Linux Issue

SSSD cache and site-affinity mismatch block Active Directory logons after controller failover.

Use this when the Linux host stays joined and users lose auth because the cache and current controller path no longer agree.

The platform is up, but one dependency path is not.

Use this when the Linux host stays joined and users lose auth because the cache and current controller path no longer agree. These issues are easy to misread because the operating system still responds while one control path, runtime dependency, or trust assumption is already out of alignment.

The symptom usually appears downstream from the real change.

  • Linux assumptions are often changed indirectly by updates, policy, hardware changes, or cleanup work that looked harmless at the time.
  • SSSD assumptions are often changed indirectly by updates, policy, hardware changes, or cleanup work that looked harmless at the time.
  • Active Directory assumptions are often changed indirectly by updates, policy, hardware changes, or cleanup work that looked harmless at the time.
  • Authentication assumptions are often changed indirectly by updates, policy, hardware changes, or cleanup work that looked harmless at the time.