(In reply to David Disseldorp from comment #0) > The Apparmor profile should permit winbindd full access to these paths, like > smbd. Hmm, looks like abstractions/samba would be the best place to fix this, as it's included by usr.sbin.smbd and usr.sbin.winbindd . Additionally, Winbind requires /etc/samba/netlogon_creds_cli.tdb rwk access.