Configuring CentOS 8 to query FreeIPA via SSSD/NSS
by JoseCuervo from LinuxQuestions.org on (#56ZP5)
Hello,
I have an IPA domain configured internally on my network, and all new hosts are automatically provisioned to join this domain. They can kinit without issue, but I'm not getting the full power of IPA yet.
I want to be able to query the IPA realm users from any host, but I'm getting bogged down reading the endless documentation and opinions on using nss/sssd and the many ways to implement them.
Can someone give me a super short tl;dr on how you would configure fresh, minimal CentOS8 installations to query a FreeIPA server for user information?
Thank you!


I have an IPA domain configured internally on my network, and all new hosts are automatically provisioned to join this domain. They can kinit without issue, but I'm not getting the full power of IPA yet.
I want to be able to query the IPA realm users from any host, but I'm getting bogged down reading the endless documentation and opinions on using nss/sssd and the many ways to implement them.
Can someone give me a super short tl;dr on how you would configure fresh, minimal CentOS8 installations to query a FreeIPA server for user information?
Thank you!