SSSD on RHEL6 is unable to get nested groups without Unix attributes from Active Directory
Issue
Users are members of a Role Group "R_Admins" which is a member of Access group "A_Admins". The Group R_Admins do not have unix attributes (no gid), but A_Admins has gid. The problem here is upon starting sssd with a clear cache doesn't resolve the user's membership in group A_Admins through the group R_Admins.
Environment
Red Hat Enterprise Linux 6.6
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.