Configure sssd to work with multiple domains in different forests
Issue
- How to authenticate users from AD domains belonging to different forests using
SSSD
- How to configure
sssd
so that it can fetch information from trusted AD domain belonging to differentAD forest
. - Can
adcli
be used to join twoAD
domains from differentAD forest
? -
- SSSD trusted domain support currently only includes retrieving information from domains within the same Active Directory Resource Forest. That being said, SSSD can be configured to resolve users and groups from more than one AD forest by configuring a domain for each forest in the SSSD configuration file.
NOTE: If expecting to use only shortnames(user
, instead of user@domain
) then user/group objects will be resolved in order of the domain sections specified in sssd.conf
.
IMPORTANT: For Red Hat Enterprise Linux 8 (and later) systems, please follow the process described in the Accessing AD with a Managed Service Account documentation.
Environment
- Redhat Enterprise Linux 7
- sssd
- adcli
- realmd
- Active Directory
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.