From looking at the sssd-ad man page, I think there's an entire sssd feature I'm not understanding. Which might be useful here.
SERVICE DISCOVERY
The service discovery feature allows back ends to automatically find the appropriate servers to connect to using a special
DNS query. This feature is not supported for backup servers.
Configuration
If no servers are specified, the back end automatically uses service discovery to try to find a server. Optionally, the user
may choose to use both fixed server addresses and service discovery by inserting a special keyword, “_srv_”, in the list of
servers. The order of preference is maintained. This feature is useful if, for example, the user prefers to use service
discovery whenever possible, and fall back to a specific server when no servers can be discovered using DNS.
The domain name
Please refer to the “dns_discovery_domain” parameter in the sssd.conf(5) manual page for more details.
For these restricted (firewalled-off) network segments, i'd like sssd to attempt to discover AD DCs for this site and then fall back to maybe a couple of hard-coded DCs.
As far as using a new adcli, the adcli version in RHEL7 is 0.8.1-13.el7.x86_64 and the adcli version on RHEL8 is 0.8.2-3.el8.x86_64. So I don't think we'll see acli 0.9.0 until RHEL9 -- circa 2025?
Spike