# SSSD integration with PBSpro

**URL:** <https://community.openpbs.org/t/sssd-integration-with-pbspro/174>\
**Category:** Users/Site Administrators\
**Created:** [July 20, 2016, 6:26am UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174 "2016-07-20T06:26:17Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joey](https://avatars.discourse-cdn.com/v4/letter/j/f14d63/32.png) [@Joey](https://community.openpbs.org/u/Joey)\
**Post date:** [July 20, 2016, 6:26am UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/1 "2016-07-20T06:26:17Z")

</div>

Hi guys,  
I’ve installed SSSD service authenticate with windows AD server for user account management. It allow me to create a HPC group and allocate hpc user in the group. I can ssh headnode. It will create /home/user@doman folder as user home directory. But when I switch to the AD user account it won’t let me run the job. It would be greate if anyone can give me some help. Thanks. below are the error information.

qsub: Bad UID for job execution  
qsub: Bad UID for job execution  
qsub: Bad UID for job execution  
qsub: Bad UID for job execution  
qsub: Bad UID for job execution  
qsub: Bad UID for job execution  
qsub: Bad UID for job execution  
qsub: Bad UID for job execution  
qsub: Bad UID for job execution  
qsub: Bad UID for job execution

I am runing 10 job at the same time as a [test.my](http://test.my) job detail are :  
#!/bin/bash

#PBS -l nodes=1:ppn=4,walltime=600

cd $PBS\_O\_WORKDIR

for ((i=100000; i\<200000; i++))  
{  
echo “$i” \>\> test.txt  
}

exit 0;

---

<div class="post-metadata">

**Author:** ![dilip-krishnan](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/dilip-krishnan/32/75_2.png) [@dilip-krishnan](https://community.openpbs.org/u/dilip-krishnan)\
**Post date:** [July 20, 2016, 6:40am UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/2 "2016-07-20T06:40:36Z")

</div>

Hi Joey,  
You need to add users to acl\_roots list to allow users to submit jobs.

To add a user to acl\_roots, you can use following command :  
qmgr -c “set server acl\_roots+=username”

Regards  
Dilip

---

<div class="post-metadata">

**Author:** ![jendker](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/jendker/32/21_2.png) [@jendker](https://community.openpbs.org/u/jendker)\
**Post date:** [July 20, 2016, 1:31pm UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/3 "2016-07-20T13:31:14Z")

</div>

Hmm when I was getting this error:

qsub: Bad UID for job execution

It was because I was starting the job as the root on the server. Try to do it as non root and remember that users on the execution nodes has to have the same name as the user on the server which submits the jobs.

Cheers

---

<div class="post-metadata">

**Author:** ![mkaro](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/mkaro/32/85_2.png) [@mkaro](https://community.openpbs.org/u/mkaro)\
**Post date:** [July 20, 2016, 3:47pm UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/4 "2016-07-20T15:47:03Z")

</div>

See section 14.7.4 of the PBS Pro Administrator’s Guide located here: [http://www.pbsworks.com/SupportGT.aspx?d=PBS-Professional,-Documentation](http://www.pbsworks.com/SupportGT.aspx?d=PBS-Professional,-Documentation)

---

<div class="post-metadata">

**Author:** ![Joey](https://avatars.discourse-cdn.com/v4/letter/j/f14d63/32.png) [@Joey](https://community.openpbs.org/u/Joey)\
**Post date:** [July 20, 2016, 11:12pm UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/5 "2016-07-20T23:12:36Z")

</div>

Hi dilip-krishnan,  
Thanks for your reply. I tried to add the test@domain.local account with qmgr command qmgr -c “set server acl\_roots+=test” or qmgr -c “set server acl\_roots+=test@domain.local” on the headnode. then switch to test user to run the job. Unfortunately it still says : qsub: Bad UID for job execution. Any idea what might be wrong? Thanks

---

<div class="post-metadata">

**Author:** ![dilip-krishnan](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/dilip-krishnan/32/75_2.png) [@dilip-krishnan](https://community.openpbs.org/u/dilip-krishnan)\
**Post date:** [July 21, 2016, 7:34am UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/6 "2016-07-21T07:34:35Z")

</div>

Hi Joey,  
If your PBS server is installed on different machine than from where you are trying to submit the job. The same user should exist on the all the mom nodes and server node. Also please set in server  
qmgr -c “set server flatuid=true”

Regards  
Dilip

---

<div class="post-metadata">

**Author:** ![Joey](https://avatars.discourse-cdn.com/v4/letter/j/f14d63/32.png) [@Joey](https://community.openpbs.org/u/Joey)\
**Post date:** [July 21, 2016, 11:30pm UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/7 "2016-07-21T23:30:59Z")

