> client install expects ntpd to be present I'm not quite sure what you mean. "freeipa-client --install" does indeed give NTP errors, but it still proceeds. Here is a transcript of installing freeipa-client inside a (privileged) 16.04 lxd container. root@unifi:~# apt-get install freeipa-client sssd-tools ... root@unifi:~# ipa-client-install --domain IPA.EXAMPLE.COM --mkhomedir -p admin -W Discovery was successful! Client hostname: unifi.int.example.com Realm: IPA.EXAMPLE.COM DNS Domain: IPA.EXAMPLE.COM IPA Server: lon-ipa-1.int.example.com BaseDN: dc=ipa,dc=example,dc=com Continue to configure the system with these values? [no]: yes Synchronizing time with KDC... Attempting to sync time using ntpd. Will timeout after 15 seconds Attempting to sync time using ntpd. Will timeout after 15 seconds Attempting to sync time using ntpd. Will timeout after 15 seconds Attempting to sync time using ntpd. Will timeout after 15 seconds Attempting to sync time using ntpd. Will timeout after 15 seconds Unable to sync time with NTP server, assuming the time is in sync. Please check that 123 UDP port is opened. Password for