Where should my clients be getting the contents of /etc/openldap/certs from?

I've got one network where my IPA authentications are blazing fast and one where they're ... not. On the slower one, clients' /etc/openldap/certs directories are either missing or empty; on the faster network, clients have certs in these directories.

Is this important, and if so what could be going wrong on my slower network that might cause the certs to not get distributed or created properly?