</div>

Hi dilip-krishnan,  
Thanks for your reply.We have four servers in total. One headnode which we submit job from. The other three are all compute node. I am trying to use System Security Services Daemon (SSSD) authenticate user against our AD so that user can ssh to the headnode with AD credential instead of maintaining local /etc/passwd. The authentication process works fine on the headnode or compute node. I can ssh with AD credential to headnode or compute node. But when submit job with AD account ie. test@domain.local,it complained :qsub: Bad UID for job execution.  
I tried to add the test@domain.local account with both qmgr command qmgr -c “set server acl\_roots+=test” and qmgr -c “set server acl\_roots+=test@domain.local” still get the same error.I tried qmgr -c “set server flatuid=true” this tiem is different error :qsub: Unauthorized Request .Please help. Thanks

---

<div class="post-metadata">

**Author:** ![dilip-krishnan](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/dilip-krishnan/32/75_2.png) [@dilip-krishnan](https://community.openpbs.org/u/dilip-krishnan)\
**Post date:** [July 23, 2016, 7:36am UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/8 "2016-07-23T07:36:45Z")

</div>

Hi Joey,  
Please share excerpt from server log for unauthorized request. If logs doesn’t have much information, then please increase the log level and repeat the scenario.

Also not relevant to the question, but are you able to ssh from head node to compute node using  
AD user account, i.e firs login to headnode with AD user account and then do ssh to compute node and vice versa.

Regards  
Dilip

---

<div class="post-metadata">

**Author:** ![Joey](https://avatars.discourse-cdn.com/v4/letter/j/f14d63/32.png) [@Joey](https://community.openpbs.org/u/Joey)\
**Post date:** [July 26, 2016, 11:47pm UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/9 "2016-07-26T23:47:05Z")

</div>

Hi Dilip,  
Sorry for the late reply. I was stuck with some other project. Below are the server\_log after I ran the job with ad account agagin. Basicly all the jobs been rejected by the server. I checked the reference for the code=15023, (Missing userID, username, or GID). I am not sure if PBS support user account authenticated by AD through SSSD service. BTW,the AD account can passwordless ssh between headnode and compute node.

