Also do not suggest publishing the private key.
Without a certificate nginx doesn’t start, and without nginx the standard service doesn’t work. To use this custom service, nginx should not listen on port 80.
The sssd.conf must be readable only by root for sssd to start.