I found this bug when setting my own trust environment.
I was unable to match username@subdomain to subdomain. This patch puts
me a step forward. I can match the subdomain now, but I can't get
account info:
[sssd[be[IPA-SUDO-SUBDOMAIN]]] [ipa_s2n_exop_send] (0x0400): Executing
extended operation
[sssd[be[IPA-SUDO-SUBDOMAIN]]] [sdap_get_generic_ext_step] (0x0400):
calling ldap_search_ext with
[objectclass=ipaNTTrustedDomain][cn=trusts,dc=*].
[sssd[be[IPA-SUDO-SUBDOMAIN]]] [ipa_s2n_exop_done] (0x0400):
ldap_extended_operation result: Operations error(1), (null)
[sssd[be[IPA-SUDO-SUBDOMAIN]]] [ipa_s2n_get_user_done] (0x0040): s2n
exop request failed.
[sssd[be[IPA-SUDO-SUBDOMAIN]]] [sdap_id_op_done] (0x0200): communication
error on cached connection, moving to next server
[sssd[nss]] [nss_cmd_getpwnam_dp_callback] (0x0040): Unable to get
information from Data Provider