如何配置SSSD阻止使用特定后端AD服务器?
Nice to hear you already resolved the issue using ad_server and ad_backup_server! Here are a few other practical approaches to prevent SSSD from reaching those unreachable domain controllers:
1. Explicit Blacklist with ad_server_blacklist
This is the most direct method for targeting specific bad servers. Add the unreachable DCs to this parameter in your SSSD domain configuration (typically in /etc/sssd/sssd.conf under the [domain/example.com] section):
ad_server_blacklist = dc-unreachable-1.example.com, dc-unreachable-2.example.com
After updating the config, restart SSSD to apply changes:
systemctl restart sssd
SSSD will now completely ignore these servers when querying your AD domain.
2. Filter DNS Records Locally
If your DNS is still returning the unreachable DCs in SRV records or domain lookups, you can override this locally:
- Edit
/etc/hosts: Map the problematic DC hostnames to a non-routable IP (like127.0.0.2) to block SSSD from connecting to them. Alternatively, explicitly map your domain to only working DCs. - Use a local DNS server: Tools like dnsmasq let you filter out the bad DCs from your domain's DNS responses. This way, SSSD won't even see those servers during initial discovery.
3. Restrict Discovery to a Specific Subdomain
If the unreachable DCs are in a separate subdomain of your forest, you can limit SSSD's server discovery to a working subdomain with:
ad_discovery_domain = working-subdomain.example.com
This tells SSSD to only look for DCs in the specified subdomain, avoiding the problematic ones elsewhere in the forest.
4. Direct LDAP URI Configuration (LDAP Provider Mode)
If you're using SSSD in LDAP mode (instead of the dedicated AD provider), you can explicitly list only working LDAP URIs and exclude the bad ones:
ldap_uri = ldap://dc-working-1.example.com, ldap://dc-working-2.example.com
Note: This method is only applicable if you're not using the AD provider (which is the recommended setup for Active Directory environments).
Each method has its own use case: ad_server_blacklist is ideal for precise targeting, while DNS-level changes prevent SSSD from ever encountering the bad servers in the first place.
内容的提问来源于stack exchange,提问作者TryTryAgain

