Am 22.08.2019 16:44, schrieb L.P.H. van Belle via samba:
>>          winbind enum users = yes
>>          winbind enum groups = yes
> Set the 2 enum to no.

Changed this and...

>>          dns_lookup_realm = true
>   dns_lookup_realm = false

also this one; I understand what they do, and I don't rely on either (as 
the host is not bound to any other kerberos domain. The casing is clear; 
I just made the placeholders lowercase. And of course domain is the 
realm, but windows does call it domain. ;-)

Anyway, I restarted winbind, but the logs show that shortly after the 
restart, there was another winbindd_getgroups_state timeout.

I've also checked DNS and network reachability of the DCs from the host 
(one of the DCs isn't at the location of the host, but rather 
tunnelled), but that is definitely correct.

Any other hints on where I might look/what I might try to debug why the 
wb_domain_request_state/wb_child_request_state times out like it 
does/takes so long?

--- Heiko.

