Do you have the SPNs properly configured? As per the document. Thing is that if you have more servers behind a single A record, RH-6 is not going to work (details? see the document). O.
-----Original Message----- From: sssd-users-bounces@lists.fedorahosted.org [mailto:sssd-users-bounces@lists.fedorahosted.org] On Behalf Of John Beranek Sent: 20 October 2015 14:48 To: End-user discussions about the System Security Services Daemon sssd-users@lists.fedorahosted.org Subject: Re: [SSSD-users] SSSD & AD & Kerberized nfs
On 20 October 2015 at 14:28, Ondrej Valousek Ondrej.Valousek@s3group.com wrote:
Read the document carefully and try again :) IDmapper has a little to do with Kerberos. Care about the *gssd services - they handle Kerberos. RH-6.7 works nicely to me.
Hmm, so it *is* the DNS for the Isilon service causing the issue:
https://gist.github.com/jberanek/f9475d4c0c756ee9e9e4
[Short version: WARNING: Failed to create krb5 context for user with uid 0 for server pool00-21.siteb.isilon.example.com ]
Can't really see how to solve that and leave the Isilon load balancing in place. :(
John