Hello, Jakub,

It seems it was a configuration deficiency. As per https://fedorahosted.org/sssd/ticket/1633#comment:1 seems that explicitly stating which DNS domain to query solves the issue.

I am not sure why it works without the /etc/hosts entry and the configs. I guess it falls back to using the kerberos domain as the DNS suffix if the machine suffix is not available.

Cheers,
Ballock