[sssd] domains = LDAP services = nss, pam config_file_version = 2 [nss] filter_groups = root filter_users = root [pam] [domain/LDAP] id_provider = ldap ldap_uri = ldap://{{ ldap_server }}/ ldap_search_base = {{ basedn }} auth_provider = krb5 krb5_server = {{ krb_server }} krb5_realm = {{ ansible_domain | upper }} cache_credentials = true min_id = 10000 max_id = 20000