Package samba: Information

  • Default inline alert: Version in the repository: 4.20.1-alt2

Source package: samba
Version: 4.19.3-alt1
Latest version according to Repology
Build time:  Dec 7, 2023, 06:39 AM in the task #335768
Category: System/Servers
Report package bug
License: GPLv3+ and LGPLv3+
Summary: The Samba4 CIFS and AD client and server suite
Description: 
Samba is the standard Windows interoperability suite of programs for Linux and Unix.

List of rpms provided by this srpm:
admx-samba (noarch)
libldb-modules-ldap (x86_64, ppc64le, i586, armh, aarch64)
libldb-modules-ldap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient-devel (x86_64, ppc64le, i586, armh, aarch64)
libwbclient (x86_64, ppc64le, i586, armh, aarch64)
libwbclient-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libwbclient-devel (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba-devel (x86_64, ppc64le, i586, armh, aarch64)
samba (x86_64, ppc64le, i586, armh, aarch64)
samba-client (x86_64, ppc64le, i586, armh, aarch64)
samba-client-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-common (noarch)
samba-common-client (noarch)
samba-common-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-common-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-common-tools (x86_64, ppc64le, i586, armh, aarch64)
samba-common-tools-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb-ceph-mutex (x86_64, ppc64le, aarch64)
samba-ctdb-ceph-mutex-debuginfo (x86_64, ppc64le, aarch64)
samba-ctdb-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb-etcd-mutex (x86_64, ppc64le, i586, armh, aarch64)
samba-dc (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-client (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-common (noarch)
samba-dc-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-mitkrb5 (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-mitkrb5-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dcerpc (x86_64, ppc64le, i586, armh, aarch64)
samba-dcerpc-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-devel (x86_64, ppc64le, i586, armh, aarch64)
samba-doc (noarch)
samba-gpupdate (x86_64, ppc64le, i586, armh, aarch64)
samba-krb5-printing (x86_64, ppc64le, i586, armh, aarch64)
samba-krb5-printing-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-pidl (noarch)
samba-test (x86_64, ppc64le, i586, armh, aarch64)
samba-test-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-usershares (x86_64, ppc64le, i586, armh, aarch64)
samba-util-private-headers (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-cephfs (x86_64, ppc64le, aarch64)
samba-vfs-cephfs-debuginfo (x86_64, ppc64le, aarch64)
samba-vfs-glusterfs (x86_64, ppc64le, i586, aarch64)
samba-vfs-glusterfs-debuginfo (x86_64, ppc64le, i586, aarch64)
samba-vfs-snapper (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-snapper-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-clients (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-clients-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-common (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-localauth (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-localauth-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-locator (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-locator-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
task-samba-dc (noarch)
task-samba-dc-mitkrb5 (noarch)

Maintainer: Evgeny Sinelnikov



    1. netpbm
    2. python3-devel
    3. ceph-devel
    4. python3-module-dns
    5. python3-module-etcd
    6. python3-module-markdown
    7. libpopt-devel
    8. python3-module-pyldb-devel
    9. dblatex
    10. python3-module-talloc-devel
    11. python3-module-tdb
    12. python3-module-tevent
    13. /proc
    14. libcap-devel
    15. /usr/bin/rpcgen
    16. librados-devel
    17. libreadline-devel
    18. libcups-devel
    19. docbook-style-xsl
    20. glibc-devel
    21. libdbus-devel
    22. glibc-kernheaders
    23. libe2fs-devel
    24. libssl-devel
    25. flex
    26. html2text
    27. perl-JSON
    28. perl-JSON-PP
    29. perl-Parse-Yapp
    30. rpm-build-python3
    31. perl-devel
    32. rpm-macros-alternatives
    33. admx-lint
    34. alternatives
    35. libglusterfs-api-devel
    36. libgnutls-devel
    37. libacl-devel
    38. libgpgme-devel
    39. gawk
    40. libarchive-devel >= 3.1.2
    41. libsystemd-devel
    42. libtalloc-devel >= 2.4.1
    43. libtasn1-devel
    44. libtasn1-utils
    45. libtdb-devel >= 1.4.9
    46. libattr-devel
    47. libtevent-devel >= 0.15.0
    48. libavahi-devel
    49. libtirpc-devel
    50. libiniparser-devel
    51. libuuid-devel
    52. libjansson-devel
    53. krb5-kdc
    54. xsltproc
    55. libkrb5-devel
    56. zlib-devel
    57. libxslt
    58. libldap-devel
    59. liblmdb-devel >= 0.9.16
    60. libldb-devel = 2.8.0
    61. libncurses-devel
    62. libpam-devel

