Important Information
Identity mapping only — not administrator authentication. The LDAP name service resolves Unix user and group identities (UID and GID) for the NFS data path. It does not authenticate administrators logging in to the Hammerspace GUI, Admin CLI, or API.
Hammerspace manages SSSD for you. When you add, update, reorder, or remove a name service, Hammerspace regenerates the SSSD configuration and distributes it to every Anvil. Do not edit SSSD files on an Anvil; Hammerspace overwrites them. For how the configuration is owned, and why a missing /etc/sssd/sssd.conf can be normal, see How Hammerspace Manages SSSD on the Anvils.
Checking lookups from the Anvil. Standard Linux commands such as getent passwd and id, run in a shell on an Anvil, do not resolve LDAP users. Hammerspace resolves names for NFS inside its own services, not through the Anvil’s system name-service switch. To check that identities resolve, use User/Group Lookup in the GUI or the --resolve-user, --resolve-group, and --resolve-user-groups options of name-service-config. On NFS client machines, getent and id work as usual.
LDAPS and StartTLS certificates are checked differently by the connection test and at run time. The connection test that runs when you add or update a name service checks only that the server certificate names the address you configured. Lookups made after the name service is saved use SSSD, which also requires the certificate to chain to a CA that the Anvil trusts. A name service can therefore pass the connection test and still fail every lookup. Add the issuing CA to the Hammerspace trust store before you add the name service. See Securing LDAP Connections with LDAPS or StartTLS.
LDAP and Active Directory are mutually exclusive in 5.3. A cluster that has joined Active Directory cannot use LDAP name services, and a cluster that has an LDAP name service cannot join Active Directory. To switch, remove every LDAP name service before joining Active Directory, or leave Active Directory before adding an LDAP name service. In the GUI, Add LDAP Nameserver is unavailable while Active Directory is joined, and Add Active Directory is unavailable while any directory service is configured.
The bind secret is stored obfuscated. If you configure a Bind DN and Bind Secret, Hammerspace stores the secret in obfuscated form in its database and in the SSSD configuration on the Anvils, never returns it in GUI, CLI, or API output, and replaces it with REDACTED in support bundles. When you pass the secret to name-service-config with --bind-secret, it is part of the command line, so use an account whose only permission is to read the directory.
Resolution order matters when more than one domain is configured. SSSD queries the domains in the configured order. If the same unqualified user or group name exists in more than one domain, the entry from the first domain in the order is used. Qualify names (user@domain) or configure the order carefully if your domains have overlapping names.
Health monitoring can take up to 24 hours to report a failure. Once a day, Hammerspace tests the connection to every name service. A service that fails this test changes to operational state DOWN, and a NAME_SERVICE_UNHEALTHY event is raised. Every 10 minutes, Hammerspace re-tests services that are not UP, and returns a service to UP (clearing the event) when its test passes. A server that stops responding can therefore show UP for up to 24 hours. To check a name service immediately, see Testing the Connection to a Name Service.