Release of Samba 4.24.0

After 6 months of development, the release of Samba 4.24.0 has been presented, continuing the Samba 4 branch with a full implementation of the domain controller and Active Directory service, compatible with the Windows Server implementation and capable of servicing all supported Microsoft versions of Windows clients, including Windows 11. Samba 4 is a multifunctional server product that also provides file server, printing service, and identification server (winbind) implementations. The project's code is written in C and is distributed under the GPLv3 license.

Key changes in Samba 4.24:

  • A new VFS module vfs_aio_ratelimit has been added to limit the intensity (rate-limit) of asynchronous I/O (AIO) operations. Limits can be set in bytes per second or in operations per second. If the specified limit is exceeded, the module begins to introduce artificial delays in asynchronous operations to maintain the specified upper threshold.
  • The VFS module vfs_ceph_new now supports the RPC protocol Keybridge and FSCrypt mode for encrypting data and file names in the CephFS filesystem. Encryption can be enabled at the level of individual directories.
  • The VFS module vfs_streams_xattr, which allows storing NTFS alternate data streams in extended file attributes (xattr) in Linux, has been enhanced with the "streams_xattr:max xattrs per stream" setting, which defines the allowed number of xattrs used for data storage. In Linux, the size of xattrs is limited to 65536 bytes, but the XFS filesystem allows attaching more than one xattr to a single file, enabling the use of multiple xattrs to store up to 1 MB of alternate data.
  • Support for auditing information related to authentication has been implemented. Debugging classes "dsdb_password_audit" and "dsdb_password_json_audit" have been added to log changes to Active Directory attributes: altSecurityIdentities, dNSHostName, msDS-AdditionalDnsHostName, msDS-KeyCredentialLink, and servicePrincipalName.
  • Support for external password management systems Microsoft Entra ID and Keycloak has been added, which utilize the password reset operation (SSPR, password reset) when changing the password without transmitting the old password to the controller. domainTo comply with policies controlling password lifespan, when resetting a password additional parameters ("password policy hints") are transmitted, allowing the operation to be processed as a standard password change. Samba now considers such parameters when applying local password-related policies.
  • Support has been added for the Kerberos PKINIT KeyTrust authentication mechanism, enabling Samba and Heimdal KDC domain controllers to use the "Windows Hello for Business Key-Trust logons" method for PKINIT authentication with self-signed keys. A command for adding and viewing the public key has been added to the samba-tool utility: "user|computer keytrust". Information about the public key is stored in the account using the msDS-KeyCredentialLink attribute.
  • Support for the Kerberos PKINIT protocol extension for key mapping ("Windows Strong and Flexible key mappings") has been added to Samba and Heimdal KDC domain controllers, used during public key authentication. By default, only exact certificate matching is allowed ("strong certificate binding enforcement = full"), but flexible matching ("strong certificate binding enforcement = compatibility") is possible, permitting certificates newer than the user account. Certificate mapping data for the account is stored in the altSecurityIdentities attribute.
  • Support for the "Kerberos PKINIT SID" protocol extension has been added, allowing the use of certificates with Object SID identifiers for authentication. The samba-tool utility has added the command "user|computer generate-csr" for signing certificates.
  • In the KDC (Key Distribution Center) implementation, by default, the PAC (Privilege Attribute Certificate) structure is returned, containing data about the user's privileges, regardless of whether the PA-PAC-REQUEST field is specified in the client's request. A configuration option "kdc always generate pac = no" has been provided to revert to the old behavior.
  • A new setting "kdc require canonicalization" has been added in KDC, which when set to "yes" mandates that clients request user name canonicalization when accessing authentication (AS_REQ). If canonicalization is not requested, the server will return an error "user unknown". In networks with users running Windows OS, enabling this new setting should not cause issues, as Windows clients by default always request canonicalization. server authentication (AS_REQ). If canonicalization is not requested, the server will return an error indicating "user unknown." In networks with users utilizing Windows OS, activating the new setting should not cause any issues, as Windows clients always request canonicalization by default.

    Mandatory canonicalization helps protect against "dollar ticket" attacks, which manipulate the fact that usernames can be specified differently ("user" and "user$") and are treated differently in canonical and standard representations. The essence of the attack is that a malicious actor could create a computer account in AD named "root$" and use it to obtain a ticket from the KDC by sending the username "root" instead of "root$" in the request. The KDC, not finding the user "root", would process the request in the context of the user "root$" and issue a ticket that could be used to connect as the root user via SSH or NFS to a Linux server with SSSD.

  • A workaround option for protecting against "dollar ticket" attacks has been added to the KDC for configurations with mandatory canonical name requests disabled ("kdc require canonicalization = no", which is the default). By default, if the client did not request canonicalization and the checked name is not found, the server performs an additional check by appending the "$" character to the name. With the new setting "kdc name match implicit dollar without canonicalization = no", this behavior can be disabled, allowing only exact checks (in the context of the aforementioned attack, the server will not check the name "root$" when requesting "root").
  • In Heimdal KDC, sending only canonical names (sAMAccountName from PAC) to Kerberos services instead of the original value cname is enabled by default. To revert to the old behavior, the setting "krb5 acceptor report canonical client name = no" can be used.
  • To fully protect against "dollar ticket" attacks, it is recommended to set the following configurations: strong certificate binding enforcement full, kdc always include pac yes, kdc require canonicalization yes.
  • To block the vulnerability CVE-2026-20833, the domain encryption method in the KDC settings has been changed to AES by default (the setting "kdc default domain supported enctypes" is set to "aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha1-96").

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster