HI!
I'm currently testing a custom build of sssd 1.13.4 against OpenLDAP server.
I notice this filter in the log:
(&(objectClass=sudoRole)(modifyTimestamp>=1))
Obviously it's a USN fallback filter since USN attribute is not available on OpenLDAP. But the LDAP syntax of assertion value "1" is wrong and therefore no match.
Ciao, Michael.