Back to bug 2190415

Who When What Removed Added
Red Hat Bugzilla 2023-04-28 11:17:09 UTC Pool ID sst_idm_sssd_rhel_9
Red Hat One Jira (issues.redhat.com) 2023-04-28 11:18:16 UTC Link ID Red Hat Issue Tracker RHELPLAN-156032
Andreas Schneider 2023-04-28 11:20:00 UTC QA Contact sssd-qe dkarpele
CC asn
Keywords Rebase, Triaged
Red Hat One Jira (issues.redhat.com) 2023-04-28 11:22:13 UTC Link ID Red Hat Issue Tracker SSSD-5994
Andreas Schneider 2023-04-28 11:24:54 UTC Docs Contact mmuehlfe
Andreas Schneider 2023-04-28 11:28:48 UTC Depends On 2190418
Andreas Schneider 2023-04-28 11:34:01 UTC Depends On 2190420
Andreas Schneider 2023-04-28 11:40:39 UTC Depends On 2190424
Andreas Schneider 2023-04-28 11:41:40 UTC Depends On 2190426
Andre Boscatto 2023-05-23 11:37:37 UTC Fixed In Version samba-4.18.2-100.el9
Status NEW ASSIGNED
CC aboscatt
Andre Boscatto 2023-05-23 11:38:41 UTC Assignee asn pfilipen
Andre Boscatto 2023-05-23 11:54:05 UTC Status ASSIGNED MODIFIED
errata-xmlrpc 2023-06-12 15:02:19 UTC CC dhodovsk
Status MODIFIED ON_QA
Denis Karpelevich 2023-06-19 15:00:44 UTC Fixed In Version samba-4.18.2-100.el9 samba-4.18.3-100.el9
Status ON_QA VERIFIED
Marc Muehlfeld 2023-08-01 09:45:24 UTC Fixed In Version samba-4.18.3-100.el9 samba-4.18.4-100.el9
Doc Type If docs needed, set a value Enhancement
Flags needinfo?(pfilipen)
Doc Text .`samba` rebased to version 4.18.4

The `samba` packages have been upgraded to upstream version 4.18.4, which provides bug fixes and enhancements over the previous version. The most notable changes:

* Security improvements in previous releases impacted the performance of the Server Message Block (SMB) server for high meta data workloads. This update improves he performance in this scenario.

* The new ´wbinfo --change-secret-at=<domain_controller>` command enforces the change of the trust account password on the specified domain controller.

* By default, Samba stores access control lists (ACLs) in the `security.NTACL` extended attribute of files. With the `acl_xattr:<security_acl_name>` setting in the `/etc/samba/smb.conf` file, you now can customize the attribute name. Note that a custom extended attribute name is not a protected location as `security.NTACL`. Consequently, users with local access to the server can be able to modify the custom attribute's content and compromise the ACL.

Note that the server message block version 1 (SMB1) protocol is deprecated since Samba 4.11 and will be removed in a future release.

Back up the database files before starting Samba. When the `smbd`, `nmbd`, or `winbind` services start, Samba automatically updates its `tdb` database files. Red Hat does not support downgrading `tdb` database files.

After updating Samba, use the `testparm` utility to verify the `/etc/samba/smb.conf` file.
Pavel Filipensky 2023-08-01 14:11:36 UTC Flags needinfo?(pfilipen)
Marc Muehlfeld 2023-08-01 15:07:37 UTC Doc Text .`samba` rebased to version 4.18.4

The `samba` packages have been upgraded to upstream version 4.18.4, which provides bug fixes and enhancements over the previous version. The most notable changes:

* Security improvements in previous releases impacted the performance of the Server Message Block (SMB) server for high meta data workloads. This update improves he performance in this scenario.

* The new ´wbinfo --change-secret-at=<domain_controller>` command enforces the change of the trust account password on the specified domain controller.

* By default, Samba stores access control lists (ACLs) in the `security.NTACL` extended attribute of files. With the `acl_xattr:<security_acl_name>` setting in the `/etc/samba/smb.conf` file, you now can customize the attribute name. Note that a custom extended attribute name is not a protected location as `security.NTACL`. Consequently, users with local access to the server can be able to modify the custom attribute's content and compromise the ACL.

