SSSD does not show group members from LDAP, even with enumeration enabled in sssd.conf

Solution Verified - Updated -


  • SSSD does not show group members from LDAP, even if enumeration is enabled in sssd.conf. The getent group does not list users who are members.
# getent group idmusers

Ideally this should list

# getent group idmusers


  • Red Hat Enterprise Linux 6.0
  • sssd-1.2.1-28.el6_0.4.x86_64
  • sssd-client-1.2.1-28.el6_0.4.x86_64
  • Red Hat Directory Server 8.2 (as the LDAP server)

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content