There was "pam-32bit" installed on the server but without "/lib/security/pam_winbind.so". Removing pam-32bit was the solution.

Thanx for your help Rowland.


Am 18.03.2017 um 13:32 schrieb Rowland Penny via samba:
On Sat, 18 Mar 2017 13:23:29 +0100
Stefan Schäfer via samba <samba@xxxxxxxxxxxxxxx> wrote:

This works for the Administrator account, but I have this Problem
with all users.
It's a user mapping problem?
You are using the winbind 'ad' backend, Have you given Domain Users a
gidNumber attribute containing a number inside the '500-30000' range?
(by the way, this range isn't a good idea, no space for ANY local Unix

Have you also given your users a uidNumber attribute containing a
unique number inside the same range ?


