Package samba: Information

  • Default inline alert: Version in the repository: 4.20.1-alt2

Source package: samba
Version: 4.19.3-alt2
Latest version according to Repology
Build time:  Dec 12, 2023, 04:30 AM in the task #336288
Category: System/Servers
Report package bug
License: GPLv3+ and LGPLv3+
Summary: The Samba4 CIFS and AD client and server suite
Description: 
Samba is the standard Windows interoperability suite of programs for Linux and Unix.

List of rpms provided by this srpm:
admx-samba (noarch)
libldb-modules-ldap (x86_64, ppc64le, i586, armh, aarch64)
libldb-modules-ldap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsmbclient-devel (x86_64, ppc64le, i586, armh, aarch64)
libwbclient (x86_64, ppc64le, i586, armh, aarch64)
libwbclient-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libwbclient-devel (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-samba-devel (x86_64, ppc64le, i586, armh, aarch64)
samba (x86_64, ppc64le, i586, armh, aarch64)
samba-client (x86_64, ppc64le, i586, armh, aarch64)
samba-client-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-common (noarch)
samba-common-client (noarch)
samba-common-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-common-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-common-tools (x86_64, ppc64le, i586, armh, aarch64)
samba-common-tools-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb-ceph-mutex (x86_64, ppc64le, aarch64)
samba-ctdb-ceph-mutex-debuginfo (x86_64, ppc64le, aarch64)
samba-ctdb-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-ctdb-etcd-mutex (x86_64, ppc64le, i586, armh, aarch64)
samba-dc (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-client (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-common (noarch)
samba-dc-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-mitkrb5 (x86_64, ppc64le, i586, armh, aarch64)
samba-dc-mitkrb5-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-dcerpc (x86_64, ppc64le, i586, armh, aarch64)
samba-dcerpc-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-devel (x86_64, ppc64le, i586, armh, aarch64)
samba-doc (noarch)
samba-gpupdate (x86_64, ppc64le, i586, armh, aarch64)
samba-krb5-printing (x86_64, ppc64le, i586, armh, aarch64)
samba-krb5-printing-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-libs (x86_64, ppc64le, i586, armh, aarch64)
samba-libs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-pidl (noarch)
samba-test (x86_64, ppc64le, i586, armh, aarch64)
samba-test-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-usershares (x86_64, ppc64le, i586, armh, aarch64)
samba-util-private-headers (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-cephfs (x86_64, ppc64le, aarch64)
samba-vfs-cephfs-debuginfo (x86_64, ppc64le, aarch64)
samba-vfs-glusterfs (x86_64, ppc64le, i586, aarch64)
samba-vfs-glusterfs-debuginfo (x86_64, ppc64le, i586, aarch64)
samba-vfs-snapper (x86_64, ppc64le, i586, armh, aarch64)
samba-vfs-snapper-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-clients (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-clients-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-common (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-localauth (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-localauth-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-locator (x86_64, ppc64le, i586, armh, aarch64)
samba-winbind-krb5-locator-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
task-samba-dc (noarch)
task-samba-dc-mitkrb5 (noarch)

Maintainer: Evgeny Sinelnikov



    1. netpbm
    2. ceph-devel
    3. python3-devel
    4. python3-module-dns
    5. /proc
    6. libpopt-devel
    7. python3-module-etcd
    8. python3-module-markdown
    9. python3-module-pyldb-devel
    10. /usr/bin/rpcgen
    11. libcap-devel
    12. dblatex
    13. libcups-devel
    14. python3-module-talloc-devel
    15. python3-module-tdb
    16. python3-module-tevent
    17. libdbus-devel
    18. librados-devel
    19. glibc-devel
    20. glibc-kernheaders
    21. libreadline-devel
    22. admx-lint
    23. libe2fs-devel
    24. alternatives
    25. libssl-devel
    26. html2text
    27. docbook-style-xsl
    28. perl-JSON
    29. perl-JSON-PP
    30. perl-Parse-Yapp
    31. perl-devel
    32. flex
    33. libglusterfs-api-devel
    34. libgnutls-devel
    35. gawk
    36. libgpgme-devel
    37. rpm-build-python3
    38. rpm-macros-alternatives
    39. libacl-devel
    40. libiniparser-devel
    41. libarchive-devel >= 3.1.2
    42. libjansson-devel
    43. libattr-devel
    44. libavahi-devel
    45. libsystemd-devel
    46. libtalloc-devel >= 2.4.1
    47. libtasn1-devel
    48. libtasn1-utils
    49. libtdb-devel >= 1.4.9
    50. libkrb5-devel
    51. libtevent-devel >= 0.15.0
    52. libtirpc-devel
    53. libldap-devel
    54. libldb-devel = 2.8.0
    55. krb5-kdc
    56. libuuid-devel
    57. liblmdb-devel >= 0.9.16
    58. libncurses-devel
    59. xsltproc
    60. zlib-devel
    61. libpam-devel
    62. libxslt

