ื’ืจืกื” ืฉืœ Samba 4.15.0

ื”ื•ืฆื’ื” ื”ืžื”ื“ื•ืจื” ืฉืœ Samba 4.15.0, ืฉื”ืžืฉื™ื›ื” ื‘ืคื™ืชื•ื— ืกื ื™ืฃ Samba 4 ืขื ื”ื˜ืžืขื” ืžืœืื” ืฉืœ ื‘ืงืจ ืชื—ื•ื ื•ืฉื™ืจื•ืช Active Directory, ื”ืชื•ืื ืœื”ื˜ืžืขืช Windows 2000 ื•ืžืกื•ื’ืœ ืœืชืช ืฉื™ืจื•ืช ืœื›ืœ ื”ื’ืจืกืื•ืช ืฉืœ ืœืงื•ื—ื•ืช Windows ื”ื ืชืžื›ื•ืช ืขืœ ื™ื“ื™ Microsoft, ื›ื•ืœืœ Windows 10. Samba 4 ื”ื•ื ืžื•ืฆืจ ืฉืจืช ืจื‘ ืชื›ืœื™ืชื™, ื”ืžืกืคืง ื’ื ื™ื™ืฉื•ื ืฉืœ ืฉืจืช ืงื‘ืฆื™ื, ืฉื™ืจื•ืช ื”ื“ืคืกื” ื•ืฉืจืช ื–ื”ื•ืช (winbind).

ืฉื™ื ื•ื™ื™ื ืžืจื›ื–ื™ื™ื ื‘ืกืžื‘ื” 4.15:

