Default Trust View in FreeIPA is designed to contain only users and groups from trusted domains. It makes zero sense to search overrides for the users from the primary IPA domain in it:
(Sat Jun 23 10:38:36 2018) [sssd[be[xs.ipa.cool]]] [sdap_get_generic_ext_step] (0x0400): calling ldap_search_ext with [(&(objectClass=ipaOverrideAnchor)(ipaAnchorUUID=:IPA:xs.ipa.cool:86f707d6-76c0-11e8-99bc-001a4a62eb77))][cn=Default Trust View,cn=views,cn=accounts,dc=xs,dc=ipa,dc=cool].
Note that it is OK to search users and groups from other IPA domains (when we get to implement IPA-IPA trust) but right now the search for the primary domain user/group overrides is not required and in fact is wrong.
Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD 2.0
to comment on this ticket.
Copyright © 2014-2018 Red Hat
4.0.4 — Documentation