You can improve the completion time of the
LDAPSync server task by removing the usercertificate attribute from the synchronization settings. You should only stop syncing usercertificate attributes if there's no need or plan to use certificate-based DE authentication (for example, CAC or smart cards).
To disable the synchronization of the usercertificate attribute:
- Open the ePO console.
- Select Configuration, Server Settings.
- Select the Drive Encryption category.
- Select Manage LDAP Attributes.
- Remove the data from the User Certificate field.
- Save the changes, and then execute the LDAPSync Server Task.
NOTE: The first
LDAPSync execution after you remove the usercertificate attribute will likely take a similar amount of time as previous slow syncs because the task must remove the unnecessary certificate information from the database. Successive tasks should be significantly faster.