownership and must not be toggled after deployment without migration.
sudo sssctl user-show 'alice@example.com'
getent passwd 'alice@example.com'
id 'alice@example.com'
getent group 'linux-admins@example.com' Distinguish lookup, authentication, and host access
Seeing an identity does not mean the user can authenticate or is authorized to log in. access_provider may enforce AD GPO, IPA HBAC, LDAP filters, simple lists, or permit-all behavior. Fail-open changes can broaden access across the fleet; test allow and deny cases against the exact PAM service.
sudo sssctl user-checks 'alice@example.com'
sudo sssctl user-checks -a acct -s sshd 'alice@example.com'
sshd -T | grep -Ei '^(usepam|allowusers|allowgroups|denyusers|denygroups)' Join and leave domains as controlled identity changes
realm join creates or uses a computer account, obtains host credentials, writes keytabs, and changes identity configuration. Use a delegated join operator rather than a domain administrator, prompt for secrets, confirm DNS and time first, and understand OU and naming policy. realm leave can immediately remove directory access and requires console recovery.
realm discover example.com
host -t SRV _ldap._tcp.example.com
timedatectl status
# Enrollment is a privileged external change:
# sudo realm join --user=join-operator example.com Protect host keys and require authenticated transport
The host keytab is a machine credential and should never be copied into tickets or normal backups without encryption and access controls. LDAP integrations should use StartTLS or LDAPS with required certificate validation, but not both for one URI. Kerberos failures commonly reflect DNS, SPNs, key version drift, or time skew.
sudo stat -c '%a %U:%G %n' /etc/krb5.keytab
sudo klist -k /etc/krb5.keytab
timedatectl status
# Never run klist with key-display options in captured output. Treat caches as availability and security state
SSSD caches identities and may cache offline credentials when configured. Offline access can preserve logins during directory outages but delays revocation until policy and credential expiry. sss_cache expires entries; deleting cache databases loses state and can cause load spikes, UID surprises, or total directory-login failure while offline.
sudo sssctl domain-status --online example.com
sudo sssctl user-show 'alice@example.com'
# Prefer targeted invalidation after confirming provider availability:
# sudo sss_cache --user 'alice@example.com' Use bounded diagnostics and sanitize identity data
Start with domain status, one user lookup, service logs, and the SSSD analyzer available in the installed release. High debug levels can expose usernames, group memberships, server topology, LDAP filters, and credential workflow details while consuming disk. Enable them for a short reproduction and restore the previous setting.
sudo sssctl config-check
sudo sssctl domain-status --all example.com
sudo sssctl user-checks 'alice@example.com'
journalctl -u sssd.service --since '-15 minutes' --no-pager Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



