- Timestamp:
- May 20, 2009, 6:46:53 PM (16 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/samba-3.2.x/docs/htmldocs/Samba3-HOWTO/ChangeNotes.html
r149 r204 1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 9. Important and Critical Change Notes for the Samba 3.x Series</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.73.1"><link rel="start" href="index.html" title="The Official Samba 3.2.x HOWTO and Reference Guide"><link rel="up" href="optional.html" title="Part III. Advanced Configuration"><link rel="prev" href="optional.html" title="Part III. Advanced Configuration"><link rel="next" href="NetworkBrowsing.html" title="Chapter 10. Network Browsing"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 9. Important and Critical Change Notes for the Samba 3.x Series</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="optional.html">Prev</a> </td><th width="60%" align="center">Part III. Advanced Configuration</th><td width="20%" align="right"> <a accesskey="n" href="NetworkBrowsing.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="ChangeNotes"></a>Chapter 9. Important and Critical Change Notes for the Samba 3.x Series</h2></div><div><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Gerald</span> <span class="othername">(Jerry)</span> <span class="surname">Carter</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jerry@samba.org">jerry@samba.org</a>></code></p></div></div></div></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="ChangeNotes.html#id25716 46">Important Samba-3.2.x Change Notes</a></span></dt><dt><span class="sect1"><a href="ChangeNotes.html#id2571658">Important Samba-3.0.x Change Notes</a></span></dt><dd><dl><dt><span class="sect2"><a href="ChangeNotes.html#id2571717">User and Group Changes</a></span></dt><dt><span class="sect2"><a href="ChangeNotes.html#id2572028">Essential Group Mappings</a></span></dt><dt><span class="sect2"><a href="ChangeNotes.html#id2572149">Passdb Changes</a></span></dt><dt><span class="sect2"><a href="ChangeNotes.html#id2572209">Group Mapping Changes in Samba-3.0.23</a></span></dt><dt><span class="sect2"><a href="ChangeNotes.html#id2572329">LDAP Changes in Samba-3.0.23</a></span></dt></dl></dd></dl></div><p>1 <html><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1"><title>Chapter 9. Important and Critical Change Notes for the Samba 3.x Series</title><link rel="stylesheet" href="../samba.css" type="text/css"><meta name="generator" content="DocBook XSL Stylesheets V1.73.1"><link rel="start" href="index.html" title="The Official Samba 3.2.x HOWTO and Reference Guide"><link rel="up" href="optional.html" title="Part III. Advanced Configuration"><link rel="prev" href="optional.html" title="Part III. Advanced Configuration"><link rel="next" href="NetworkBrowsing.html" title="Chapter 10. Network Browsing"></head><body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">Chapter 9. Important and Critical Change Notes for the Samba 3.x Series</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="optional.html">Prev</a> </td><th width="60%" align="center">Part III. Advanced Configuration</th><td width="20%" align="right"> <a accesskey="n" href="NetworkBrowsing.html">Next</a></td></tr></table><hr></div><div class="chapter" lang="en"><div class="titlepage"><div><div><h2 class="title"><a name="ChangeNotes"></a>Chapter 9. Important and Critical Change Notes for the Samba 3.x Series</h2></div><div><div class="author"><h3 class="author"><span class="firstname">John</span> <span class="othername">H.</span> <span class="surname">Terpstra</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jht@samba.org">jht@samba.org</a>></code></p></div></div></div></div><div><div class="author"><h3 class="author"><span class="firstname">Gerald</span> <span class="othername">(Jerry)</span> <span class="surname">Carter</span></h3><div class="affiliation"><span class="orgname">Samba Team<br></span><div class="address"><p><code class="email"><<a class="email" href="mailto:jerry@samba.org">jerry@samba.org</a>></code></p></div></div></div></div></div></div><div class="toc"><p><b>Table of Contents</b></p><dl><dt><span class="sect1"><a href="ChangeNotes.html#id2571660">Important Samba-3.2.x Change Notes</a></span></dt><dt><span class="sect1"><a href="ChangeNotes.html#id2571671">Important Samba-3.0.x Change Notes</a></span></dt><dd><dl><dt><span class="sect2"><a href="ChangeNotes.html#id2571731">User and Group Changes</a></span></dt><dt><span class="sect2"><a href="ChangeNotes.html#id2572042">Essential Group Mappings</a></span></dt><dt><span class="sect2"><a href="ChangeNotes.html#id2572162">Passdb Changes</a></span></dt><dt><span class="sect2"><a href="ChangeNotes.html#id2572222">Group Mapping Changes in Samba-3.0.23</a></span></dt><dt><span class="sect2"><a href="ChangeNotes.html#id2572343">LDAP Changes in Samba-3.0.23</a></span></dt></dl></dd></dl></div><p> 2 2 Please read this chapter carefully before update or upgrading Samba. You should expect to find only critical 3 3 or very important information here. Comprehensive change notes and guidance information can be found in the 4 4 section <a class="link" href="upgrading-to-3.0.html" title="Chapter 35. Updating and Upgrading Samba">Updating and Upgrading Samba</a>. 