  • ื”ืขื‘ื•ื“ื” ืขืœ ืฉื“ืจื•ื’ ืฉื›ื‘ืช VFS ื”ืกืชื™ื™ืžื”. ืžืกื™ื‘ื•ืช ื”ื™ืกื˜ื•ืจื™ื•ืช, ื”ืงื•ื“ ืขื ื™ื™ืฉื•ื ืฉืจืช ื”ืงื‘ืฆื™ื ื ืงืฉืจ ืœืขื™ื‘ื•ื“ ืฉื‘ื™ืœื™ ืงื‘ืฆื™ื, ืืฉืจ ืฉื™ืžืฉ ื’ื ืขื‘ื•ืจ ืคืจื•ื˜ื•ืงื•ืœ SMB2, ืืฉืจ ื”ื•ืขื‘ืจ ืœืฉื™ืžื•ืฉ ื‘-descriptor. ื”ืžื•ื“ืจื ื™ื–ืฆื™ื” ื›ืœืœื” ื”ืžืจืช ื”ืงื•ื“ ื”ืžืกืคืง ื’ื™ืฉื” ืœืžืขืจื›ืช ื”ืงื‘ืฆื™ื ืฉืœ ื”ืฉืจืช ืœืฉื™ืžื•ืฉ ื‘ืชื™ืื•ืจื™ ืงื‘ืฆื™ื ื‘ืžืงื•ื ื‘ื ืชื™ื‘ื™ ืงื‘ืฆื™ื (ืœื“ื•ื’ืžื”, ืงืจื™ืื” ืœ-fstat() ื‘ืžืงื•ื stat() ื•- SMB_VFS_FSTAT() ื‘ืžืงื•ื SMB_VFS_STAT()).
  • ื”ื˜ืžืขืช ื˜ื›ื ื•ืœื•ื’ื™ื™ืช BIND DLZ (ืื–ื•ืจื™ื ื˜ืขื•ื ื™ื ื“ื™ื ืžื™ืช), ื”ืžืืคืฉืจืช ืœืœืงื•ื—ื•ืช ืœืฉืœื•ื— ื‘ืงืฉื•ืช ื”ืขื‘ืจืช ืื–ื•ืจื™ DNS ืœืฉืจืช ื”-BIND ื•ืœืงื‘ืœ ืžืขื ื” ืžืกืžื‘ื”, ื”ื•ืกื™ืคื” ืืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ืจืฉื™ืžื•ืช ื’ื™ืฉื” ื”ืžืืคืฉืจื•ืช ืœืš ืœืงื‘ื•ืข ืื™ืœื• ืœืงื•ื—ื•ืช ื”ื ืžื•ืชืจ ื‘ืงืฉื•ืช ื›ืืœื” ื•ืืฉืจ ืœื. ื”ืชื•ืกืฃ DLZ DNS ืื™ื ื• ืชื•ืžืš ืขื•ื“ ื‘ืขื ืคื™ Bind 9.8 ื•-9.9.
  • ื”ืชืžื™ื›ื” ื‘ื”ืจื—ื‘ื” ื”ืจื‘-ืขืจื•ืฆื™ืช SMB3 (ืคืจื•ื˜ื•ืงื•ืœ SMB3 Multi-Channel) ืžื•ืคืขืœืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื•ืžืชื™ื™ืฆื‘ืช, ื•ืžืืคืฉืจืช ืœืœืงื•ื—ื•ืช ืœื™ืฆื•ืจ ืžืกืคืจ ื—ื™ื‘ื•ืจื™ื ื›ื“ื™ ืœื”ืงื‘ื™ืœ ื”ืขื‘ืจื•ืช ื ืชื•ื ื™ื ื‘ืชื•ืš ื”ืคืขืœืช SMB ืื—ืช. ืœื“ื•ื’ืžื”, ื‘ืขืช ื’ื™ืฉื” ืœืงื•ื‘ืฅ ื‘ื•ื“ื“, ื ื™ืชืŸ ืœื”ืคื™ืฅ ืคืขื•ืœื•ืช I/O ืขืœ ืคื ื™ ืžืกืคืจ ื—ื™ื‘ื•ืจื™ื ืคืชื•ื—ื™ื ื‘ื•-ื–ืžื ื™ืช. ืžืฆื‘ ื–ื” ืžืืคืฉืจ ืœืš ืœื”ื’ื“ื™ืœ ืืช ื”ืชืคื•ืงื” ื•ืœื”ื’ื‘ื™ืจ ืืช ื”ื”ืชื ื’ื“ื•ืช ืœื›ืฉืœื™ื. ื›ื“ื™ ืœื”ืฉื‘ื™ืช ืืช SMB3 Multi-Channel, ืขืœื™ืš ืœืฉื ื•ืช ืืช ืืคืฉืจื•ืช "ืชืžื™ื›ื” ืžืจื•ื‘ืช ืขืจื•ืฆื™ื ื‘ืฉืจืช" ื‘-smb.conf, ืืฉืจ ืžื•ืคืขืœืช ื›ืขืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืคืœื˜ืคื•ืจืžื•ืช Linux ื•-FreeBSD.
  • ื›ืขืช ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” samba-tool ื‘ืชืฆื•ืจื•ืช Samba ืฉื ื‘ื ื• ืœืœื ืชืžื™ื›ื” ื‘ื‘ืงืจ ืชื—ื•ื Active Directory (ื›ืืฉืจ ืžืฆื•ื™ื ืช ื”ืืคืฉืจื•ืช "--without-ad-dc"). ืื‘ืœ ื‘ืžืงืจื” ื–ื”, ืœื ื›ืœ ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื–ืžื™ื ื”; ืœืžืฉืœ, ื”ื™ื›ื•ืœื•ืช ืฉืœ ื”ืคืงื•ื“ื” 'samba-tool domain' ืžื•ื’ื‘ืœื•ืช.
  • ืžืžืฉืง ืฉื•ืจืช ืคืงื•ื“ื” ืžืฉื•ืคืจ: ืžื ืชื— ืืคืฉืจื•ื™ื•ืช ืฉื•ืจืช ืคืงื•ื“ื” ื—ื“ืฉ ื”ื•ืฆืข ืœืฉื™ืžื•ืฉ ื‘ื›ืœื™ ืขื–ืจ ืฉื•ื ื™ื ืฉืœ ืกืžื‘ื”. ืืคืฉืจื•ื™ื•ืช ื“ื•ืžื•ืช ืฉื ื‘ื“ืœื• ื‘ื›ืœื™ ืขื–ืจ ืฉื•ื ื™ื ืื•ื—ื“ื•, ืœืžืฉืœ, ืื•ื—ื“ ืขื™ื‘ื•ื“ ื”ืืคืฉืจื•ื™ื•ืช ื”ืงืฉื•ืจื•ืช ืœื”ืฆืคื ื”, ืขื‘ื•ื“ื” ืขื ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื•ืฉื™ืžื•ืฉ ื‘-kerberos. smb.conf ืžื’ื“ื™ืจ ื”ื’ื“ืจื•ืช ืœื”ื’ื“ืจืช ืขืจื›ื™ ื‘ืจื™ืจืช ืžื—ื“ืœ ืขื‘ื•ืจ ืืคืฉืจื•ื™ื•ืช. ื›ื“ื™ ืœื”ื•ืฆื™ื ืฉื’ื™ืื•ืช, ื›ืœ ื›ืœื™ ื”ืฉื™ืจื•ืช ืžืฉืชืžืฉื™ื ื‘-STDERR (ืขื‘ื•ืจ ืคืœื˜ ืœ-STDOUT, ืžื•ืฆืขืช ื”ืืคืฉืจื•ืช "--debug-stdout").

    ื ื•ืกืคื” ืืคืฉืจื•ืช "--client-protection=off|sign|encrypt".

    ืืคืฉืจื•ื™ื•ืช ืฉืฉื™ื ื•: --kerberos -> --use-kerberos=required|desired|off --krb5-ccache -> --use-krb5-ccache=CCACHE --scope -> --netbios-scope=SCOPE --use -ccache -> --use- winbind-ccache

    ื”ืืคืฉืจื•ื™ื•ืช ืฉื”ื•ืกืจื•: "-e|โ€”encrypt" ื•-"-S|โ€”signing".

    ื ืขืฉืชื” ืขื‘ื•ื“ื” ืœื ื™ืงื•ื™ ืืคืฉืจื•ื™ื•ืช ื›ืคื•ืœื•ืช ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช ldbadd, ldbdel, ldbedit, ldbmodify, ldbrename ื•-ldbsearch, ndrdump, net, sharesec, smbcquotas, nmbd, smbd ื•-winbindd.

  • ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืกืจื™ืงืช ืจืฉื™ืžืช ื”-Trusted Domains ื‘ืขืช ื”ืคืขืœืช winbindd ืžื•ืฉื‘ืชืช, ืžื” ืฉื”ื™ื” ื”ื’ื™ื•ื ื™ ื‘ื™ืžื™ NT4, ืืš ืื™ื ื• ืจืœื•ื•ื ื˜ื™ ืขื‘ื•ืจ Active Directory.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืžื ื’ื ื•ืŸ ODJ (Offline Domain Join), ื”ืžืืคืฉืจ ืœื”ืฆื˜ืจืฃ ืœืžื—ืฉื‘ ืœื“ื•ืžื™ื™ืŸ ืžื‘ืœื™ ืœื™ืฆื•ืจ ืงืฉืจ ื™ืฉื™ืจ ืขื ื‘ืงืจ ื“ื•ืžื™ื™ืŸ. ื‘ืžืขืจื›ื•ืช ื”ืคืขืœื” ื“ืžื•ื™ื•ืช Unix ื”ืžื‘ื•ืกืกื•ืช ืขืœ ืกืžื‘ื”, ืžื•ืฆืขืช ื”ืคืงื•ื“ื” 'net offlinejoin' ืœื”ืฆื˜ืจืคื•ืช, ื•ื‘-Windows ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืชื•ื›ื ืช djoin.exe ื”ืกื˜ื ื“ืจื˜ื™ืช.
  • ื”ืคืงื•ื“ื” 'samba-tool dns zoneoptions' ืžืกืคืงืช ืืคืฉืจื•ื™ื•ืช ืœื”ื’ื“ืจืช ืžืจื•ื•ื— ื”ืขื“ื›ื•ืŸ ื•ืฉืœื™ื˜ื” ื‘ื˜ื™ื”ื•ืจ ืจืฉื•ืžื•ืช DNS ืžื™ื•ืฉื ื•ืช. ืื ื›ืœ ื”ืจืฉื•ืžื•ืช ืขื‘ื•ืจ ืฉื DNS ื ืžื—ืงื•ืช, ื”ืฆื•ืžืช ืžืžื•ืงื ื‘ืžืฆื‘ ืžืฆื‘ื”.
  • ื›ืขืช ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืฉืจืช DNS DCE/RPC ืขืœ ื™ื“ื™ ื›ืœื™ ืขื–ืจ ืฉืœ samba ื•-Windows ื›ื“ื™ ืœืชืคืขืœ ืจืฉื•ืžื•ืช DNS ื‘ืฉืจืช ื—ื™ืฆื•ื ื™.
  • ื‘ืขืช ื‘ื™ืฆื•ืข ื”ืคืงื•ื“ื” "samba-tool domain backup offline", ื ืขื™ืœื” ื ื›ื•ื ื” ื‘ืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ LMDB ืžื•ื‘ื˜ื—ืช ื›ื“ื™ ืœื”ื’ืŸ ืžืคื ื™ ืฉื™ื ื•ื™ ืžืงื‘ื™ืœ ืฉืœ ื”ื ืชื•ื ื™ื ื‘ืžื”ืœืš ื”ื’ื™ื‘ื•ื™.
  • ื”ื•ืคืกืงื” ื”ืชืžื™ื›ื” ื‘ื ื™ื‘ื™ื ื ื™ืกื™ื•ื ื™ื™ื ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ SMB - SMB2_22, SMB2_24 ื•-SMB3_10, ืฉื”ื™ื• ื‘ืฉื™ืžื•ืฉ ืจืง ื‘ื‘ื ื™ื™ืช ืžื‘ื—ืŸ ืฉืœ Windows.
  • ื‘-builds ืขื ื™ื™ืฉื•ื ื ื™ืกื™ื•ื ื™ ืฉืœ Active Directory ื”ืžื‘ื•ืกืก ืขืœ MIT Kerberos, ื”ื“ืจื™ืฉื•ืช ืœื’ืจืกื” ืฉืœ ื—ื‘ื™ืœื” ื–ื• ื”ื•ืขืœื•. Build ืขื›ืฉื™ื• ื“ื•ืจืฉ ืœืคื—ื•ืช MIT Kerberos ื’ืจืกื” 1.19 (ื ืฉืœื— ืขื Fedora 34).
  • ืชืžื™ื›ืช โ‚ช ื”ื•ืกืจื”.
  • ืคื’ื™ืขื•ืช ืชื•ืงื ื” CVE-2021-3671, ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืœื ืžืื•ืžืช ืœืงืจื•ืก ื‘ืงืจ ืชื—ื•ื ืžื‘ื•ืกืก Heimdal KDC ืื ื ืฉืœื—ืช ื—ื‘ื™ืœืช TGS-REQ ืฉืื™ื ื” ื›ื•ืœืœืช ืฉื ืฉืจืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”