Hi All,

While TCPdumping logins on an IPA client using an AD account I found out that 
SSSD doesn't take AD Sites into account. I see a DNS lookup for 
_kerberos._udp.<ad.domain> and _kerberos._tcp.<ad-domain> and then a Kerberos 
attempt at one or more of the AD servers (both the local and non-local ones).

While this isn't a huge problem it does delay logins where communication with 
the AD kdc is required.

Is there a way to get sssd to use the proper site for trusted AD domains?

Met vriendelijke groet,

Wouter Hummelink
Cloud Engineer
[Description: Beschrijving: Beschrijving: cid:image003.gif@01CC7CE9.FCFEC140]
KPN IT Solutions
Platform Organisation Cloud Services
Mail: wouter.hummel...@kpn.com<mailto:wouter.hummel...@kpn.com>
Telefoon: +31 (0)6 1288 2447
P Save Paper - Do you really need to print this e-mail?
KPN IT SOLUTIONS is de 'handelsnaam' voor KPN Corporate Market BV, 
Handelsregister 52959597 Amsterdam
The information transmitted is intended only for use by the addressee and may 
contain confidential and/or privileged material.
Any review, re-transmission, dissemination or other use of it, or the taking of 
any action in reliance upon this information by persons
and/or entities other than the intended recipient is prohibited. If you 
received this in error, please inform the sender and/or addressee immediately
and delete the material. Thank you.

Manage your subscription for the Freeipa-users mailing list:
Go to http://freeipa.org for more info on the project

Reply via email to