Release of Samba 4.13.0

Introduced release Samba 4.13.0, continuing the development branch Samba 4 with a full implementation of the domain controller and Active Directory service, compatible with the Windows 2000 implementation and capable of supporting all Microsoft versions of Windows clients, including Windows 10. Samba 4 is a multifunctional server product that also provides a file server, printing service, and identity server (winbind).

Key changes in Samba 4.13:

  • Added protection against the vulnerability ZeroLogon (CVE-2020-1472), allowing an attacker to gain administrator rights on the domain controller in systems not using the configuration 'server schannel = yes'.
  • Minimum Python version requirements have been raised from Python 3.5 to Python 3.6. The ability to build the file server with Python 2 is still retained (before running './configure' and 'make', the environment variable 'PYTHON=python2' should be set), but it will be removed in the next branch, and having Python 3.6 will be mandatory for building.
  • The functionality 'wide links = yes', which allows file server administrators to create symbolic links outside of the current SMB/CIFS share, has been moved from smbd to a separate module 'vfs_widelinks'. Currently, this module is automatically loaded when the 'wide links = yes' parameter is present in the settings. In the future, support for 'wide links = yes' is planned to be removed due to security issues, and Samba users are strongly urged to switch to using external FS mounts via 'mount --bind' instead of 'wide links = yes'.
  • Support for the classic domain controller mode has been deprecated. Users of NT4-like domain controllers ('classic') should switch to using Samba Active Directory domain controllers to be able to work with modern Windows clients.
  • Unsafe authentication methods that can only be used with the SMBv1 protocol have been deprecated: 'domain logons', 'raw NTLMv2 auth', 'client plaintext auth', 'client NTLMv2 auth', 'client lanman auth', and 'client use spnego'.
  • Support for the 'ldap ssl ads' option has been removed from smb.conf. The removal of the 'server schannel' option is expected in the next release.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster