Open
Description
I am investigating an ongoing issue. We are working with vendor support also, but we have still not been able to find a solution.
SSSD Version: 2.9.4
OS: RHEL 7/8/9
SSSD is connected upstream to a RedHat IdM (FreeIPA) cluster.
There seems to be two related issues.
- SSSD is being killed by watchdog. We think external load from backups is causing this to happen, but it is still unclear for certain.
- SSSD is not restarted after being killed by Watchdog.
When this happens users become unable to login via SSH. We have tried the following to resolve the issue, but we continue to see SSSD get killed by Watchdog without being restarted.
- Upgrading SSSD to latest version available to RHEL.
- Increasing SSSD timeout.
- Adding 'Restart=on-failure' to the SSSD systemd unit.
- Looking for selinux alerts and setting selinux to permissive.
- Disabling third party security services.
- Validating the configs.
- Reviewing relevant logs.
As a temporary fix we added a cron job to restart the service, but this does not work reliably. I can collect logs, or configs, at request to further this investigation. I am seeking feedback regarding known issues or ways I may continue to look for root cause.
Thank you in advance.
Metadata
Metadata
Assignees
Labels
No labels