Samba: Authenticated users can change other users' password
samba.org
samba.org
We're using LDAP so we cannot turn that off.
Samba can only use PAM when plaintext passwords are used, which is not supported at all with AD (Samba as standalone requires you to store passwords in it's own database). As an Active Directory server, passwords are stored in the directory with access provided by multiple protocols. This was an issue in the LDAP ACL verification.