ELSA-2023-7139

ELSA-2023-7139 - samba security, bug fix, and enhancement update

Type:SECURITY
Severity:MODERATE
Release Date:2023-11-18

Description


evolution-mapi
[3.28.3-8]
- Related: #2190417 - Rebuild for samba rebase to 4.18.x

openchange
[2.3-32.0.1]
- Use ldconfig_scriptlets

[2.3-32]
- Related: #2190417 (Rebuild for samba rebase to 4.18.x)

samba
[4.18.6-1]
- related: rhbz#2190417 - Update to version 4.18.6
- resolves: rhbz#2232564 - Fix the rpc dsgetinfo command

[4.18.5-0]
- resolves: rhbz#2222894 - Fix CVE-2022-2127 CVE-2023-3347 CVE-2023-34966 CVE-2023-34967 CVE-2023-34968

[4.18.4-2]
- resolves: rhbz#2222884 - Fix trust relationship between workstation and DC

[4.18.4-1]
- resolves: rhbz#2221594 - Fix broken symlink for libwbclient
- resolves: rhbz#2221600 - Fix segfault of winbind child when listing users with winbind scan trusted domains = yes
- resolves: rhbz#2175385 - Fix access of Samba share with veto files = /.*/
- resolves: rhbz#2218237 - Fix Python tarfile extraction to avoid a warning

[4.18.4-0]
- resolves: rhbz#2190417 - Update to version 4.18.4

[4.18.3-0]
- resolves: rhbz#2190417 - Update to version 4.18.3

[4.18.2-2]
- resolves: rhbz#2190417 - Rebuild to trigger distrobaker sync

[4.18.2-1]
- resolves: rhbz#2190417 - Add missing tests to fix osci.brew-build.tier0.functional

[4.18.2-0]
- resolves: rhbz#2190417 - Update to version 4.18.2

[4.17.5-2]
- resolves: rhbz#2169339 - Fix winbind memory leak
- resolves: rhbz#2152899 - Fix Samba shares not accessible issue

[4.17.5-1]
- resolves: rhbz#2167691 - Create package samba-tools

[4.17.5-0]
- related: rhbz#2132051 - Update to version 4.17.5

[4.17.4-1]
- related: rhbz#2132051 - Create package dc-libs also for 'non-dc build'

[4.17.4-0]
- related: rhbz#2132051 - Update to version 4.17.4
- resolves: rhbz#2154370 - Fix CVE-2022-38023
- resolves: rhbz#2142331 - Fix %U include directive for share listing (netshareenum)
- resolves: rhbz#2148943 - Fix Winbind to retrieve user groups from Active Directory

[4.17.2-2]
- Always add epoch to samba_depver to fix osci.brew-build.rpmdeplint.functional
- related: rhbz#2132051

[4.17.2-1]
- resolves: rhbz#2132051 - Update to version 4.17.2
- resolves: rhbz#2126174 - Fix CVE-2022-1615
- resolves: rhbz#2108487 - ctdb: Add dependency to samba-winbind-clients

[4.16.4-2]
- resolves: rhbz#2120956 - Do not require samba package in python3-samba

[4.16.4-1]
- Rebase to version 4.16.4
- resolves: rhbz#2108331 - Fix CVE-2022-32742

[4.16.3-0]
- related: rhbz#2077468 - Rebase Samba to 4.16.3
- resolves: rhbz#2106672 - The pcap background queue process should not be stopped
- resolves: rhbz#2106263 - Fix crash in rpcd_classic
- resolves: rhbz#2100093 - Fix net ads info returns LDAP server and LDAP server name

[4.16.2-1]
- resolves: rhbz#2084162 - Fix printer displays only after 300 seconds timeout

[4.16.2-0]
- Fix rpminspect abidiff
- related: rhbz#2077468 - Rebase Samba to 4.16.2

[4.16.1-0]
- Update to Samba 4.16.1
- resolves: rhbz#2077468 Rebase Samba to the the latest 4.16.x release

[4.15.5-8]
- resolves: rhbz#2070522 - Fix UPNs handling in lookup_name*() calls

[4.15.5-7]
- resolves: rhbz#2076505 - PAM Kerberos authentication fails with a clock skew error

[4.15.5-6]
- resolves: rhbz#2059151 - Fix username map for unix groups
- resolves: rhbz#2065212 - Fix 'create krb5 conf = yes when a KDC has a single IP address.

