encrypted password in sssd.conf

Currently, the password of the “AD search only” account in the /etc/sssd/sssd.conf is not encrypted.

ldap_default_authtok_type = password
ldap_default_authtok = ^Marco$Polo2011$

To change this situation and to encrypt it follow this steps

# yum –y install sssd-tools

# sss_obfuscate -d WMD.EDU
Enter password - ^Marco$Polo2011$
Enter again = ^Marco$Polo2011$ 

The last command command modifies the file changing the following two entries:

ldap_default_authtok_type = obfuscated_password
ldap_default_authtok = AAAQALnUQMEhhj7/reDfWBkSbUrOCvfxuOwJfdOXFxGzUoGS8zOZWCP5jC4BqvcFkBk8q

