How does it compare to 389 Directory Server? I've been using that with SSSD for user management and authentication in a small LAN with about twenty machines for about ten years. It is rock solid, but every few years when I do an major OS upgrade I have to get deep into the weeds and it always takes me a few days to become familiar with all the backend stuff again. I'm not using Kerberos or single sign on or anything fancy.
389 is afaik full-featured enterprise LDAP server, so I guess the main difference is complexity. One thing to note is that there is also FreeIPA companion project for 389, which a bundles in kerberos, sssd etc that are needed for full auth set-up