5 </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id25716 46"></a>Important Samba-3.2.x Change Notes</h2></div></div></div><p>5 </p><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2571660"></a>Important Samba-3.2.x Change Notes</h2></div></div></div><p> 6 6 !!!!!!!!!!!!Add all critical update notes here!!!!!!!!!!!!! 7 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id25716 58"></a>Important Samba-3.0.x Change Notes</h2></div></div></div><p>7 </p></div><div class="sect1" lang="en"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a name="id2571671"></a>Important Samba-3.0.x Change Notes</h2></div></div></div><p> 8 8 These following notes pertain in particular to Samba 3.0.23 through Samba 3.0.25c (or more recent 3.0.25 9 9 update). Samba is a fluid and ever changing project. Changes throughout the 3.0.x series release are … … 22 22 This chapter is new to the release of the HOWTO for Samba 3.0.23. It includes much of the notes provided 23 23 in the <code class="filename">WHATSNEW.txt</code> file that is included with the Samba source code release tarball. 24 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id25717 17"></a>User and Group Changes</h3></div></div></div><p>24 </p><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2571731"></a>User and Group Changes</h3></div></div></div><p> 25 25 The change documented here affects unmapped user and group accounts only. 26 26 </p><p> 27 <a class="indexterm" name="id2571730"></a>28 <a class="indexterm" name="id2571737"></a>29 27 <a class="indexterm" name="id2571743"></a> 30 <a class="indexterm" name="id2571753"></a> 31 <a class="indexterm" name="id2571762"></a> 28 <a class="indexterm" name="id2571750"></a> 29 <a class="indexterm" name="id2571757"></a> 30 <a class="indexterm" name="id2571766"></a> 31 <a class="indexterm" name="id2571775"></a> 32 32 The user and group internal management routines have been rewritten to prevent overlaps of 33 33 assigned Relative Identifiers (RIDs). In the past the has been a potential problem when … … 36 36 <code class="literal">net rpc vampire</code>. 37 37 </p><p> 38 <a class="indexterm" name="id2571793"></a>39 <a class="indexterm" name="id2571799"></a>40 38 <a class="indexterm" name="id2571806"></a> 41 <a class="indexterm" name="id2571812"></a> 39 <a class="indexterm" name="id2571813"></a> 40 <a class="indexterm" name="id2571820"></a> 41 <a class="indexterm" name="id2571826"></a> 42 42 Unmapped users are now assigned a SID in the <code class="literal">S-1-22-1</code> domain and unmapped 43 43 groups are assigned a SID in the <code class="literal">S-1-22-2</code> domain. Previously they were … … 46 46 been under the authority of the local SAM (see the man page for <code class="literal">net getlocalsid</code>). 47 47 </p><p> 48 <a class="indexterm" name="id2571849"></a>49 <a class="indexterm" name="id2571856"></a>50 48 <a class="indexterm" name="id2571863"></a> 51 <a class="indexterm" name="id25718 69"></a>49 <a class="indexterm" name="id2571870"></a> 52 50 <a class="indexterm" name="id2571876"></a> 51 <a class="indexterm" name="id2571883"></a> 52 <a class="indexterm" name="id2571890"></a> 53 53 The result is that any unmapped users or groups on an upgraded Samba domain controller may 54 54 be assigned a new SID. Because the SID rather than a name is stored in Windows security … … 60 60 An example helps to illustrate the change: 61 61 </p><p> 62 <a class="indexterm" name="id2571899"></a>63 <a class="indexterm" name="id2571906"></a>64 62 <a class="indexterm" name="id2571912"></a> 65 63 <a class="indexterm" name="id2571919"></a> 64 <a class="indexterm" name="id2571926"></a> 65 <a class="indexterm" name="id2571932"></a> 66 66 Assume that a group named <span class="emphasis"><em>developers</em></span> exists with a UNIX GID of 782. In this 67 67 case this user does not exist in Samba's group mapping table. It would be perfectly normal for … … 69 69 <code class="literal">S-1-5-21-647511796-4126122067-3123570092-2565</code>. 