07/27/2016 09:05:00;0040;Server@cciavmlhpct1;Svr;cciavmlhpct1;Scheduler sent command 3  
07/27/2016 09:05:00;0040;Server@cciavmlhpct1;Svr;cciavmlhpct1;Scheduler sent command 0  
07/27/2016 09:05:00;0100;Server@cciavmlhpct1;Req;;Type 21 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:05:00;0100;Server@cciavmlhpct1;Req;;Type 81 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:05:00;0100;Server@cciavmlhpct1;Req;;Type 71 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:05:00;0100;Server@cciavmlhpct1;Req;;Type 58 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:05:00;0100;Server@cciavmlhpct1;Req;;Type 20 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:05:00;0100;Server@cciavmlhpct1;Req;;Type 51 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:15:00;0040;Server@cciavmlhpct1;Svr;cciavmlhpct1;Scheduler sent command 3  
07/27/2016 09:15:00;0040;Server@cciavmlhpct1;Svr;cciavmlhpct1;Scheduler sent command 0  
07/27/2016 09:15:00;0100;Server@cciavmlhpct1;Req;;Type 21 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:15:00;0100;Server@cciavmlhpct1;Req;;Type 81 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:15:00;0100;Server@cciavmlhpct1;Req;;Type 71 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:15:00;0100;Server@cciavmlhpct1;Req;;Type 58 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:15:00;0100;Server@cciavmlhpct1;Req;;Type 20 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:15:00;0100;Server@cciavmlhpct1;Req;;Type 51 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:25:00;0040;Server@cciavmlhpct1;Svr;cciavmlhpct1;Scheduler sent command 3  
07/27/2016 09:25:00;0040;Server@cciavmlhpct1;Svr;cciavmlhpct1;Scheduler sent command 0  
07/27/2016 09:25:00;0100;Server@cciavmlhpct1;Req;;Type 21 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:25:00;0100;Server@cciavmlhpct1;Req;;Type 81 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:25:00;0100;Server@cciavmlhpct1;Req;;Type 71 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:25:00;0100;Server@cciavmlhpct1;Req;;Type 58 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:25:00;0100;Server@cciavmlhpct1;Req;;Type 20 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:25:00;0100;Server@cciavmlhpct1;Req;;Type 51 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:35:00;0040;Server@cciavmlhpct1;Svr;cciavmlhpct1;Scheduler sent command 3  
07/27/2016 09:35:00;0040;Server@cciavmlhpct1;Svr;cciavmlhpct1;Scheduler sent command 0  
07/27/2016 09:35:00;0100;Server@cciavmlhpct1;Req;;Type 21 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:35:01;0100;Server@cciavmlhpct1;Req;;Type 81 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:35:01;0100;Server@cciavmlhpct1;Req;;Type 71 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:35:01;0100;Server@cciavmlhpct1;Req;;Type 58 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:35:01;0100;Server@cciavmlhpct1;Req;;Type 20 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:35:01;0100;Server@cciavmlhpct1;Req;;Type 51 request received from Scheduler@cciavmlhpct1, sock=16  
07/27/2016 09:44:32;0100;Server@cciavmlhpct1;Req;;Type 0 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:32;0100;Server@cciavmlhpct1;Req;;Type 49 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:32;0100;Server@cciavmlhpct1;Req;;Type 21 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:32;0100;Server@cciavmlhpct1;Req;;Type 1 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0080;Server@cciavmlhpct1;Req;req\_reject;Reject reply code=15023, aux=0, type=1, from jcao@cciamr.local@cciavmlhpct1  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 0 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 49 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 21 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 1 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0080;Server@cciavmlhpct1;Req;req\_reject;Reject reply code=15023, aux=0, type=1, from jcao@cciamr.local@cciavmlhpct1  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 0 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 49 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 21 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 1 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0080;Server@cciavmlhpct1;Req;req\_reject;Reject reply code=15023, aux=0, type=1, from jcao@cciamr.local@cciavmlhpct1  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 0 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 49 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 21 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 1 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0080;Server@cciavmlhpct1;Req;req\_reject;Reject reply code=15023, aux=0, type=1, from jcao@cciamr.local@cciavmlhpct1  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 0 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 49 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 21 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 1 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:33;0080;Server@cciavmlhpct1;Req;req\_reject;Reject reply code=15023, aux=0, type=1, from jcao@cciamr.local@cciavmlhpct1  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 0 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 49 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 21 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 1 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0080;Server@cciavmlhpct1;Req;req\_reject;Reject reply code=15023, aux=0, type=1, from jcao@cciamr.local@cciavmlhpct1  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 0 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 49 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 21 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 1 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0080;Server@cciavmlhpct1;Req;req\_reject;Reject reply code=15023, aux=0, type=1, from jcao@cciamr.local@cciavmlhpct1  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 0 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 49 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 21 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 1 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0080;Server@cciavmlhpct1;Req;req\_reject;Reject reply code=15023, aux=0, type=1, from jcao@cciamr.local@cciavmlhpct1  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 0 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 49 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 21 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 1 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0080;Server@cciavmlhpct1;Req;req\_reject;Reject reply code=15023, aux=0, type=1, from jcao@cciamr.local@cciavmlhpct1  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 0 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 49 request received from jcao@cciamr.local@cciavmlhpct1, sock=19  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 21 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0100;Server@cciavmlhpct1;Req;;Type 1 request received from jcao@cciamr.local@cciavmlhpct1, sock=16  
07/27/2016 09:44:33;0080;Server@cciavmlhpct1;Req;req\_reject;Reject reply code=15023, aux=0, type=1, from jcao@cciamr.local@cciavmlhpct1

---

<div class="post-metadata">

**Author:** ![dilip-krishnan](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/dilip-krishnan/32/75_2.png) [@dilip-krishnan](https://community.openpbs.org/u/dilip-krishnan)\
**Post date:** [July 27, 2016, 4:51pm UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/10 "2016-07-27T16:51:36Z")

</div>

Hi Joey,  
You are right that PBS doesn’t currently support SSSD. Looking at the log, the user submitting the  
job is also not in correct format , instead of user as user@hostname, PBS server is getting user@lhostname@something. Internally PBS consider everything after @ as hostname. This could be one of the reason why PBS is not able to authorize the qsub request.

---

<div class="post-metadata">

**Author:** ![taco](https://avatars.discourse-cdn.com/v4/letter/t/ec9cab/32.png) [@taco](https://community.openpbs.org/u/taco)\
**Post date:** [July 27, 2016, 6:48pm UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/11 "2016-07-27T18:48:27Z")

</div>

We are using pbspro (version 13.1) with SSSD. It works for us. This looks more  
like some kind of mis configuration, could be a username or hostname with an @ in it.

