Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed)
Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket
Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7
Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name
Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable")
Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #