Есть два dc(samba4.2. Debian8) в домене c настроенной репликацией ad и gpo. подключил к домену(sssd realmd) файловый сервер (samba4.2 debian) пользователи опознаются.все путем, но если отключить первичный dc0 то все пользователи теряются, т.е. sssd не берет список пользователей с dc1, как поправить
cat /etc/sssd/sssd.conf
[nss]
filter_groups = root
filter_users = root
reconnection_retries = 3
[pam]
reconnection_retries = 3
use_fully_qualified_names = False
[sssd]
domains = domain.ru
config_file_version = 2
services = nss, pam
[domain/domain.ru]
ad_domain = domain.ru
krb5_realm = domain.RU
realmd_tags = manages-system joined-with-samba
cache_credentials = True
id_provider = ad
krb5_store_password_if_offline = True
default_shell = /bin/bash
ldap_id_mapping = True
use_fully_qualified_names = False
fallback_homedir = /home/%d/%u
access_provider = ad
cat /etc/realmd.conf
[service]
automatic-install = no
[domain.ru]
fully-qualified-names = no
host -t SRV _kerberos._udp.domain.ru.
_kerberos._udp.domain.ru has SRV record 0 100 88 dc1.domain.ru.
_kerberos._udp.domain.ru has SRV record 0 100 88 dc0.domain.ru.
host -t SRV _ldap._tcp.domain.ru.
_ldap._tcp.domain.ru has SRV record 0 100 389 dc1.domain.ru.
_ldap._tcp.domain.ru has SRV record 0 100 389 dc0.domain.ru.
cat /etc/krb5.conf
[libdefaults]
default_realm = DOMAIN.RU
dns_lookup_realm = false
dns_lookup_kdc = true
cat /etc/resolv.conf
search kell.ru
nameserver 192.168.40.1 #dc0
nameserver 192.168.40.2 #dc1