70 70 </p><p> 71 <a class="indexterm" name="id2571943"></a>72 <a class="indexterm" name="id2571949"></a>73 71 <a class="indexterm" name="id2571956"></a> 74 72 <a class="indexterm" name="id2571963"></a> 73 <a class="indexterm" name="id2571970"></a> 74 <a class="indexterm" name="id2571976"></a> 75 75 With the release of Samba-3.0.23, the group SID would be reported as <code class="literal">S-1-22-2-782</code>. Any 76 76 security descriptors associated with files stored on a Windows NTFS disk partition will not allow access based … … 80 80 even though both SIDs in some respect refer to the same UNIX group. 81 81 </p><p> 82 <a class="indexterm" name="id257 1999"></a>83 <a class="indexterm" name="id25720 06"></a>82 <a class="indexterm" name="id2572013"></a> 83 <a class="indexterm" name="id2572020"></a> 84 84 The workaround for versions of Samba prior to 3.0.23, is to create a manual domain group mapping 85 85 entry for the group <span class="emphasis"><em>developers</em></span> to point at the 86 86 <code class="literal">S-1-5-21-647511796-4126122067-3123570092-2565</code> SID. With the release of Samba-3.0.23 this 87 87 workaround is no longer needed. 88 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id25720 28"></a>Essential Group Mappings</h3></div></div></div><p>88 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2572042"></a>Essential Group Mappings</h3></div></div></div><p> 89 89 Samba 3.0.x series releases before 3.0.23 automatically created group mappings for the essential Windows 90 90 domain groups <code class="literal">Domain Admins, Domain Users, Domain Guests</code>. Commencing with Samba 3.0.23 … … 103 103 For further information regarding group mappings see <a class="link" href="groupmapping.html" title="Chapter 12. Group Mapping: MS Windows and UNIX">Group Mapping: MS Windows 104 104 and UNIX</a>. 105 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2572149"></a>Passdb Changes</h3></div></div></div><p> 106 <a class="indexterm" name="id2572156"></a> 107 <a class="indexterm" name="id2572163"></a> 105 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2572162"></a>Passdb Changes</h3></div></div></div><p> 108 106 <a class="indexterm" name="id2572170"></a> 109 107 <a class="indexterm" name="id2572177"></a> 108 <a class="indexterm" name="id2572183"></a> 109 <a class="indexterm" name="id2572190"></a> 110 110 The <a class="link" href="smb.conf.5.html#PASSDBBACKEND">passdb backend</a> parameter no long accepts multiple passdb backends in a 111 111 chained configuration. Also be aware that the SQL and XML based passdb modules have been 112 112 removed in the Samba-3.0.23 release. More information regarding external support for a SQL 113 113 passdb module can be found on the <a class="ulink" href="http://pdbsql.sourceforge.net/" target="_top">pdbsql</a> web site. 114 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2572209"></a>Group Mapping Changes in Samba-3.0.23</h3></div></div></div><p> 115 <a class="indexterm" name="id2572216"></a> 116 <a class="indexterm" name="id2572223"></a> 114 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2572222"></a>Group Mapping Changes in Samba-3.0.23</h3></div></div></div><p> 117 115 <a class="indexterm" name="id2572230"></a> 118 116 <a class="indexterm" name="id2572237"></a> … … 121 119 <a class="indexterm" name="id2572257"></a> 122 120 <a class="indexterm" name="id2572264"></a> 123 <a class="indexterm" name="id257227 0"></a>124 <a class="indexterm" name="id257227 7"></a>121 <a class="indexterm" name="id2572271"></a> 122 <a class="indexterm" name="id2572278"></a> 125 123 <a class="indexterm" name="id2572284"></a> 124 <a class="indexterm" name="id2572291"></a> 125 <a class="indexterm" name="id2572298"></a> 126 126 The default mapping entries for groups such as <code class="literal">Domain Admins</code> are no longer 127 127 created when using an <code class="literal">smbpasswd</code> file or a <code class="literal">tdbsam</code> passdb … … 130 130 Windows group SID to UNIX GID mappings. This change has no effect on winbindd's IDMAP functionality 131 131 for domain groups. 132 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2572329"></a>LDAP Changes in Samba-3.0.23</h3></div></div></div><p> 133 <a class="indexterm" name="id2572337"></a> 134 <a class="indexterm" name="id2572344"></a> 132 </p></div><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2572343"></a>LDAP Changes in Samba-3.0.23</h3></div></div></div><p> 135 133 <a class="indexterm" name="id2572351"></a> 136 134 <a class="indexterm" name="id2572358"></a> 137 135 <a class="indexterm" name="id2572364"></a> 136 <a class="indexterm" name="id2572371"></a> 137 <a class="indexterm" name="id2572378"></a> 138 138 There has been a minor update the Samba LDAP schema file. A substring matching rule has been 139 139 added to the <code class="literal">sambaSID</code> attribute definition. For OpenLDAP servers, this
Note:
See TracChangeset
for help on using the changeset viewer.