https://jhrozek.fedorapeople.org/sssd/2.2.0/man/sssd-ad.5.html
man 5 sssd-ad
The AD provider is a back end used to connect to an Active Directory server. This provider requires that the machine be joined to the AD domain and a keytab is available. Back end communication occurs over a GSSAPI-encrypted channel, SSL/TLS options should not be used with the AD provider and will be superseded by Kerberos usage.
Почему не используется безопасный LDAPS, с сертификатами?