Last changed


Dec. 5, 2023 Evgeny Sinelnikov 4.19.3-alt1
- Update to stable release of Samba 4.19 with fixes of the Samba CVE for
  Deleted Object tombstones visible in AD LDAP to normal users (CVE-2018-14628).
- Security fixes:
  + CVE-2018-14628: Wrong ntSecurityDescriptor values for "CN=Deleted Objects"
                    allow read of object tombstones over LDAP
                    (Administrator action required!)
                    https://www.samba.org/samba/security/CVE-2018-14628.html
Nov. 6, 2023 Evgeny Sinelnikov 4.19.2-alt1
- Update to stable release of Samba 4.19 with latest bugfixes and new features:
 + Migrated smbget to use common command line parser. This has some advantages
   as you get all the feature it provides like Kerberos authentication. The
   support for smbgetrc has been removed.
 + gpupdate changes: The libgpo.get_gpo_list function has been deprecated in
   favor of an implementation written in python,  connects to Active Directory
   using the SamDB module, instead of ADS (which is what libgpo uses).
 + Improved winbind logging and a new tool for parsing the winbind logs. Winbind
   logs (if smb.conf 'winbind debug traceid = yes' is set) contain new trace
   header fields 'traceid' and 'depth'.
 + AD database prepared to Functional Level 2016 standards for new domains.
   While Samba still provides only Functional Level 2008R2 by default, Samba as
   an AD DC will now, in provision ensure that the blank database is already
   prepared for Functional Level 2016, with AD Schema 2019.
 + Kerberos Claims, Authentication Silos and NTLM authentication policies.
   The primary limitation is that while Samba can read and write claims
   in the directory, and populate the PAC, Samba does not yet use them
   for access control decisions.
 + Improved KDC Auditing now provides Samba-style JSON audit logging of all
   issued Kerberos tickets, including if they would fail a policy that is not
   yet enforced. Additionally most failures are audited.
 + Kerberos Armoring (FAST) Support for Windows clients. In domains where the
   domain controller functional level is set to 2012, 2012_R2 or 2016, Windows
   clients will, if configured via GPO, use FAST to protect user passwords
   between (in particular) a workstation and the KDC on the AD DC. This is a
   significant security improvement, as weak passwords in an AS-REQ are no
   longer available for offline attack.
 + Claims compression in the AD PAC. Samba as an AD DC will compress "AD claims"
   using the same compression algorithm as Microsoft Windows.
 + Resource SID compression in the AD PAC. Samba as an AD DC will now correctly
   populate the various PAC group membership buffers, splitting global and local
   groups correctly.
 + Resource Based Constrained Delegation (RBCD) support in both MIT and Heimdal.
   Samba 4.17 added to samba-tool delegation the 'add-principal' and
   'del-principal' subcommands in order to manage RBCD, and the database changes
   made by these tools are now honoured by the Heimdal KDC once Samba is upgraded.
 + New samba-tool support for silos, claims, sites and subnets.
   samba-tool can now list, show, add and manipulate Authentication Silos
   (silos) and Active Directory Authentication Claims (claims).
 + Updated Heimdal import. Samba's Heimdal branch (known as lorikeet-heimdal)
   has been updated to the current pre-8.0 (master) tree from upstream Heimdal,
   ensuring that this vendored copy, included in our release remains as close as
   possible to the current upstream code.
 + Revocation support in Heimdal KDC for PKINIT certificates. Samba will now
   correctly honour the revocation of 'smart card' certificates used for PKINIT
   Kerberos authentication.
 + Require encrypted connection to modify unicodePwd on the AD DC.
 + Samba AD TLS Certificates can be reloaded. The TLS certificates used for
   Samba's AD DC LDAP server were previously only read on startup, and this
   meant that when then expired it was required to restart Samba, disrupting
   service to other users (smbcontrol ldap_server reload-certs).
Nov. 1, 2023 Evgeny Sinelnikov 4.18.8-alt1
- Update to maintenance release of Samba 4.18 with latest bugfixes and new features:
 + SMB Server performance improvements. The locking overhead for contended path
   based operations is reduced by an additional factor of ~ 3 compared to 4.17.
 + More succinct samba-tool error messages.
 + Accessing the old samba-tool messages with full Python stack trace by using
   the argument '-d3'.
 + New samba-tool dsacl subcommand for deleting ACES
 + Colour output with samba-tool --color and
 + No colour with NO_COLOR environment variable
 + New wbinfo option --change-secret-at which forces the trust account password
   to be changed at a specified domain controller.
 + New option acl_xattr:security_acl_name to change the NT ACL default protected
   location security.NTACL not accessible from normal users outside of Samba.
 + New option server addresses as per-share parameter to limit share visibility
   and accessibility to specific server IP addresses. This option can offer a
   different set of shares per interface.
 + Azure Active Directory / Office365 synchronisation improvements with the
   Azure AD Connect cloud sync tool which now supported for password hash
   synchronisation, allowing Samba AD Domains to synchronise passwords with this
   popular cloud environment.