Taco

---

<div class="post-metadata">

**Author:** ![Joey](https://avatars.discourse-cdn.com/v4/letter/j/f14d63/32.png) [@Joey](https://community.openpbs.org/u/Joey)\
**Post date:** [July 28, 2016, 12:27am UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/12 "2016-07-28T00:27:39Z")

</div>

Hi Taco,  
This is how we configure the SSSD. Please advise where it went wrong. Many thanks  
First, install the realmd package:

1. 
# yum install -y realmd
2. 
# realm discover cciamr.local

cciamr.local  
type: kerberos  
realm-name: CCIAMR.LOCAL  
domain-name: cciamr.local  
configured: no  
server-software: active-directory  
client-software: sssd  
required-package: oddjob  
required-package: oddjob-mkhomedir  
required-package: sssd  
required-package: adcli  
required-package: samba-common  
3.# yum install -y oddjob oddjob-mkhomedir sssd adcli samba-common  
4 # realm join --user=jcao.da cciamr.local  
5 add the default domain suffix to the sssd configuration file:  
vim /etc/sssd/sssd.conf  
domains = cciamr.local  
config\_file\_version = 2  
services = nss, pam  
#default\_domain\_suffix = cciamr.local  
[domain/cciamr.local]  
ad\_domain = cciamr.local  
krb5\_realm = CCIAMR.LOCAL  
realmd\_tags = manages-system joined-with-samba  
cache\_credentials = True  
id\_provider = ad  
krb5\_store\_password\_if\_offline = True  
default\_shell = /bin/bash  
ldap\_id\_mapping = True  
use\_fully\_qualified\_names = True  
fallback\_homedir = /home/%u@%d  
access\_provider = simple  
6 # service sssd restart  
7 # realm permit -g hpc@cciamr.local  
8 # realm discover cciamr.local  
cciamr.local  
type: kerberos  
realm-name: CCIAMR.LOCAL  
domain-name: cciamr.local  
configured: kerberos-member  
server-software: active-directory  
client-software: sssd  
required-package: oddjob  
required-package: oddjob-mkhomedir  
required-package: sssd  
required-package: adcli  
required-package: samba-common  
login-formats: %U@cciamr.local  
login-policy: allow-permitted-logins  
permitted-logins:  
permitted-groups: hpc@cciamr.local

BTW. I can ssh to the headnode with AD user account in hpc group and ssh from headnode to compute node too.

---

<div class="post-metadata">

**Author:** ![dilip-krishnan](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/dilip-krishnan/32/75_2.png) [@dilip-krishnan](https://community.openpbs.org/u/dilip-krishnan)\
**Post date:** [July 28, 2016, 7:06am UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/13 "2016-07-28T07:06:42Z")

</div>

Hi Joey,  
Not sure, but I guess setting login-formats as ‘%U’ and use\_full\_qualified\_names=False  
can work. But that is just a rough guess.

Regards  
Dilip

---

<div class="post-metadata">

**Author:** ![taco](https://avatars.discourse-cdn.com/v4/letter/t/ec9cab/32.png) [@taco](https://community.openpbs.org/u/taco)\
**Post date:** [July 28, 2016, 6:46pm UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/14 "2016-07-28T18:46:56Z")

</div>

We don’t use AD as backend but LDAP, but that should not make much difference.  
Dilip’s suggestions seem like something you should try.

Also, the fallback\_homedir is odd for unix based directories, but that is another guess  
and I see %U and %u both used, not sure if that matters but good to look into.

Another question is: what do you use to log in, user@domain or just user?

Let us know how this works out,

Taco

---

<div class="post-metadata">

**Author:** ![Joey](https://avatars.discourse-cdn.com/v4/letter/j/f14d63/32.png) [@Joey](https://community.openpbs.org/u/Joey)\
**Post date:** [July 29, 2016, 6:17am UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/15 "2016-07-29T06:17:09Z")

</div>

Hi guys,  
Thanks for your reply. Before any change in sssd.conf. I ssh to server with username instead of username@domain. I got the home directory /home/user@domain. Now I removed #default\_domain\_suffix = cciamr.local, set login-formats as ‘%u’ and use\_full\_qualified\_names=“False” in sssd.conf. Restart the service. I ssh with user, got the /home/user directory. Now the job is working. Thanks for your help. guys 😊

---

<div class="post-metadata">

**Author:** ![taco](https://avatars.discourse-cdn.com/v4/letter/t/ec9cab/32.png) [@taco](https://community.openpbs.org/u/taco)\
**Post date:** [July 29, 2016, 6:41pm UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/16 "2016-07-29T18:41:24Z")

</div>

Good that you have things working now, this one was kind of complicated to figure out.

Taco

---

<div class="post-metadata">

**Author:** ![vincent718](https://avatars.discourse-cdn.com/v4/letter/v/f9ae1b/32.png) [@vincent718](https://community.openpbs.org/u/vincent718)\
**Post date:** [February 25, 2020, 12:29am UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/17 "2020-02-25T00:29:06Z")

</div>

Hello Guys,  
I have a similar problem only that in my case the job status says ‘H’

Following the information above I created a test queue but still job status says ‘H’. Below is my queue configuration

qmgr -c ‘p q test’

# 

Create queues and set their attributes.

# 

# 

Create and define queue test

# 

create queue test  
set queue test queue\_type = Execution  
set queue test acl\_user\_enable = True  
set queue test acl\_users = dummyuser  
set queue test acl\_users += users  
set queue test acl\_group\_enable = True  
set queue test acl\_groups = domain  
set queue test acl\_groups += users  
set queue test enabled = True  
set queue test started = True

By the way , our cluster uses ROCKS 7 . Could that also be a factor?

---

<div class="post-metadata">

**Author:** ![mkaro](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/mkaro/32/85_2.png) [@mkaro](https://community.openpbs.org/u/mkaro)\
**Post date:** [February 25, 2020, 7:50pm UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/18 "2020-02-25T19:50:34Z")

</div>

Hello @vincent718,

Please share the output of “qstat -f [jobid]” and “tracejob [jobid]” for one of the held jobs.

Thanks!

---

<div class="post-metadata">

**Author:** ![vincent718](https://avatars.discourse-cdn.com/v4/letter/v/f9ae1b/32.png) [@vincent718](https://community.openpbs.org/u/vincent718)\
**Post date:** [February 26, 2020, 9:34am UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/19 "2020-02-26T09:34:03Z")

</div>

**Tracejob**  
tracejob: Couldn’t find Job Id 109871.master1.local in logs of past 1 day

**qstat -f [jobid]**  
Job Id: 109871.master1.local  
Job\_Name = test.sh  
Job\_Owner = ztest@login.local  
job\_state = H  
queue = workq  
server = master1.local  
Checkpoint = u  
ctime = Wed Feb 26 09:29:07 2020  
Error\_Path = login.local:/home/ztest/error.txt  
Hold\_Types = s  
Join\_Path = n  
Keep\_Files = n  
Mail\_Points = a  
mtime = Wed Feb 26 09:29:13 2020  
Output\_Path = login.local:/home/ztest/out.txt  
Priority = 0  
qtime = Wed Feb 26 09:29:07 2020  
Rerunable = True  
Resource\_List.mem = 2097152kb  
Resource\_List.mpiprocs = 2  
Resource\_List.ncpus = 2  
Resource\_List.nodect = 1  
Resource\_List.nodes = 1:ppn=2  
Resource\_List.place = scatter  
Resource\_List.select = 1:ncpus=2:mem=2097152KB:mpiprocs=2  
stime = Wed Feb 26 09:29:13 2020  
substate = 20  
Variable\_List = PBS\_O\_HOME=/home/ztest,PBS\_O\_LANG=en\_US.UTF-8,  
PBS\_O\_LOGNAME=ztest,  
PBS\_O\_PATH=/usr/local/bin:/usr/bin:/usr/local/sbin:/usr/sbin:/opt/ibut  
ils/bin:/opt/pbs/bin:/opt/apps/htop/2.0.2:/home/ztest/.local/bin:/home/  
ztest/bin,PBS\_O\_MAIL=/var/spool/mail/ztest,PBS\_O\_SHELL=/bin/bash,  
PBS\_O\_WORKDIR=/home/ztest,PBS\_O\_SYSTEM=Linux,PBS\_O\_QUEUE=workq,  
PBS\_O\_HOST=login.local  
comment = job held, too many failed attempts to run  
run\_count = 21  
Exit\_status = -10  
Submit\_arguments = test.sh  
project = \_pbs\_project\_default

---

<div class="post-metadata">

**Author:** ![mkaro](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/mkaro/32/85_2.png) [@mkaro](https://community.openpbs.org/u/mkaro)\
**Post date:** [February 26, 2020, 4:16pm UTC](https://community.openpbs.org/t/sssd-integration-with-pbspro/174/20 "2020-02-26T16:16:09Z")

</div>

> [@vincent718](#):
>
> comment = job held, too many failed attempts to run

The tracejob output would be helpful to diagnose the above portion of the output. The scheduler found resources for the job, the server sent the job to MoM for execution, and MoM refused to run the job. After this happens 20 times, a hold is placed on the job. Please take a look at the MoM logs to figure out why it is refusing to run the job.

[Next page](https://community.openpbs.org/t/sssd-integration-with-pbspro/174.md?page=2)
