The only other thing I can think of is the group scope. Please make sureOn Mon, Aug 21, 2017 at 10:24:50AM +1000, Lachlan Musicman wrote:
> On 18 August 2017 at 17:33, Jakub Hrozek <jhrozek@redhat.com> wrote:
>
> Hmmm. Weird. We are still seeing the "AD group not reflected in cache"
> problem and am not seeing evidence of SSSD updating from the IPA server on
> request (via login from other machine, via id command).
>
> We have debug_level = 7 in [pam] and [domain/loremipsum], I have now added
> to [sssd] and [ssh] and will restart.
>
> Is there anything I should be looking out for?
the group is not domain-local, other scopes will do.