Tagged: 

Viewing 1 reply thread
  • Author
    Posts
    • #1557564
      IT Engineer
      Participant
      Member Points: 631
      Rank: 2

      People,

      In CentOS v8 sssd: How to allow specific AD security group like Domain Admins with space in the name to log in while denying everything else?

      This is the /etc/sssd/sssd.conf content:

      [sssd]
      domains = DOMAIN.com
      config_file_version = 2
      services = nss, pam
      
      [domain/DOMAIN.com]
      ad_domain = DOMAIN.com
      krb5_realm = DOMAIN.COM
      realmd_tags = manages-system joined-with-adcli
      cache_credentials = True
      id_provider = ad
      krb5_store_password_if_offline = True
      default_shell = /bin/bash
      ldap_id_mapping = True
      use_fully_qualified_names = True
      fallback_homedir = /home/%u@%d
      access_provider = ldap
      ldap_access_filter = (memberOf=CN=Domain Admins,CN=Users,DC=DOMAIN,dc=com)

      I can only type in the username in Putty as Myself.Admin@DOMAIN.com, but then if the password is correct, I get:

      ---------------------------
      PuTTY Fatal Error
      ---------------------------
      Remote side unexpectedly closed network connection
      ---------------------------
      OK 
      ---------------------------

      Thank you in advance.

    • #1557641
      Steven
      Participant
      Member Points: 1,114
      Rank: 3

      Hello,

      From what I could see, people are using groups without spacing in the CN. Also, have you tried without spacing in Domain Admins by any chance?

      1. https://sssd.io/docs/design_pages/active_directory_access_control.html
      2. https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/5/html/deployment_guide/config-sssd-domain-access
Viewing 1 reply thread
  • You must be logged in to reply to this topic.
© 4sysops 2006 - 2022

CONTACT US

Please ask IT administration questions in the forums. Any other messages are welcome.

Sending

Log in with your credentials

or    

Forgot your details?

Create Account