In ipa_service_init(), we aren't checking krb5_realm before using ipa_domain. Additionally, the LDAP child for IPA uses only krb5_realm (falling back to the SSSD domain name) instead of the IPA domain.
The IPA auth provider also uses only the krb5_realm and ignores the ipa_domain.
Fields changed
milestone: NEEDS_TRIAGE => SSSD 1.5.2
Fixed by 7cefb94d9f00a5629cb5c12cc71d01208e7ead63 and 9bd24b75f3252817addc052673959bde7cad5ebc
resolution: => fixed status: new => closed
rhbz: => 0
Metadata Update from @sgallagh: - Issue set to the milestone: SSSD 1.5.2
SSSD is moving from Pagure to Github. This means that new issues and pull requests will be accepted only in SSSD's github repository.
This issue has been cloned to Github and is available here: - https://github.com/SSSD/sssd/issues/1846
If you want to receive further updates on the issue, please navigate to the github issue and click on subscribe button.
subscribe
Thank you for understanding. We apologize for all inconvenience.