Estas (mesmas) perguntas foram respondidas em serverfault :
No, I don't think this is possible except with an ugly hack. The only special-case that sssd supports is a different LDAP server for change password operations (with
ldap_chpass_uri
).But what you could do is to use
id_provider=proxy
, configure it to usenslcd
(akanss-pam-ldapd
) and configurenslcd
to use the identity LDAP server. Then configureauth_provider=ldap
and point it to the auth LDAP server.It's not pretty and you would have two LDAP daemons running, but I can't think of another way of solving the problem.