URL: https://github.com/freeipa/freeipa/pull/823
Title: #823: ipa-kdb: reload certificate mapping rules periodically

dkupka commented:
@sumit-bose Works suspiciously well. I would expect some delay (up to 5 
minutes) between modifying the rule and the change being effective but there's 
Is there a chance it (accidentally) reloads the rules with every TGT request? 
That would probably have undesired performance impact.

