[SCM] Samba Website Repository - branch master updated

Karolin Seeger kseeger at samba.org
Fri Jun 17 14:08:04 MDT 2011


The branch, master has been updated
       via  8925b0c [PATCH] s3-WHATSNEW 3.5.9 Add information on kerberos change
      from  ec99588 Update latest stable release.

http://gitweb.samba.org/?p=samba-web.git;a=shortlog;h=master


- Log -----------------------------------------------------------------
commit 8925b0ceed6bfb6109a5283ce040fd705421a427
Author: Andrew Bartlett <abartlet at samba.org>
Date:   Fri Jun 17 22:06:10 2011 +0200

    [PATCH] s3-WHATSNEW 3.5.9 Add information on kerberos change
    
    This patch modifies the release notes after the release, so the hints are not
    included in the 3.5.9 tarball.

-----------------------------------------------------------------------

Summary of changes:
 history/samba-3.5.9.html |   15 +++++++++++++++
 1 files changed, 15 insertions(+), 0 deletions(-)


Changeset truncated at 500 lines:

diff --git a/history/samba-3.5.9.html b/history/samba-3.5.9.html
index 8450077..feb9b58 100755
--- a/history/samba-3.5.9.html
+++ b/history/samba-3.5.9.html
@@ -25,6 +25,21 @@ Major enhancements in Samba 3.5.9 include:
 o  Sgid bit lost on folder rename (bug #7996).
 o  ACL can get lost when files are being renamed (bug #7987).
 o  Respect "allow trusted domains = no" in Winbind (bug #6966).
+o  Samba now follows Windows behaviour as a kerberos client,
+   requesting a CIFS/ ticket (bug #7893).
+
+New Kerberos behaviour
+----------------------
+
+A new parameter 'client use spnego principal' defaults to 'no' and
+means Samba will use CIFS/hostname to obtain a kerberos ticket, acting
+more like Windows when using Kerberos against a CIFS server in
+smbclient, Winbind and other Samba client tools.  This will change
+which servers we will successfully negotiate Kerberos connections to.
+This is due to Samba no longer trusting a server-provided hint which
+is not available from Windows 2008 or later.  For correct operation
+with all clients, all aliases for a server should be recorded as a as
+a servicePrincipalName on the server's record in AD.
 
 
 Changes since 3.5.8:


-- 
Samba Website Repository


More information about the samba-cvs mailing list