with pdb backend, the samba debian release has following problem: with account policy "minimum password age" set, instead of the pwd-can-change-time attribute of an account, there ll be used the summ of the password-last-set and the "minimum password age" accpol value - in case of judge/compute logged-in password change requests. i dont really know if it is a bug, but in older version was the can-change-time used.
fixed