So... I could use some help explaining this.  I finally decided to just
start playing and ended up doing the following:

1) Added passdb backend entries on my member servers pointing to LDAP,
similar to what the PDC/BDC configurations have.

This addition, when viewed from Windows suddenly started displaying
SIDs.  Going back a few emails in this thread someone else brought up
they were seeing this behavior without winbind running.

2) Started up winbind

and everything "appears" to be working now.  So my question is, why?  I
still don't quite understand how all these pieces fit together.  Is it
wrong to have the passdb backend on a member server?



