On Thu, Nov 5, 2020 at 10:56 PM Josh Sonstroem <jsonstro@ucsc.edu> wrote:
Ok, I believe we found the culprit. There had been a new very large group added to the AD hierarchy. With the right combo of debug flags I eventually caught the messages about the group's membership not being over the valid percentage threshold and it would start trying to resync the group and it would not get far enough before it would trigger the watchdog timer again.

Recent versions of SSSD (both 1-16 and 2.x branches) should log journal message in case any service was terminated by internal watchdog.

 
Sigh, once they removed the group everything went quiet.

Other options you could try:
 - ignore_group_members = true
 - increase `timeout` option
 

_______________________________________________
sssd-users mailing list -- sssd-users@lists.fedorahosted.org
To unsubscribe send an email to sssd-users-leave@lists.fedorahosted.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.org