Last changed


Dec. 12, 2023 Evgeny Sinelnikov 4.19.3-alt2
- Replace samba service pam config to samba-common due regression with password
  authentication in security = user mode with obey pam restrictions = yes.
Dec. 5, 2023 Evgeny Sinelnikov 4.19.3-alt1
- Update to stable release of Samba 4.19 with fixes of the Samba CVE for
  Deleted Object tombstones visible in AD LDAP to normal users (CVE-2018-14628).
- Security fixes:
  + CVE-2018-14628: Wrong ntSecurityDescriptor values for "CN=Deleted Objects"
                    allow read of object tombstones over LDAP
                    (Administrator action required!)
                    https://www.samba.org/samba/security/CVE-2018-14628.html
Nov. 6, 2023 Evgeny Sinelnikov 4.19.2-alt1
- Update to stable release of Samba 4.19 with latest bugfixes and new features:
 + Migrated smbget to use common command line parser. This has some advantages
   as you get all the feature it provides like Kerberos authentication. The
   support for smbgetrc has been removed.
 + gpupdate changes: The libgpo.get_gpo_list function has been deprecated in
   favor of an implementation written in python,  connects to Active Directory
   using the SamDB module, instead of ADS (which is what libgpo uses).
 + Improved winbind logging and a new tool for parsing the winbind logs. Winbind
   logs (if smb.conf 'winbind debug traceid = yes' is set) contain new trace
   header fields 'traceid' and 'depth'.
 + AD database prepared to Functional Level 2016 standards for new domains.
   While Samba still provides only Functional Level 2008R2 by default, Samba as
   an AD DC will now, in provision ensure that the blank database is already
   prepared for Functional Level 2016, with AD Schema 2019.
 + Kerberos Claims, Authentication Silos and NTLM authentication policies.
   The primary limitation is that while Samba can read and write claims
   in the directory, and populate the PAC, Samba does not yet use them
   for access control decisions.
 + Improved KDC Auditing now provides Samba-style JSON audit logging of all
   issued Kerberos tickets, including if they would fail a policy that is not
   yet enforced. Additionally most failures are audited.
 + Kerberos Armoring (FAST) Support for Windows clients. In domains where the
   domain controller functional level is set to 2012, 2012_R2 or 2016, Windows
   clients will, if configured via GPO, use FAST to protect user passwords
   between (in particular) a workstation and the KDC on the AD DC. This is a
   significant security improvement, as weak passwords in an AS-REQ are no
   longer available for offline attack.
 + Claims compression in the AD PAC. Samba as an AD DC will compress "AD claims"
   using the same compression algorithm as Microsoft Windows.
 + Resource SID compression in the AD PAC. Samba as an AD DC will now correctly
   populate the various PAC group membership buffers, splitting global and local
   groups correctly.
 + Resource Based Constrained Delegation (RBCD) support in both MIT and Heimdal.
   Samba 4.17 added to samba-tool delegation the 'add-principal' and
   'del-principal' subcommands in order to manage RBCD, and the database changes
   made by these tools are now honoured by the Heimdal KDC once Samba is upgraded.
 + New samba-tool support for silos, claims, sites and subnets.
   samba-tool can now list, show, add and manipulate Authentication Silos
   (silos) and Active Directory Authentication Claims (claims).
 + Updated Heimdal import. Samba's Heimdal branch (known as lorikeet-heimdal)
   has been updated to the current pre-8.0 (master) tree from upstream Heimdal,
   ensuring that this vendored copy, included in our release remains as close as
   possible to the current upstream code.
 + Revocation support in Heimdal KDC for PKINIT certificates. Samba will now
   correctly honour the revocation of 'smart card' certificates used for PKINIT
   Kerberos authentication.
 + Require encrypted connection to modify unicodePwd on the AD DC.
 + Samba AD TLS Certificates can be reloaded. The TLS certificates used for
   Samba's AD DC LDAP server were previously only read on startup, and this
   meant that when then expired it was required to restart Samba, disrupting
   service to other users (smbcontrol ldap_server reload-certs).