Release Announcements
=====================
-This is the first preview release of Samba 4.11. This is *not*
+This is the first preview release of Samba 4.12. This is *not*
intended for production environments and is designed for testing
purposes only. Please report any defects via the Samba bug reporting
system at https://bugzilla.samba.org/.
-Samba 4.11 will be the next version of the Samba suite.
+Samba 4.12 will be the next version of the Samba suite.
UPGRADING
NEW FEATURES/CHANGES
====================
-Default samba process model
----------------------------
+Python 3.5 Required
+-------------------
-The default for the --model argument passed to the samba executable has changed
-from 'standard' to 'prefork'. This means a difference in the number of samba
-child processes that are created to handle client connections. The previous
-default would create a separate process for every LDAP or NETLOGON client
-connection. For a network with a lot of persistent client connections, this
-could result in significant memory overhead. Now, with the new default of
-'prefork', the LDAP, NETLOGON, and KDC services will create a fixed number of
-worker processes at startup and share the client connections amongst these
-workers. The number of worker processes can be configured by the 'prefork
-children' setting in the smb.conf (the default is 4).
+Samba's minimum runtime requirement for python was raised to Python
+3.4 with samba 4.11. Samba 4.12 raises this minimum version to Python
+3.5 both to access new features and because this is the oldest version
+we test with in our CI infrastructure.
-Authentication Logging.
------------------------
+(Build time support for the file server with Python 2.6 has not
+changed)
-Winbind now logs PAM_AUTH and NTLM_AUTH events, a new attribute "logonId" has
-been added to the Authentication JSON log messages. This contains a random
-logon id that is generated for each PAM_AUTH and NTLM_AUTH request and is passed
-to SamLogon, linking the windbind and SamLogon requests.
-
-The serviceDescription of the messages is set to "winbind", the authDescription
-is set to one of:
- "PASSDB, <command>, <pid>"
- "PAM_AUTH, <command>, <pid>"
- "NTLM_AUTH, <command>, <pid>"
-where:
- <command> is the name of the command makinmg the winbind request i.e. wbinfo
- <pid> is the process id of the requesting process.
-
-The version of the JSON Authentication messages has been changed to 1.2 from 1.1
-
-Reindex performance improvements
---------------------------------
-
-The performance of samba-tool dbcheck --reindex has been improved, especially
-for large domains.
-
-LDAP referrals
---------------
-
-The scheme of returned LDAP referrals now reflects the scheme of the original
-request, i.e. referrals received via ldap are prefixed with "ldap://"
-and those over ldaps are prefixed with "ldaps://"
-
-Previously all referrals were prefixed with "ldap://"
-
-Bind9 logging
--------------
-
-It is now possible to log the duration of DNS operations performed by Bind9
-This should aid future diagnosis of performance issues, and could be used to
-monitor DNS performance. The logging is enabled by setting log level to
-"dns:10" in smb.conf
-
-The logs are currently Human readable text only, i.e. no JSON formatted output.
+GnuTLS 3.4.7 required
+---------------------
-Log lines are of the form:
+Samba is making efforts to remove in-tree cryptographic functionality,
+and to instead rely on externally maintained libraries. To this end,
+Samba has chosen GnuTLS as our standard cryptographic provider.
- <function>: DNS timing: result: [<result>] duration: (<duration>)
- zone: [<zone>] name: [<name>] data: [<data>]
+Samba now requires GnuTLS 3.4.7 to be installed (including development
+headers at build time) for all configurations, not just the Samba AD
+DC.
- durations are in microseconds.
+Using GnuTLS for SMB3 encryption you will notice huge performance and copy
+speed improvements. Tests with the CIFS Kernel client from Linux Kernel 5.3
+show a 3x speed improvement for writing and a 2.5x speed improvement for reads!
-Default schema updated to 2012_R2
--------------------------
+NOTE WELL: The use of GnuTLS means that Samba will honour the
+system-wide 'FIPS mode' (a reference to the US FIPS-140 cryptographic
+standard) and so will not operate in many still common situations if
+this system-wide parameter is in effect, as many of our protocols rely
+on outdated cryptography.
-Default AD schema changed from 2008_R2 to 2012_R2. 2012_R2 functional level
-is not yet available. Older schemas can be used by provisioning with the
-'--base-schema' argument. Existing installations can be updated with the
-samba-tool command "domain schemaupgrade".
+A future Samba version will mitigate this to some extent where good
+cryptography effectively wraps bad cryptography, but for now that above
+applies.
-Setting lmdb map size
----------------------
-
-It is now possible to set the lmdb map size (The maximum permitted size for
-the database). "samba-tool" now accepts the "--backend-store-size"
-i.e. --backend-store-size=4Gb. If not specified it defaults to 8Gb.
-This option is avaiable for the following sub commands:
- * domain provision
- * domain join
- * domain dcpromo
- * drs clone-dc-database
REMOVED FEATURES
================
-Web server
-----------
-
-As a leftover from work related to the Samba Web Administration Tool (SWAT),
-Samba still supported a Python WSGI web server (which could still be turned on
-from the 'server services' smb.conf parameter). This service was unused and has
-now been removed from Samba.
-
-
-samba-tool join subdommain
---------------------------
+BIND9_FLATFILE deprecated
+-------------------------
-The subdommain role has been removed from the join command. This option did
-not work and has no tests.
+The BIND9_FLATFILE DNS backend is deprecated in this release and will
+be removed in the future. This was only practically useful on a single
+domain controller or under expert care and supervision.
+This release removes the "rndc command" smb.conf parameter, which
+supported this configuration by writing out a list of DCs permitted to
+make changes to the DNS Zone and nudging the 'named' server if a new
+DC was added to the domain. Administrators using BIND9_FLATFILE will
+need to maintain this manually from now on.
smb.conf changes
================
Parameter Name Description Default
-------------- ----------- -------
- web port Removed
- fruit:zero_file_id Changed default False
-
+ nfs4:acedup Changed default merge
+ rndc command Removed
KNOWN ISSUES
============
-https://wiki.samba.org/index.php/Release_Planning_for_Samba_4.11#Release_blocking_bugs
+https://wiki.samba.org/index.php/Release_Planning_for_Samba_4.12#Release_blocking_bugs
#######################################