Is there any news on this issue?
I tried the following work-around which unfortunately did not work.
1. On the IPA Server:
]# yum install ipa-server-trust-ad
2. On the IPA Server: Run "ipa-adtrust-install"
]# ipa-adtrust-install
3. On ipa-server: Copy "" to samba server:
]# scp /usr/lib64/samba/pdb/
4. On ipa-server:Create the following CIFS service:
]# ipa service-add cifs/
5. On ipa-server: Create keytab for samba server and copy over to samba server
]# ipa-getkeytab -s -p
cifs/ -k /tmp/samba.keytab
]# scp /tmp/samba.keytab

6. On samba server:
vi /etc/samba/smb.conf
        workgroup = BECKECH
        server string = Samba Server Version %v
        netbios name = FILES0V1

        log file = /var/log/samba/%m.log
        max log size = 50

        realm = BECKE.CH
        kerberos method = dedicated keytab
        dedicated keytab file = FILE:/etc/samba/samba.keytab
        create krb5 conf = no

        security = user

#        passdb backend = ipasam:ldapi://%2fvar%2frun%2fslapd-BECKE-CH.socket
        passdb backend = ipasam:ldaps://

        ldap ssl = off
        ldap suffix = dc=becke,dc=ch
        ldap user suffix = cn=users,cn=accounts
        ldap group suffix = cn=groups,cn=accounts
        ldap machine suffix = cn=computers,cn=accounts

But all this did not help and I always get:
]# smbclient -L -U test--s0-v1%eo885418 -d 10
SPNEGO login failed: Logon failure
session setup failed: NT_STATUS_LOGON_FAILURE

Doing the same against the IPA Server everything works fine:
# smbclient -L -U test--s0-v1%eo885418 -d 10

... Maybe there is something wrong in: "cli_init_creds" ... but now after
hours of research, debugging and testing I will give up and switch to
"tdbsam" which is not optimal but should at least work ...

