This goal will be achieved by implementing an nssswitch-like architecture, managed through a single file - sursswitch.conf. sursswitch.conf will have a similar layout and role to that of nsswitch.conf.
TODO: expand this:
Understanding how to correctly map between the Unix and Windows NT security models, and narrowing down the best possible places to perform this mapping has taken an extraordinarily long time to crystallise. This has resulted in SURS http://cb1.com/~lkcl/cifs/draft-lkcl-sidtouidmap-00.txt and a first practical, if specifically targetted, implementation of SURS in Winbind (cite winbind ref).