That seems to fix the issue. I'm not sure why, but it does. I guess the LDAP server could refer to another server or domain by a name not included in the cert? Even with logging turned way up I could not find any entry that said that though. I may be stuck with using this and other kludge in sssd.conf since it doesn't appear to log what actually happened to cause the failure.

--
Jeff White
HPC Systems Engineer
Information Technology Services - WSU

On 10/02/2017 11:46 AM, Jakub Hrozek wrote:
On Mon, Oct 02, 2017 at 11:39:05AM -0700, Jeff White wrote:
LDAP is working fine.  I can query no problems with ldapsearch search, sssd
just won't accept the exact same certificate.
Sorry, I should have read the logs before replying.

Try adding:
     ldap_referrals = false
to the domain section, please.
_______________________________________________
sssd-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
_______________________________________________
sssd-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to