[4.15.5-4]
- resolves: rhbz#2057503 - Fix winbind kerberos ticket refresh

[4.15.5-3]
- related: rhbz#1979959 - Fix typo in testparm output

[4.15.5-2]
- resolves: rhbz#1979959 - Improve idmap autorid sanity checks and documentation

[4.15.5-1]
- resolves: #1995849 - [RFE] Change change password change prompt phrasing
- resolves: #2029417 - virusfilter_vfs_openat: Not scanned: Directory or special file

[4.15.5-0]
- Update to Samba 4.15.5
- related: rhbz#2013596 - Rebase Samba to the the latest 4.15.x release
- resolves: rhbz#2046127 - Fix CVE-2021-44141
- resolves: rhbz#2046153 - Fix CVE-2021-44142
- resolves: rhbz#2044404 - Printing no longer works on Windows 7
- resolves: rhbz#2043154 - Fix systemd notifications
- resolves: rhbz#2049602 - Disable NTLMSSP for ldap client connections (e.g. libads)

[4.15.4-0]
- Update to Samba 4.15.4
- related: rhbz#2013596 - Rebase Samba to the the latest 4.15.x release
- resolves: rhbz#2039153 - Fix CVE-2021-20316
- resolves: rhbz#1912549 - Winexe: Kerberos flag not invoking Kerberos Auth
- resolves: rhbz#2039157 - Fix CVE-2021-43566
- resolves: rhbz#2038148 - Failed to authenticate users after upgrade samba package to release samba-4.14.5-7
- resolves: rhbz#2035528 - [smb] Segmentation fault when joining the domain
- resolves: rhbz#2038796 - filename_convert_internal: open_pathref_fsp [xxx] failed: NT_STATUS_ACCESS_DENIED

[4.15.3-1]
- related: rhbz#2013596 - Rebase to version 4.15.3
- resolves: rhbz#2028029 - Fix possible null pointer dereference in winbind
- resolves: rhbz#1912549 - Winexe: Kerberos Auth is respected via --use-kerberos=desired

[4.15.2-2]
- related: rhbz#2013596 - Remove unneeded lmdb dependency

[4.15.2-1]
- resolves: rhbz#2013596 - Rebase to version 4.15.2
- resolves: rhbz#1999294 - Remove noisy error message in winbindd
- resolves: rhbz#1958881 - Don't require winbind being online for krb5 auth
with one-way trusts
- resolves: rhbz#2019461 - Fix deleting directories with dangling symlinks

[4.14.5-14]
- related: rbhz#2019674 - Fix CVE-2020-25717
- Fix running ktest (selftest)

[4.14.5-13]
- related: rbhz#2019674 - Fix CVE-2020-25717
- Add missing checks for IPA DC server role

[4.14.5-12]
- related: rbhz#2019674 - Fix regression with 'allow trusted domains = no'

[4.14.5-11]
- resolves: rhbz#2021425 - Add missing PAC buffer types to krb5pac.idl

[4.14.4-3]
- resolves: rhbz#2019662 - Fix CVE-2016-2124
- resolves: rhbz#2019668 - Fix CVE-2021-23192
- resolves: rbhz#2019674 - Fix CVE-2020-25717

[ 4.14.4-2]
- related: rhbz#1980346 - Rebuild for libtalloc 0.11.0

[4.14.4-1]
- resolves: rhbz#1974792 - Create a subpackage for vfs-io-uring
- resolves: rhbz#1965397 - Raise log level for dfs ENOENT debug message

