Ah, and of course the SSSD pem file is properly populated:
$ sudo openssl crl2pkcs7 -nocrl -certfile /etc/sssd/pki/sssd_auth_ca_db.pem | openssl pkcs7 -print_certs -noout | grep subject | wc -l 421
Ah, and of course the SSSD pem file is properly populated:
$ sudo openssl crl2pkcs7 -nocrl -certfile /etc/sssd/ pki/sssd_ auth_ca_ db.pem | openssl pkcs7 -print_certs -noout | grep subject | wc -l
421