Limitations
-
NFSv4.2 only. LDAP identity mapping is supported on the NFSv4.2 data path only. NFSv3, NFSv4.1, SMB, and S3 are not supported.
-
Cannot coexist with Active Directory in 5.3. LDAP name services and Active Directory cannot be configured on the same cluster at the same time.
-
RFC 2307 and RFC 2307bis schemas only. LDAP entries must include
uidNumberandgidNumberattributes. Other schemas are not supported. -
Anonymous and simple bind only. Kerberos (GSSAPI) and other SASL bind methods are not supported.
-
The domain name cannot be changed. After a name service is created, its domain name is fixed. To use a different domain name, remove the name service and add it again.
-
One domain per name service, and one name service per domain. Two name services cannot use the same domain name, even with different search bases.
-
One server address when the connection test runs. Adding or updating a name service with more than one server address fails when the connection test runs. The GUI always runs the connection test, so in the GUI a name service can have only one address. To configure more than one address, use the Admin CLI with
--no-connection-test,--transport-mode, and a port on every address. See Adding an LDAP Name Service. -
Certificate checking cannot be relaxed. SSSD always requires a trusted LDAP server certificate for LDAPS and StartTLS. This is not configurable.
-
Cache tuning is not configurable. SSSD cache timeouts and refresh intervals are not exposed for configuration in 5.3.
-
SSSD log verbosity is not configurable. SSSD debug levels cannot be set through the GUI, Admin CLI, or API in 5.3.
-
There is no LDAP cache flush. In 5.3, Clear Cache in clears Hammerspace’s own identity-mapping caches but does not expire entries that SSSD has cached from LDAP. Changes made in the LDAP directory are seen when SSSD’s cached entries expire.
-
getentandiddo not resolve LDAP users on the Anvil. See Important Information.
If a configuration change fails to apply, lookups stop until Hammerspace retries. In 5.3, if SSSD cannot be restarted with a new configuration on the primary Anvil, Hammerspace removes /etc/sssd/sssd.conf from that Anvil and raises an SSSD_CONFIG_SYNC_FAILED event. LDAP lookups fail until the next attempt, which Hammerspace makes every 2 minutes, succeeds and the event clears. If you see lookup failures immediately after adding, updating, or removing a name service, check for this event.