Search the docs

Admin CLI Reference: name-service-config

When called without an operation, name-service-config lists the configured name services, as with --list. Operations cannot be combined in one command.

Option Used with Required? Notes

--add

Add a new LDAP name service. Requires --name and --address.

--list

List the configured name services in resolution order, or one name service when given --name, --id, or --internal-id.

--update

Update a configured name service. Requires --name, --id, or --internal-id.

--remove

Remove a configured name service. Requires --name, --id, or --internal-id.

--name <name>

--add, --list, --update, --remove

Required for --add

The management name of the name service. Maximum 255 characters; must be unique (case-insensitive).

--id <uuid>

--list, --update, --remove

Optional

UUID of the name service. Not allowed with --add.

--internal-id <n>

--list, --update, --remove

Optional

Integer ID of the name service. Not allowed with --add.

--new-name <name>

--update

Optional

Rename the name service (management name).

--domain <domain>

--add

Optional

The domain name, for example corp.example.com. If omitted, the --name value is used as the domain name and must be a valid domain name. Must be unique (case-insensitive); cannot be changed later.

--address <host[:port]>

--add, --update

Required for --add

IP address or DNS name of the LDAP server, with an optional port (1–65535). Repeat --address once per server; do not separate addresses with commas. On --update, the addresses given replace all existing addresses. If a port is omitted, the connection test determines it. More than one address works only with --no-connection-test.

--transport-mode <mode>

--add, --update

Optional

LDAP, LDAPS, or STARTTLS (not case-sensitive). If omitted, the connection test tries STARTTLS, then LDAPS, then LDAP, each on port 389 and then 636 when no port is given, and keeps the first that works. Required with --no-connection-test.

--transport-mode-reset

--update

Optional

Clear the transport mode so that the connection test determines it again. Cannot be used with --no-connection-test.

--schema <schema>

--add, --update

Optional

RFC2307 (default) or RFC2307BIS.

--search-base <base>

--add, --update

Optional

Base DN for searches, for example ou=people,dc=corp,dc=example,dc=com. Defaults to the root of the domain. Pass "" to set an empty search base.

--search-base-reset

--update

Optional

Reset the search base to the root of the domain (for example, dc=corp,dc=example,dc=com).

--bind-dn <dn>

--add, --update

Optional

Bind distinguished name for authenticated access. On --add, a plain account name is expanded to cn=<name>,<domain in dc= form>; on --update, give a full DN. Must be given with --bind-secret.

--bind-secret <secret>

--add, --update

Optional

Password for the Bind DN. Must be given with --bind-dn when adding a name service. On --update, give it alone to change only the secret. The Admin CLI does not prompt for it. In 5.3, also required on every --update of a name service that has a Bind DN, except with --bind-clear.

--bind-clear

--update

Optional

Remove the Bind DN and Bind Secret, so that the name service uses anonymous access.

--no-connection-test

--add, --update

Optional

Skip the connection test. Requires --transport-mode and a port on every --address.

--resolution-order <list>

Set the resolution order. Give a comma-separated list of names, UUIDs, or internal IDs, all of the same type. Name services not listed are placed after the listed ones, in no guaranteed order.

--resolve-user <user>

Look up a user through SSSD. An unqualified name (jsmith) is looked up in every configured domain, with a result for each; a qualified name (jsmith@corp.example.com) only in that domain, and an unconfigured domain returns an error.

--resolve-group <group>

Look up a group. Qualified and unqualified names behave as for --resolve-user.

--resolve-user-groups <user>

List the groups a user belongs to. Qualified and unqualified names behave as for --resolve-user.

--test-connect <list>

Run the connection test for one or more configured name services, using their saved settings. Give a name, UUID, or internal ID, or a comma-separated list of identifiers of the same type.