This AD DC's domain is very close, in AD DC configurations over a internal ncacn_np pipe and otherwise in the same process via C linking. It is however very expensive to re-create the binding handle per SID->name lookup, so keep a cache. This makes samba-tool netacl sysvolreset and the nss tests much faster.
Created attachment 14194 [details] patch for 4.8 cherry-picked from master
Please also pick for 4.7.
Reassigning to Karolin for inclusion in 4.7 and 4.8.
(In reply to Ralph Böhme from comment #3) Pushed to autobuild-v4-{8,7}-test.
(In reply to Karolin Seeger from comment #4) Pushed to both branches. Closing out bug report. Thanks!