Adoptable Cookbooks List

Looking for a cookbook to adopt? You can now see a list of cookbooks available for adoption!
List of Adoptable Cookbooks

Supermarket Belongs to the Community

Supermarket belongs to the community. While Chef has the responsibility to keep it running and be stewards of its functionality, what it does and how it works is driven by the community. The chef/supermarket repository will continue to be where development of the Supermarket application takes place. Come be part of shaping the direction of Supermarket by opening issues and pull requests or by joining us on the Chef Mailing List.

Select Badges

Select Supported Platforms

Select Status


sssd_ad (8) Versions 0.4.0

Installs/Configures SSSD for AD integration

cookbook 'sssd_ad', '= 0.4.0', :supermarket
cookbook 'sssd_ad', '= 0.4.0'
knife supermarket install sssd_ad
knife supermarket download sssd_ad
Quality 0%


This cookbook installs SSSD on a Ubuntu system and configures it for Active Directory authentication. It loosely follows the directions found here:

IMPORTANT: This cookbook assumes the system's FQDN (e.g. '') is in /etc/hosts. Joining the domain may fail if this is not the case. See the above link for details.


Tested on Ubuntu 14.04.


  • ['sssd_ad']['access_filter'] - optional ad_access_filter for the joined domain, e.g. "(&(sAMAccountName=jo*)(unixHomeDirectory=*))"
  • ['sssd_ad']['cache_credentials'] - boolean to enable SSSD credential caching; defaults to false
  • ['sssd_ad']['dc'] - the FQDN of the primary domain controller
  • ['sssd_ad']['use_ntp'] - configure NTP to sync with the primary domain controller; defaults to true
  • ['sssd_ad']['join_domain'] - join the system to the domain (requires credentials in a chef-vault item); defaults to false
  • ['sssd_ad']['vault_name'] - name of the data bag containing domain credentials
  • ['sssd_ad']['vault_item'] - name of the chef-vault item containing domain credentials


Add the sssd_ad::default recipe to the node's run list, and set the ['samba']['workgroup'], ['samba']['options']['realm'], and ['sssd_ad']['dc'] attributes. If the system should be joined to the domain automatically, set the join_domain attribute to true and create a chef-vault item containing AD credentials that have appropriate permissions.

Dependent cookbooks

chef-vault ~> 1.0
samba ~> 0.12

Contingent cookbooks

There are no cookbooks that are contingent upon this one.

Foodcritic Metric

0.4.0 failed this metric

FC009: Resource attribute not recognised: /tmp/cook/b7e6cb9ff1b24e0d8ffe0e3a/sssd_ad/recipes/join_domain.rb:33
FC031: Cookbook without metadata file: /tmp/cook/b7e6cb9ff1b24e0d8ffe0e3a/sssd_ad/metadata.rb:1
FC045: Consider setting cookbook name in metadata: /tmp/cook/b7e6cb9ff1b24e0d8ffe0e3a/sssd_ad/metadata.rb:1