Trust between Samba 4 AD DC and IPAv3 is not yet possible because Samba 4 AD DC does not support cross-forest trusts yet. Work is ongoing on that one. Once we'll (Samba Team) get cross-forest trusts working in Samba 4 AD DC, this setup will work automatically with IPAv3 cross-forest AD trusts.
SSSD can work with standalone Samba 4 AD DC domain already, either using LDAP or AD provider, it is cross-forest trusts that are not supported in Samba 4 AD DC yet.