Headnode has keytab, there are also 3 login nodes and they have keytab too.  then there are 100 compute nodes which presently do not.

anonymous is clever idea, but i was hoping to instrument compute nodes such that my user and group filters on headnode sssd config would be in effect.  IE the users and groups the headnode sees the computes also see.

of the two the groups is the tricky one as i need special permissions on my host keytab to actually get that data (its not avail anonymously).

thank you for the help i would really like to get this working.

Can you just use anonymous LDAP binds on the other nodes?
