Release of Samba 4.11.0

Introduced release Samba 4.11.0, continuing the development branch Samba 4 with a full implementation of the domain controller and Active Directory service, compatible with the Windows 2000 implementation and capable of supporting all Microsoft versions of Windows clients, including Windows 10. Samba 4 is a multifunctional server product that also provides a file server, printing service, and identity server (winbind).

Key changes in Samba 4.11:

  • By default, the 'prefork' process model is now used, allowing support for a pool of pre-started handler processes. When starting Samba, the ‘—model’ option now accepts the value ‘prefork’ instead of ‘standard’. Previously, a separate child process was launched for each LDAP and NETLOGON client connection, which led to significant memory consumption with a large number of persistent connections. With the ‘prefork’ model, a fixed number of processes is started for LDAP, NETLOGON, and KDC services, which together handle client connections and distribute them among handlers (4 handlers are started by default);
  • In Winbind, the logging of PAM_AUTH and NTLM_AUTH authentication events is now preserved, as well as the reflection in authentication records and the transmission to SamLogon of the attribute ‘logonId’, which contains the login identifier generated for PAM_AUTH and NTLM_AUTH requests;
  • The scheme for returned LDAP referrals now reflects the scheme from the original request; for example, links received via ldap are prefixed with ‘ldap://’, while ldaps ones are prefixed with ‘ldaps://’;
  • A feature has been added to log the duration of DNS operations performed by Bind 9. The output is enabled by specifying the log level ‘dns:10’ in smb.conf;
  • The default Active Directory schema has been updated to version
    2012_R2.
    The old schema can be selected using the ‘—base-schema’ argument. To upgrade existing installations, the samba-tool command ‘domain schemaupgrade’ can be used.
  • The cryptographic library GnuTLS 3.2 has been included as a mandatory dependency, replacing the built-in cryptographic functions in Samba;
  • The command ‘samba-tool contact’ has been added to search for and edit records in the address book stored in LDAP;
  • The command ‘samba-tool [user|group|computer|group|contact] edit’ has improved support for working with national encodings;
  • Samba has been optimized for operation in very large organizations with up to 100,000 users and 120,000 objects;
  • The performance of reindexing (‘samba-tool dbcheck —reindex’) and domain join operations (‘samba-tool domain join’) for large AD domains has been increased;
  • The LDAP server has increased memory efficiency when generating large LDAP responses (for example, when searching for all objects) by eliminating data duplication in memory.
  • A '—backend-store-size' option has been added to 'samba-tool' to define the maximum allowed size of the database (lmdb map).
  • A 'batch_mode' option has been added to LDB, allowing batch operations to be optimized by executing them within a single transaction. Additionally, search performance in large LDB databases has improved, and subtree renaming performance has increased.
  • A VFS module 'ceph_snapshots' has been added, providing support for CephFS snapshots to work with previous versions of files.
  • The method of storing the Active Directory database on disk has been changed. The new format will be automatically applied after upgrading to release 4.11, but in case of a rollback from Samba 4.11 to earlier releases, manual conversion of the format will be required.
  • Support for the SMB1 protocol is disabled by default (the settings ‘client min protocol’ and ‘server min protocol’ are set to SMB2_02), which has been deprecated and is no longer used by Microsoft.
  • A new parameter ‘—option’ has been added to most command-line utilities, such as smbclient and smbcacls, which allows overriding the settings in smb.conf. For example, to change the minimum supported protocol version, you can specify ‘—option=’client min protocol=NT1’ to revert to SMB1.
  • The LanMan and plaintext authentication methods have been deprecated. Support for NTLM, NTLMv2, and Kerberos methods remains unchanged.
  • The DNS backend BIND9_FLATFILE has been deprecated and will be removed in a future release. The ‘rndc command’ option in smb.conf has also been moved to obsolete status.
  • The embedded HTTP server code (Python WSGI), which was previously used to provide the SWAT web interface, has been removed.
  • Support for Python 2 is disabled by default, and Python 3 is now used (to revert to Python 2 support, you must set the environment variable ‘PYTHON=python2’ before running ‘./configure’ and ‘make’ during the Samba build process.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster