This bug is created as a clone of upstream ticket:
as I reported on the mailing list:
The migrate-ds procedure assume that on the source LDAP server ou=people and ou=groups subtrees are flat (they are actually searched with scope=1) while, for example in my deploy, there could be a lot of nested OUs under which to find entries.
I would like the possibility to search in nested ou's.
Created attachment 1076147 [details]
Created attachment 1076149 [details]
IPA server version : ipa-server-4.2.0-11.el7.x86_64
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.