У нас примерно так работает:
[sssd]
domains = LDAP
config_file_version = 2
services=nss,pam,sudo,ssh
[nss]
default_shell = /bin/bash
fallback_homedir = /home/%u
filter_groups = root
filter_users = root
[domain/LDAP]
cache_credentials = true
id_provider = ldap
auth_provider = ldap
chpass_provider = ldap
access_provider = ldap
sudo_provider = ldap
ldap_schema = rfc2307bis
ldap_uri = ldap://ad.mycompany.com
ldap_backup_uri = ldap://ad.mycompany.com
ldap_search_base = dc=ad,dc=mycompany,dc=ru
ldap_user_search_base = ou=users,dc=ad,dc=mycompany,dc=ru?subtree?
ldap_group_search_base = ou=user_groups,dc=ad,dc=mycompany,dc=ru?subtree?
ldap_sudo_search_base = ou=sudoers,dc=ad,dc=mycompany,dc=ru
ldap_access_order = host
ldap_pwdlockout_dn = cn=ppolicy,ou=ppolicies,dc=ad,dc=mycompany,dc=ru
ldap_user_ssh_public_key = carLicense
ldap_tls_reqcert = allow
ldap_default_bind_dn = uid=userquery,ou=systems,ou=users,dc=ad,dc=mycompany,dc=ru
ldap_default_authtok = mySuperPassword