On Sat, Nov 14, 2020 at 6:02 PM Markus Larsson <qrsbrwn@xxxxxxxxxx> wrote: > Sounds like a horrible experience. It seems circumventable by not caching entire OUs though. They way sssd has been used where I have been it has only cached users actually logging in. That's a single setting in sssd.conf that makes all the difference. > Not saying you're wrong though, I've just never seen the issue over the years. > I have seen early sssd take down an AD domain controller do to aggressively asking for every user but that was many years ago :) Which setting are you referring to? Because a couple of years ago, I couldn't find a graceful way to prevent it. _______________________________________________ devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx