Search the docs

Limitations

  • NFSv4.2 only. LDAP identity mapping is supported on the NFSv4.2 data path only. NFSv3, NFSv4.1, SMB, and S3 are not supported.

  • Cannot coexist with Active Directory in 5.3. LDAP name services and Active Directory cannot be configured on the same cluster at the same time.

  • RFC 2307 and RFC 2307bis schemas only. LDAP entries must include uidNumber and gidNumber attributes. Other schemas are not supported.

  • Anonymous and simple bind only. Kerberos (GSSAPI) and other SASL bind methods are not supported.

  • The domain name cannot be changed. After a name service is created, its domain name is fixed. To use a different domain name, remove the name service and add it again.

  • One domain per name service, and one name service per domain. Two name services cannot use the same domain name, even with different search bases.

  • One server address when the connection test runs. Adding or updating a name service with more than one server address fails when the connection test runs. The GUI always runs the connection test, so in the GUI a name service can have only one address. To configure more than one address, use the Admin CLI with --no-connection-test, --transport-mode, and a port on every address. See Adding an LDAP Name Service.

  • Certificate checking cannot be relaxed. SSSD always requires a trusted LDAP server certificate for LDAPS and StartTLS. This is not configurable.

  • Cache tuning is not configurable. SSSD cache timeouts and refresh intervals are not exposed for configuration in 5.3.

  • SSSD log verbosity is not configurable. SSSD debug levels cannot be set through the GUI, Admin CLI, or API in 5.3.

  • There is no LDAP cache flush. In 5.3, Clear Cache in Administration  Directory Services clears Hammerspace’s own identity-mapping caches but does not expire entries that SSSD has cached from LDAP. Changes made in the LDAP directory are seen when SSSD’s cached entries expire.

  • getent and id do not resolve LDAP users on the Anvil. See Important Information.

If a configuration change fails to apply, lookups stop until Hammerspace retries. In 5.3, if SSSD cannot be restarted with a new configuration on the primary Anvil, Hammerspace removes /etc/sssd/sssd.conf from that Anvil and raises an SSSD_CONFIG_SYNC_FAILED event. LDAP lookups fail until the next attempt, which Hammerspace makes every 2 minutes, succeeds and the event clears. If you see lookup failures immediately after adding, updating, or removing a name service, check for this event.