Samba 4.14.0 Release

The release of Samba 4.14.0 has been announced, continuing the development of the Samba 4 branch with a full implementation of the domain controller and Active Directory service, compatible with the Windows 2000 implementation and capable of servicing all supported Microsoft Windows client versions, including Windows 10. Samba 4 is a multifunctional server product that also provides file server, printing service, and identity server (winbind) implementation.

Key changes in Samba 4.14:

  • A significant modernization of the VFS layer has taken place. Historically, the code implementing the file server server was tied to file path processing, which was also used for the SMB2 protocol, switched to using descriptors. In Samba 4.14.0, the code providing access to the server's file system is rewritten to use file descriptors rather than file paths. For instance, the fstat() call is utilized instead of stat() and SMB_VFS_FSTAT() instead of SMB_VFS_STAT().
  • The reliability of printer publishing in Active Directory has been enhanced, and additional information about printers passed to Active Directory has been expanded. Support for Windows printer drivers on ARM64 systems has been added.
  • The ability to use Group Policy for Winbind clients has been provided. The Active Directory administrator can now define policies that modify sudoers settings or add periodic job executions via cron. To enable the application of Group Policies for the client in smb.conf, the setting ‘apply group policies’ is included. Policy application occurs every 90-120 minutes. In case of issues, changes can be undone with the command ‘samba-gpupdate —unapply’ or reapplied with the command ‘samba-gpupdate —force’. To view the policies that will be applied to the system, the command ‘samba-gpupdate —rsop’ can be used.
  • The requirements for the Python language version have been raised. For building Samba, having Python version 3.6 or higher is now mandatory. Support for building with older Python releases has been discontinued.
  • The samba-tool utility provides tools for managing objects in Active Directory (users, computers, groups). You can now use the 'add' command to add a new object in AD, in addition to 'create'. The 'rename' command is supported for renaming users, groups, and contacts. The command 'samba-tool user unlock' is offered for unlocking users. The 'samba-tool user list' and 'samba-tool group listmembers' commands now include the options '--hide-expired' and '--hide-disabled' to hide expired or disabled user accounts.
  • In the CTDB component, which is responsible for handling cluster configurations, offensive terms have been cleaned up. Instead of master and slave, when configuring NAT and LVS, it is now recommended to use 'leader' for the main node in a group and 'follower' for the other group members. The command 'ctdb natgw master' has been replaced with 'ctdb natgw leader'. To indicate that a node is not the leader, the flag 'follower-only' is now displayed instead of 'slave-only'. The command 'ctdb isnotrecmaster' has been removed.

Additionally, clarification has been provided regarding the boundaries of the GPL license under which the Samba code is distributed, specifically concerning VFS (Virtual File System) components. The GPL license requires that all derivative works be made available under the same terms. Samba includes an interface for connecting plugins that allows external code to be invoked. Some of these plugins are VFS modules that use header files shared with Samba for API definitions, through which services implemented in Samba can be accessed, making it necessary for Samba's VFS modules to be distributed under the GPL or a compatible license.

There is uncertainty regarding third-party libraries accessed by VFS modules. In particular, it has been suggested that VFS modules can only use libraries licensed under GPL or compatible licenses. Samba developers clarified that the libraries do not invoke Samba code through the API and do not access internal structures, so they cannot be considered derivative works and are not subject to distribution under GPL-compatible licenses.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster