We should probably allow, in future, to configure a trust so that sssd does not use algorithmic mapping ofr SID->[UG]ID translation but instead asks IPA which in turn will look them up from AD.
This should be optional and to be explicitly enabled by IPA admins when the trust is created.
This is a duplicate to #2904.
Metadata Update from @simo:
- Issue assigned to rcritten
- Issue set to the milestone: FreeIPA 3.3 - 2013/05
to comment on this ticket.