abbra commented on a pull request
NACK. This is wrong.
In the case of external trust to a child domain we cannot run
netr_DsRGetForestTrustInformation() against the child domain, regardless what
credentials we have. Instead, we should run this request against the forest
root domain using the credentials specified by the user.
See the full comment at
Manage your subscription for the Freeipa-devel mailing list:
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code