Clearing the sssd cache make the AD login works for a short while, it's probably not necessary nor "production" ready. Looking at /var/log/sssd/
. I do see offline messages:
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [sdap_id_op_connect_done] (0x0020): Failed to connect, going offline (5 [Input/output error])
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [be_mark_offline] (0x2000): Going offline!
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [be_mark_offline] (0x2000): Enable check_if_online_ptask.
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [be_ptask_enable] (0x0400): Task [Check if online (periodic)]: enabling task
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [be_ptask_schedule] (0x0400): Task [Check if online (periodic)]: scheduling task 65 seconds from now [1502119252]
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [be_run_offline_cb] (0x0080): Going offline. Running callbacks.
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [sdap_id_op_connect_done] (0x4000): notify offline to op #1
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [ipa_subdomains_refresh_connect_done] (0x0020): Unable to connect to LDAP [11]: Resource temporarily unavailable
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [ipa_subdomains_refresh_connect_done] (0x0080): No IPA server is available, cannot get the subdomain list while offline
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [be_ptask_done] (0x0040): Task [Subdomains Refresh]: failed with [1432158212]: SSSD is offline
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [be_ptask_schedule] (0x0400): Task [Subdomains Refresh]: scheduling task 14400 seconds from now [1502133587]
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [sdap_id_release_conn_data] (0x4000): releasing unused connection
(Mon Aug 7 15:19:47 2017) [sssd[be[
domain.ad.com]]] [be_ptask_online_cb] (0x0400): Back end is online
Both my IPA servers looks healthy.AD trust agent/controller server role are installed on both.
ipa trustdomain-find
ad.com does return all of my AD domains on both IPA servers.
Thanks,
Alex