Release of Samba 4.21.0

After 6 months of development, the release of Samba 4.21.0 has been announced, continuing the Samba 4 branch with a full implementation of a domain controller and an Active Directory service compatible with the Windows 2008 implementation and capable of servicing all supported versions of Microsoft Windows clients, including Windows 11. Samba 4 is a multifunctional server product that also provides a file server, printing service, and identification server (winbind).

Key changes in Samba 4.20:

  • The security of processing the 'valid users', 'invalid users', 'read list', and 'write list' has been strengthened. If a user's or group's SID cannot be determined due to a data transmission error, the problematic entry in the lists is not ignored but results in an error output. Non-existent users and groups are ignored.
  • In server LDAP now supports authentication using SASL through Kerberos or NTLMSSP with connections tunneled over TLS (ldaps or starttls). The default setting for 'ldap server require strong auth' now implies the use of SASL over TLS, which is equivalent to setting LdapEnforceChannelBinding in the NTDS settings on the Windows platform.
  • The LDB database implementation used in Samba AD DC is now built as a public library without creating a separate tar archive. The binding with the LDB Modules API for Python, which has been non-functional for several years, has been removed. Unicode handling in LDB has been modified.
  • Some public Samba libraries (dcerpc-samr, samba-policy, tevent-util, dcerpc, samba-hostconfig, samba-credentials, dcerpc_server, and samdb) have been downgraded by default to internal (private) status.
  • The ability to use ldaps from 'winbindd' and 'net ads' has been provided. The 'client ldap sasl wrapping' settings have been updated to support 'starttls' for using STARTTLS on TCP port 389 and 'ldaps' for using TLS on TCP port 636.
  • A new 'dns hostname' option has been added for setting the client name in DNS (default is '[netbios name].[realm]').
  • In Samba AD, password rotation for accounts that use smart cards for login (indicated by the 'smart card require for logon' setting) has been implemented, with the password being used as a fallback when reverting to NTLM or for encrypting the local profile.
  • The 'veto files' and 'hide files' settings can now be defined in association with individual users and groups. For instance, 'hide files: USERNAME = /somefile.txt/'.
  • Automatic keytab updates are ensured after changing the password used for the computer's authentication in the domain (machine password).
  • A new VFS module for the Ceph FS has been added, using the low-level libcephfs API and allowing for higher performance compared to the existing cephfs module. To configure the new module, use the name ‘ceph_new’ instead of ‘ceph’ in smb.conf.
  • Support for managed gMSA (Group Managed Service Account) accounts has been added, corresponding to the functional level of Active Directory Domain Services 2012 (Functional Level 2012). Commands for working with gMSA root keys (KDS), such as 'samba-tool domain kds root_key create' and 'samba-tool domain kds root_key list', have been added to the samba-tool utility.
  • Support for the Active Directory Domain Services 2012R2 functional level (Functional Level 2012R2) has been implemented.
  • Efforts have been made to ensure reproducible builds, allowing confirmation that the binary file was built from the provided source texts. For example, the build result is now independent of locale settings and the directory in which the build occurred.
  • Protection against the reflection of sensitive data in /proc indicated during Samba utility calls has been added, ensuring that this data is not visible in the output of ps or top.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster