This bug is created as a clone of upstream ticket:
SSSD appears to be taking more than 2+ seconds to start and be able to properly respond to queries in an IPA setup.
I saw this in RHEL but, it was suggested that I open an RFE upstream. The version I was using was 1.8.0-17. This was seen on an IPA Master server.
Is it possible to speed this up without sacrificing something?
From Jakub Hrozek's explanation:
SSSD first starts all the back ends (aka domains), then all services
including NSS and PAM. The problem is, that the SSSD IPA domains startup
is taking quite a long time. I added more debugging and it seems that
the biggest culprit is selecting the correct principal from keytab. With
all the debugging on (which admittedly slows things down quite a bit),
one pass of the principal selection function takes more than a second.
For some reason, we are calling the principal selection twice - I assume
that's for identity and authentication parts of the back end but I could
This request was not resolved in time for the current release.
Red Hat invites you to ask your support representative to
propose this request, if still desired, for consideration in
the next release of Red Hat Enterprise Linux.
This request was erroneously removed from consideration in Red Hat Enterprise Linux 6.4, which is currently under development. This request will be evaluated for inclusion in Red Hat Enterprise Linux 6.4.
Marking as verified sanity only after all tests passed for version 1.9.2-82
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.