As there's replication latency between the DCs and password changes can fail - on the way to a DC - on the DC itself - on the way back from the DC - when storing success locally It means maintaining the following 3 or 4 passwords help us to handle these situations without loosing the trust to our primary domain next password (a possible leftover from from a failing password change) current password old password older password In order to reliable authenticate against a DC we try them all before giving up. Currently we only do that for the netlogon secure channel. But we don't do it for kerberos authentiation, which means we can hit temporary problems after changing the machine password.
This bug was referenced in samba master: d79a93b2d4f1beb998cc3eabf5838c343445098f 36f219c945542edda7b7c86c9a5e5fb0bb576ccb 518549419f7f7e91672800e0e59a913eb0b3ee3d e798edafd7b7838d7a4bc2f6075ae2f772781ee2 e772963342173db847271a9ad7fb93778b0f5426 b295880041c12791955f9eba44cd10cdf272573d d09d92c48a894271e1de52fd04470a0ad6b6790a ca02e65347aabd6df7fc0bd0f23646f56153a698 daffb46eabf0320da312112d5826a683d41d81ca 6b606dc1dc47c533737153cdbd64aaafdadfed4c b7776f36d959ca5c678121606f03b203ea6a78f2 856fbd5f1da766ae9e9869b6e10ed0470b877533 ed41f2b7aa53c19d662542e2002804442857c5ca