[Samba] Winbind / Samba auth problem after username change

Julian Zielke jzielke at next-level-integration.com
Wed Sep 7 09:12:35 UTC 2016

Good Morning Rowland,

oh well, the bad side of the Internet... well the samba stuff was implemented by a former co-worker so I've to get into everything he did.

Here’s the information you’ve requested, additionally with my config files I know changed based on the samba wiki:


cat /etc/samba/smb.conf


workgroup = MYDOMAIN

realm = MYDOMAIN.local

netbios name = vmu09tcse01

server string = Samba AD Client Version %v

security = ads

password server = DC03, DC04, DC01, DC02, *

server role = standalone server

idmap uid = 10000-20000

idmap gid = 10000-20000

winbind nss info = template

winbind enum users = yes

winbind enum groups = yes

winbind cache time = 10

winbind use default domain = yes

template homedir = /home/MYDOMAIN.LOCAL/%U

template shell = /bin/bash

client use spnego = yes

client ntlmv2 auth = yes

encrypt passwords = yes

restrict anonymous = 2

domain master = no

local master = no

preferred master = no

os level = 0

# Default idmap config used for BUILTIN and local windows accounts/groups

idmap config *:backend = tdb

idmap config *:range = 2000-9999

# idmap config for domain MYDOMAIN

idmap config MYDOMAIN:backend = rid

idmap config MYDOMAIN:range = 10000-99999


# /etc/nsswitch.conf


# Example configuration of GNU Name Service Switch functionality.

# If you have the `glibc-doc-reference' and `info' packages installed, try:

# `info libc "Name Service Switch"' for information about this file.

passwd: compat winbind

group: compat winbind

shadow:         compat

hosts: files dns mdns4

networks:       files

protocols:      db files

services:       db files

ethers:         db files

rpc:            db files

Sanitized version of user object:

user (strukturell)

organizationalPerson (strukturell)

person (strukturell)

top (abstrakt)




14.09.30828 04:48:05 MESZ (9223372036854775807)



User Rename Test









05.09.2016 16:28:18 MESZ (131175592980000000)




ren_test4 at domain.local



06.09.2016 15:48:37 MESZ (20160906134837.0Z)

05.09.2016 16:28:16 MESZ (20160905142816.0Z)

BTW: when I do

# getent passwd | grep ren_test4

I get:


but when I do: getent passwd ren_test4





