diff --git a/ad-auth/tasks/sssd.yml b/ad-auth/tasks/sssd.yml
index 9ed44f4bca9702527402bffc53ecbf129a129219..7f03caa4a840c5169493ce31774ed5df7e05ca11 100644
--- a/ad-auth/tasks/sssd.yml
+++ b/ad-auth/tasks/sssd.yml
@@ -40,19 +40,10 @@
       tags:
         - sssd
 
-    - name: get a kerberos ticket
-      # yamllint disable-line rule:line-length
-      shell: echo "{{ ad_admin_password_content }}" | kinit Administrator
-      when: debian_version == "jessie"
-      no_log: true
-      tags:
-        - sssd
-
     - name: ensure pexpect is installed
       apt:
         name: python-pexpect
         state: present
-      when: debian_version != "jessie"
       tags:
         - sssd
 
@@ -62,7 +53,6 @@
         responses:
           # yamllint disable-line rule:line-length
           "Passwor(d|t) f(o|ΓΌ)r Administrator.*": "{{ ad_admin_password_content }}"
-      when: debian_version != "jessie"
       no_log: true
       tags:
         - sssd
diff --git a/nfs-client/tasks/main.yml b/nfs-client/tasks/main.yml
index 06dfd10cfcca5ad6ede99b6f089e76d485de82f2..42fd11d2543752e33e14900682049e10a793b2a6 100644
--- a/nfs-client/tasks/main.yml
+++ b/nfs-client/tasks/main.yml
@@ -77,29 +77,6 @@
   tags:
     - nfs-client
 
-- name: ensure the kernel key storage used for idmapping is sufficiently high
-  sysctl:
-    name: kernel.keys.root_maxkeys
-    state: present
-    value: 1000  # default is 200, this quote was reached
-  when: debian_version == "jessie"
-  notify:
-    - reload sysctl
-  tags:
-    - nfs-client
-    - sysctl
-
-- name: stretch has a reasonable default value for the kernel key storage size
-  sysctl:
-    name: kernel.keys.root_maxkeys
-    state: absent
-  when: debian_version == "stretch"
-  notify:
-    - reload sysctl
-  tags:
-    - nfs-client
-    - sysctl
-
 - name: enable rpc-svcgssd iff we use kerberized NFS
   systemd:
     name: rpc-svcgssd.service