I can confirm above as John. I’ve tested.
DC’s running : Version 4.2.11-SerNet-Debian-9.jessie All works ok. Member servers. Samba 4.1.17 ( everything works ok ) Samba 4.3.6 ( everything works ok ) ( recompiled version from sid ) Samba 4.2.10 ( wbinfo –g works, -u not ) Samba 4.3.7 ( wbinfo –g works, -u not ) ( recompiled version from sid ) Samba 4.3.8 ( wbinfo –g works, -u not ) ( recompiled version from sid ) Samba 4.4.1 ( wbinfo –g works, -u not ) ( recompiled version from experimental ) Samba 4.4.2 ( wbinfo –g works, -u not ) ( recompiled version from samba source ) Added the debian folder and removed unneeded patches. All other testes like : work ok. wbinfo --domain-info=NTDOMAIN wbinfo –p wbinfo -P wbinfo –g wbinfo –s SID wbinfo –n Name wbinfo –g Rowland tested an install from source only (4.4.2), on Debian Jessie. this works. So im thinking maybe its related to teven talloc ldb tdb something like that. Based on the Samba 4.4.2 packages i created and Rowlands install, thats the only difference i found. See also the samba treath: [Samba] FW: Domain member seems to work, wbinfo -u not Part of the debug log. Wbinfino –g success [2016/04/18 13:25:38.723377, 1, pid=14148, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:439(ndr_print_function_debug) wbint_QueryGroupList: struct wbint_QueryGroupList out: struct wbint_QueryGroupList groups : * groups: struct wbint_Principals num_principals : 74 principals: ARRAY(74) principals: struct wbint_Principal sid : S-1-5-21-2934682428-2610421433-476865461-571 type : SID_NAME_DOM_GRP (2) name : * name : 'Allowed RODC Password Replication Group' .. etc etc. 74 groups shown. Wbinfo –u fail [2016/04/18 16:56:38.145224, 10, pid=27010, effective(0, 0), real(0, 0)] ../auth/kerberos/gssapi_helper.c:303(gssapi_unseal_packet) Unsealed 32 bytes, with 76 bytes header/signature. [2016/04/18 16:56:38.145236, 10, pid=27010, effective(0, 0), real(0, 0), class=rpc_cli] ../source3/rpc_client/cli_pipe.c:525(cli_pipe_validate_current_pdu) Got pdu len 140, data_len 24 [2016/04/18 16:56:38.145249, 10, pid=27010, effective(0, 0), real(0, 0), class=rpc_cli] ../source3/rpc_client/cli_pipe.c:975(rpc_api_pipe_got_pdu) rpc_api_pipe: got frag len of 140 at offset 0: NT_STATUS_OK [2016/04/18 16:56:38.145261, 10, pid=27010, effective(0, 0), real(0, 0), class=rpc_cli] ../source3/rpc_client/cli_pipe.c:1075(rpc_api_pipe_got_pdu) rpc_api_pipe: host dc2.internal.domain.tld returned 24 bytes. [2016/04/18 16:56:38.145279, 1, pid=27010, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:439(ndr_print_function_debug) samr_Close: struct samr_Close out: struct samr_Close handle : * handle: struct policy_handle handle_type : 0x00000000 (0) uuid : 00000000-0000-0000-0000-000000000000 result : NT_STATUS_OK [2016/04/18 16:56:38.145362, 5, pid=27010, effective(0, 0), real(0, 0)] ../libcli/smb/smb2_signing.c:93(smb2_signing_sign_pdu) signed SMB2 message [2016/04/18 16:56:38.145697, 1, pid=27010, effective(0, 0), real(0, 0)] ../librpc/ndr/ndr.c:439(ndr_print_function_debug) wbint_QueryUserList: struct wbint_QueryUserList out: struct wbint_QueryUserList users : * users: struct wbint_userinfos num_userinfos : 0x00000000 (0) userinfos: ARRAY(0) result : NT_STATUS_IO_TIMEOUT [2016/04/18 16:56:38.145769, 4, pid=27010, effective(0, 0), real(0, 0), class=winbind] ../source3/winbindd/winbindd_dual.c:1397(child_handler) Finished processing child request 59 Greetz, Louis