Note that the server message block version 1 (SMB1) protocol is deprecated since Samba 4.11 and will be removed in a future release.

Back up the database files before starting Samba. When the `smbd`, `nmbd`, or `winbind` services start, Samba automatically updates its `tdb` database files. Red Hat does not support downgrading `tdb` database files.

After updating Samba, use the `testparm` utility to verify the `/etc/samba/smb.conf` file.
.`samba` rebased to version 4.18.4

The `samba` packages have been upgraded to upstream version 4.18.4, which provides bug fixes and enhancements over the previous version. The most notable changes:

* Security improvements in previous releases impacted the performance of the Server Message Block (SMB) server for high meta data workloads. This update improves the performance in this scenario.

* The new ´wbinfo --change-secret-at=<domain_controller>` command enforces the change of the trust account password on the specified domain controller.

* By default, Samba stores access control lists (ACLs) in the `security.NTACL` extended attribute of files. With the `acl_xattr:<security_acl_name>` setting in the `/etc/samba/smb.conf` file, you now can customize the attribute name. Note that a custom extended attribute name is not a protected location as `security.NTACL`. Consequently, users with local access to the server can be able to modify the custom attribute's content and compromise the ACL.

Note that the server message block version 1 (SMB1) protocol is deprecated since Samba 4.11 and will be removed in a future release.

Back up the database files before starting Samba. When the `smbd`, `nmbd`, or `winbind` services start, Samba automatically updates its `tdb` database files. Red Hat does not support downgrading `tdb` database files.

After updating Samba, use the `testparm` utility to verify the `/etc/samba/smb.conf` file.
Marc Muehlfeld 2023-08-02 08:15:21 UTC Doc Text .`samba` rebased to version 4.18.4

The `samba` packages have been upgraded to upstream version 4.18.4, which provides bug fixes and enhancements over the previous version. The most notable changes:

* Security improvements in previous releases impacted the performance of the Server Message Block (SMB) server for high meta data workloads. This update improves the performance in this scenario.

* The new ´wbinfo --change-secret-at=<domain_controller>` command enforces the change of the trust account password on the specified domain controller.

* By default, Samba stores access control lists (ACLs) in the `security.NTACL` extended attribute of files. With the `acl_xattr:<security_acl_name>` setting in the `/etc/samba/smb.conf` file, you now can customize the attribute name. Note that a custom extended attribute name is not a protected location as `security.NTACL`. Consequently, users with local access to the server can be able to modify the custom attribute's content and compromise the ACL.

Note that the server message block version 1 (SMB1) protocol is deprecated since Samba 4.11 and will be removed in a future release.

Back up the database files before starting Samba. When the `smbd`, `nmbd`, or `winbind` services start, Samba automatically updates its `tdb` database files. Red Hat does not support downgrading `tdb` database files.

After updating Samba, use the `testparm` utility to verify the `/etc/samba/smb.conf` file.
.`samba` rebased to version 4.18.4

The `samba` packages have been upgraded to upstream version 4.18.4, which provides bug fixes and enhancements over the previous version. The most notable changes:

* Security improvements in previous releases impacted the performance of the Server Message Block (SMB) server for high metadata workloads. This update improves the performance in this scenario.

* The new `wbinfo --change-secret-at=<domain_controller>` command enforces the change of the trust account password on the specified domain controller.

* By default, Samba stores access control lists (ACLs) in the `security.NTACL` extended attribute of files. You can now customize the attribute name with the `acl_xattr:<security_acl_name>` setting in the `/etc/samba/smb.conf` file. Note that a custom extended attribute name is not a protected location as `security.NTACL`. Consequently, users with local access to the server can be able to modify the custom attribute's content and compromise the ACL.

Note that the server message block version 1 (SMB1) protocol has been deprecated since Samba 4.11 and will be removed in a future release.

Back up the database files before starting Samba. When the `smbd`, `nmbd`, or `winbind` services start, Samba automatically updates its `tdb` database files. Red Hat does not support downgrading `tdb` database files.

After updating Samba, use the `testparm` utility to verify the `/etc/samba/smb.conf` file.
Andreas Schneider 2023-08-17 15:21:31 UTC Fixed In Version samba-4.18.4-100.el9 samba-4.18.6-100.el9

Back to bug 2190415