Is there a way to list all the members of an AD group ?
getent only return members of the cache :
$ getent group mygroup
mygroup:*toto
$ id tata
uid=xxx(tata) gid=yyy(first_group) groups=zzz(mygroup)
$ getent group mygroup
mygroup:*toto,tata
My /etc/sssd/sssd.conf :
Code: Select all
[sssd]
domains = domain.local
config_file_version = 2
services = nss, pam
[domain/domain.local]
ad_domain = domain.local
krb5_realm = DOMAIN.LOCAL
realmd_tags = manages-system joined-with-samba
cache_credentials = True
id_provider = ad
krb5_store_password_if_offline = True
default_shell = /bin/bash
ldap_id_mapping = True
use_fully_qualified_names = False
fallback_homedir = /home/%d/%u
access_provider = ad