This bug is created as a clone of upstream ticket: https://fedorahosted.org/freeipa/ticket/4867 FreeIPA supports [http://www.freeipa.org/page/Trusts trusts with AD] (mostly in AD -> IPA direction, the other direction will be ready when #3125 is closed). When the full AD trust is ready, the implemented interface shall be also used to create trust with other FreeIPA DCs.
It would also be great to be able to only trust a subset of users of another domain. I.e. a group of users.