Title: #522: Prepare SSSD to support IPA in trust to Samba AD
@jhrozek @sumit-bose I've updated the patches to address Jakub's comments.TDO
lookup should only be performed in the server mode, so I added that. At the server side
there will be ACIs limiting this access to `cn=adtrust agents` members (e.g. SSSD and smbd
on IPA masters) only. I also added a filter `(objectclass=ipaIDObject)` which will be used
by the TDO objects.
I'm going to test it more extensively today.
See the full comment at https://github.com/SSSD/sssd/pull/522#issuecomment-369189670