Release of Samba 4.20.0

After 6 months of development, the Samba 4.20.0 release has been presented, continuing the development of the Samba 4 branch with a full implementation of the domain controller and Active Directory service, compatible with the Windows 2008 implementation and capable of servicing all supported Microsoft versions of Windows clients, including Windows 11. Samba 4 is a multifunctional server product that also provides file server, print service, and identification server (winbind) implementations.

Key changes in Samba 4.20:

  • By default, a new ‘wspsearch’ utility is included with the implementation of an experimental client for the WSP (Windows Search Protocol). The utility allows sending search queries to a Windows server where the WSP service is running.
  • Support for writing Discretionary Access Control Lists (DACL) to a file and restoring a DACL from a file has been implemented in the ‘smbcacls’ command. Data is saved in a format compatible with the Windows utility 'icacls.exe', ensuring portability of files with saved DACLs.
  • Extensions for centralized access policies of Active Directory (Claims), authentication policies (Authentication Policies), and policy containers (Authentication Silos) have been added to the ‘samba-tool’ utility. The samba-tool can now be used to link users with claims for subsequent use in rules that determine access under authentication policy.

    Additionally, the samba-tool utility can now be used to create and manage authentication policies, as well as create and manage policy containers. For example, through samba-tool, you can define where a user can connect from and to if NTLM usage is allowed, and in which services the user can be authenticated.

  • In the Samba-based controller domain Active Directory, support for authentication policies (Authentication Policies) and policy containers (Authentication Silos) created through the samba-tool or imported from Microsoft AD configurations has been added. This feature is only available on systems with an Active Directory functional level of at least 2012_R2 ('ad dc functional level = 2016' in smb.conf).
  • The samba-tool utility now includes client-side support for Group Managed Service Accounts (gMSA) with automatically updated passwords. The password management commands previously only usable with the local sam.ldb database can now be applied to external authentication using the '-H ldap://$DCNAME' option. server Among the supported operations are: 'samba-tool user getpassword' for reading the current and past gMSA password; 'samba-tool user get-kerberos-ticket' for writing the Kerberos TGT (Ticket Granting Ticket) to the local account cache.
  • Support for Conditional ACEs (Access Control Entries) has been added, allowing access to be granted or denied based on additional conditions—if the conditional expression is not met, the ACE is ignored; otherwise, it applies like a regular ACE. Conditional checks can also apply to the attributes of the protected object, described by Resource Attribute ACEs.
  • The ctdb cluster implementation now includes the ability to provide the MS-SWN (Service Witness Protocol), which allows clients to monitor their SMB connections to cluster nodes. For example, a client connected to node 'A' can request node 'B' to send a notification if node 'A' becomes unavailable. A series of commands, 'net witness [list|client-move|share-move|force-unregister|force-response]', is proposed for managing the service, allowing cluster administrators to view registered clients and request movement of connections to other cluster nodes.
  • For configurations with MIT Kerberos5 operating as an Active Directory domain controller, at least version MIT Krb5 1.21 is now required, which includes additional protection against the CVE-2022-37967 vulnerability.
  • When building with imported Heimdal Kerberos, it is no longer necessary to install the Perl JSON module, as the built-in JSON::PP module in Perl5 is used instead.
  • In the commands 'samba-tool user getpassword' and 'samba-tool user syncpasswords', used for retrieving and synchronizing passwords, the output has changed when using the parameter ';rounds=' with the attributes virtualCryptSHA256 and virtualCryptSHA512 (for example, ‘—attributes="virtualCryptSHA256;rounds=50000"'). Previously: virtualCryptSHA256: {CRYPT}$5$rounds=2561$hXem.M9onhM9Vuix$dFdSBwF Now: virtualCryptSHA256;rounds=2561:{CRYPT}$5$rounds=2561$hXem.M9onhM9Vuix$dFdSBwF.
  • The implementation of MS-WKST (Workstation Service Remote Protocol) has discontinued support for outputting the list of connected users based on the contents of the file /var/run/utmp, which stores data about users currently working in the system. Support for utmp has been discontinued due to this format being susceptible to the year 2038 problem.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster