No reason more than troubleshooting last night.
I should revert to the very basic setup I was starting with.

new sssd.conf
[root@galaxy sssd]# cat /etc/sssd/sssd.conf 
[sssd]
domains = ENSKEDE.LOCAL
services = nss, pam, pac
config_file_version = 2

[domain/ENSKEDE.LOCAL]
id_provider = ad
auth_provider = ad
access_provider = ad
chpass_provider = ad
cache_credentials = true
ldap_id_mapping = False
enumerate=false

same problem.
New debuglog (sssd -d9 -i 2>&1 | grep kb)
http://pastebin.com/CWPiZkwP


On Tue, Apr 14, 2015 at 7:51 PM, Jakub Hrozek <jhrozek@redhat.com> wrote:
On Tue, Apr 14, 2015 at 07:14:11PM +0200, Ola Nystrom wrote:
> ldap_referrals = false

referrals are already disabled by default with the ad provider btw

> krb5_use_kdcinfo = false

Any particular reason to disable kdcinfo files?

> krb5_store_password_if_offline = true
_______________________________________________
sssd-users mailing list
sssd-users@lists.fedorahosted.org
https://lists.fedorahosted.org/mailman/listinfo/sssd-users



--
Ola Nyström

“OSI model jokes work on so many levels”
— jorge_rbs