[SCM] Samba Shared Repository - branch master updated

Andreas Schneider asn at samba.org
Wed May 3 13:58:02 UTC 2017


The branch, master has been updated
       via  61d6882 WHATSNEW: Add Samba AD with MIT Kerberos
       via  3ef844d WHATSNEW: Give the 'strict sync' change a header line
      from  9f5dbde s3:winbindd:idmap_autorid remove a stray comment

https://git.samba.org/?p=samba.git;a=shortlog;h=master


- Log -----------------------------------------------------------------
commit 61d6882b54d975cef25d5498f1662285a97a6179
Author: Andreas Schneider <asn at samba.org>
Date:   Thu Apr 27 11:19:12 2017 +0200

    WHATSNEW: Add Samba AD with MIT Kerberos
    
    Pair-Programmed-With: Guenther Deschner <gd at samba.org>
    
    Signed-off-by: Andreas Schneider <asn at samba.org>
    Signed-off-by: Guenther Deschner <gd at samba.org>
    Reviewed-by: David Disseldorp <ddiss at samba.org>
    
    Autobuild-User(master): Andreas Schneider <asn at cryptomilk.org>
    Autobuild-Date(master): Wed May  3 15:57:44 CEST 2017 on sn-devel-144

commit 3ef844de27c1b08f76d208d36e79583422a7f368
Author: Andreas Schneider <asn at samba.org>
Date:   Thu Apr 27 11:11:53 2017 +0200

    WHATSNEW: Give the 'strict sync' change a header line
    
    Signed-off-by: Andreas Schneider <asn at samba.org>
    Reviewed-by: David Disseldorp <ddiss at samba.org>

-----------------------------------------------------------------------

Summary of changes:
 WHATSNEW.txt | 41 ++++++++++++++++++++++++++++++++++++-----
 1 file changed, 36 insertions(+), 5 deletions(-)


Changeset truncated at 500 lines:

diff --git a/WHATSNEW.txt b/WHATSNEW.txt
index d9324e7..a385d07 100644
--- a/WHATSNEW.txt
+++ b/WHATSNEW.txt
@@ -16,11 +16,33 @@ UPGRADING
 NEW FEATURES/CHANGES
 ====================
 
-The "strict sync" global parameter has been changed from
-a default of "no" to "yes". This means smbd will by default
-obey client requests to synchronize unwritten data in operating
-system buffers safely onto disk. This is a safer default setting
-for modern SMB1/2/3 clients.
+Samba AD with MIT Kerberos
+--------------------------
+
+After four years of development, Samba finally supports compiling and
+running Samba AD with MIT Kerberos. You can enable it with:
+
+    ./configure --with-system-mitkrb5
+
+Samba requires version 1.15.1 of MIT Kerberos to build with AD DC support.
+The krb5-devel and krb5-server packages are required.
+The feature set is not on par with with the Heimdal build but the most important
+things, like forest and external trusts, are working. Samba uses the KDC binary
+provided by MIT Kerberos.
+
+Missing features, compared to Heimdal, are:
+  * PKINIT support
+  * S4U2SELF/S4U2PROXY support
+  * RODC support (not fully working with Heimdal either)
+
+The Samba AD process will take care of starting the MIT KDC and it will load a
+KDB (Kerberos Database) driver to access the Samba AD database.  When
+provisioning an AD DC using 'samba-tool' it will take care of creating a correct
+kdc.conf file for the MIT KDC. Note that 'samba-tool' will overwrite the system
+kdc.conf by default. It is possible to use a different location during
+provision. You should consult the 'samba-tool' help and smb.conf manpage for
+details.
+
 
 Authentication and Authorization audit support
 ----------------------------------------------
@@ -40,6 +62,15 @@ authentication, SMB and RPC authorization is covered, however password
 changes are not at this stage, and this support is not currently
 backed by a testsuite.
 
+Parameter changes
+-----------------
+
+The "strict sync" global parameter has been changed from
+a default of "no" to "yes". This means smbd will by default
+obey client requests to synchronize unwritten data in operating
+system buffers safely onto disk. This is a safer default setting
+for modern SMB1/2/3 clients.
+
 smb.conf changes
 ================
 


-- 
Samba Shared Repository



More information about the samba-cvs mailing list