URL: https://github.com/SSSD/sssd/pull/854 Title: #854: LDAP: Do not require START_TLS for loopback connections
simo5 commented: """ @scabrero To be honest I would prefer to write a tool that simply generates a local certificate, adds it to the local machine trust store and gives it to the LDAP server. Then there is no need for exceptions on the SSSD side, and a local attacker can't impersonate the server no matter what. Is that hard to do for some reason ? """
See the full comment at https://github.com/SSSD/sssd/pull/854#issuecomment-515029731