Hi,
Thanks for the detailed bug report. Upstream added the capability
limitations to the service files in 2.5, and for the old ways we'd need
CAP_DAC_OVERRIDE so it would work with files owned by sssd user while
the daemon is running as root (or so I'm told anyway).
But since the 'run sssd as a non-privileged user' -feature is still not
used in Fedora either, best to make it run as root and change the file
permissions to match.
I've pushed a new version to salsa, could you build and test that in
your environment? The autopkgtest at least passes so the daemon should
work (and didn't on the current version, which I didn't notice, boo).
thanks!
--
t