[sssd] domains = ds.tssn.services config_file_version = 2 services = nss, pam, sudo, ssh [domain/ds.tssn.services] default_shell = /bin/bash krb5_store_password_if_offline = True cache_credentials = True krb5_realm = DS.TSSN.SERVICES realmd_tags = manages-system joined-with-adcli id_provider = ad fallback_homedir = /home/%u@%d ad_domain = ds.tssn.services use_fully_qualified_names = False ldap_id_mapping = True access_provider = ad ldap_user_extra_attrs = altSecurityIdentities:altSecurityIdentities ldap_user_ssh_public_key = altSecurityIdentities ldap_use_tokengroups = True