Release of Samba 4.12.0

Introduced release Samba 4.12.0, continuing the development branch Samba 4 with a full implementation of the domain controller and Active Directory service, compatible with the Windows 2000 implementation and capable of supporting all Microsoft versions of Windows clients, including Windows 10. Samba 4 is a multifunctional server product that also provides a file server, printing service, and identity server (winbind).

Key changes In Samba 4.12:

  • The embedded implementations of cryptographic functions have been removed from the codebase in favor of using external libraries. It has been decided to use GnuTLS as the main cryptographic library (version 3.4.7 or higher is required). In addition to reducing potential threats related to vulnerabilities discovered in the embedded implementations of cryptographic algorithms, the transition to GnuTLS has also significantly improved performance when using encryption in SMB3. Testing with the CIFS client implementation from Linux kernel 5.3 showed a 3-fold increase in write speed and a 2.5-fold increase in read speed.
  • A new backend for searching SMB shares using the protocol Spotlight, based on the search engine Elasticsearch (previously provided by the backend based on GNOME Tracker). A utility called 'mdfind' has also been added, allowing users to send search queries to any SMB server running the Spotlight RPC service. The default value of the 'spotlight backend' setting has been changed to 'noindex' (for Tracker or Elasticsearch, the values 'tracker' or 'elasticsearch' should be explicitly set).
  • The behavior of the 'net ads kerberos pac save' and 'net eventlog export' operations has been changed so that they no longer overwrite the file, and attempting to export to an existing file will result in an error.
  • In samba-tool, the addition of contact entries for group members has been improved. Previously, the 'samba-tool group addmemers' command could only add users, groups, and computers as new group members, but now it supports adding contacts as group members.
  • In samba-tool, filtering by organizational units (OU, Organizational Unit) or subtree has been enabled. New flags —base-dn and —member-base-dn have been added, allowing operations to be performed only on a specific part of the Active Directory tree, such as within a single OU.
  • A new VFS module 'io_uring' has been added, utilizing the new Linux kernel interface. io_uring for asynchronous input/output. Io_uring supports I/O polling and can work with buffering (the previously proposed "aio" mechanism did not support buffered I/O). When operating with polling enabled, io_uring significantly outperforms aio. Currently, Samba has implemented support for SMB_VFS_{PREAD,PWRITE,FSYNC}_SEND/RECV based on io_uring, and the overhead for maintaining a threadpool in user space has been reduced when using the default VFS backend. To build the VFS module ‘io_uring’, the library is required. liburing and Linux kernel 5.1+.
  • The VFS provides the ability to specify a special value of UTIME_OMIT to mark the need to ignore time in the SMB_VFS_NTIMES() function.
  • Support for the parameter "write cache size" has been removed from smb.conf, as it became meaningless after the implementation of io_uring support.
  • In Samba-DC and Kerberos, support for encryption using the DES algorithm has been discontinued. The weak-crypto code has been removed from Heimdal-DC.
  • The vfs_netatalk module has been removed as it was no longer maintained and became obsolete.
  • The BIND9_FLATFILE backend has been declared obsolete and will be removed in one of the upcoming releases.
  • The zlib library has been included in the build dependencies. The built-in implementation of zlib has been removed from the codebase (the code was based on an old version of zlib, which had encryption support issues).
  • Fuzz testing of the codebase has been established, including in the service
    oss-fuzz. During fuzz testing, many bugs were discovered and fixed.
  • The minimum Python version requirements have been raised from Python
    3.4 to Python 3.5. The ability to build the file server with Python 2 is still retained (before running './configure' and 'make', set the environment variable 'PYTHON=python2').

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster