[Freeipa-users] Config applied to SSSd

Alexander Bokovoy abokovoy at redhat.com
Mon Oct 6 10:27:38 UTC 2014

On Mon, 06 Oct 2014, Adam Bishop wrote:
>ipa-client-install on RHEL6-ish distro's configures SSSd as follows:
>    [domain/MYDOMAIN]
>    ...
>    ipa_server = _srv_, ldap01.my.domain
>    ...
>The man page isn't too clear on what is this value used for (or how
>ipa-client-install derives it in a multi-server deployment), or what
>would happen if ldap01 went offline.
_srv_ means using all servers from the SRV record _ldap._tcp.domain,
taking next one is previous one failed. Adding an explicit hostname will
extend this list to include the one if DNS resolution of SRV record or
any of servers the advertised in the SRV record fails.

If all of them will fail, SSSD will go offline and try them again after
it considers going online.

The hostname put by ipa-client-install corresponds to the server to
which this client is enrolled.  You enroll with a single server, after
/ Alexander Bokovoy

