Without a certificate nginx doesn’t start, and without nginx the standard service doesn’t work. To use this custom service, nginx should not listen on port 80.
The sssd.conf must be readable only by root for sssd to start.