[4.14.4-0]
- related: rhbz#1944657 - Update to version 4.14.5
- resolves: rhbz#1969787 - Fix memory leak in RPC server
- resolves: rhbz#1954974 - Validate smb.conf option for domain members with testparm
- resolves: rhbz#1963298 - Fix smbd trying to delete files with wrong permissions
- resolves: rhbz#1890008 - Update rpcclient manpage to list all available commands
- resolves: rhbz#1857254 - Update smbcacls manpage to document inhertance flags

[4.14.4-4]
- related: rhbz#1944657 - Fix possible upgrade issues

[4.14.4-2]
- resolves: rhbz#1944657 - Update to version 4.14.4
- resolves: rhbz#1949445 - Fix CVE-2021-20254
- resolves: rhbz#1947945 - Fix libsmbldap.so.2 not being a symbolic link
- resolves: rhbz#1908506 - Fix creating the gencache user directory
- resolves: rhbz#1901029 - Build the vfs_io_uring module

[4.13.3-3]
- resolves: #1924615 - Fix a memcache bug when cache is full
- resolves: #1924571 - Ensure that libwbclient has been updated before
restarting services

[4.13.3-2]
- resolves: #1909647 - Fix winbind in trust scenarios with connection issues

[4.13.3-1]
- related: #1878109 - Rebase Samba to version 4.13.3

[4.13.2-5]
- resolves: #1904174 - Fix ldap timeout with 'net ads join'

[4.13.2-4]
- resolves: #1902198 - Document weak crypto output of testparm

[4.13.2-3]
- resolves: #1899113 - Fix following dfs links with smb clients

[4.13.2-2]
- related: #1869702 - Fix spoolss crash
- resolves: #1896736 - Fix name lookups of FreeIPA users
- resolves: #1899113 - Fix DFS links

[4.13.2-1]
- resolves: #1878109 - Rebase Samba to version 4.13.2
- resolves: #1872833 - Add samba-winexe subpackage
- resolves: #1891688 - Fix CVE-2020-14323
- resolves: #1892633 - Fix CVE-2020-14318
- resolves: #1892639 - Fix CVE-2020-14383
- resolves: #1879835 - Fix CVE-2020-1472
- resolves: #1888990 - Update smb.conf manpages to describe how to apply
config changes.
- resolves: #1869702 - Fix %U substitution for 'valid users' option
- resolves: #1818038 - Improve FIPS compliance

[4.12.3-12]
- resolves: #1868558 - cannot create a directory in home over SMB2, mkdirat returns EBADF

[4.12.3-11]
- resolves: #1859277 - Allow a user to use gencache

[4.12.3-10]
- related: #1856315 - Fix net-ads-join with LDAP over TLS

[4.12.3-9]
- related: #1817557 - Move DECRPC mdssvc data files to correct package
- resolves: #1856676 - Fix lookuprids in winbind

[4.12.3-8]
- resolves: #1856315 - Fix net-ads-join with LDAP over TLS

[4.12.3-7]
- resolves: #1855711 - Fix 'require_membership_of' documentation in
pam_winbind manpage

[4.12.3-6]
- related: #1842844 - Fix TLS connections with GnuTLS

[4.12.3-5]
- resolves: #1823612 - Fix segfault in 'net ads dns gethostbyname'
- resolves: #1792553 - Fix 'net ads join createcomputer=OU'

[4.12.3-4]
- resolves: #1850980 - Add 'additional dns hostname' to keytab
- resolves: #1850981 - Add net-ads-join dnshostname=fqdn option

[4.12.3-1]
- resolves: #1666737 - Add a new smbc_readdirplus2() function to libsmbclient
- resolves: #1842844 - Fix GnuTLS priority list for TLS connections

[4.12.3-0]
- resolves: #1817557 - Rebase to version 4.12.3
- resolves: #1813833 - Fix 'net ads join createupn='

[4.11.2-14]
- Rebuild with krb5 1.18
- Resolves: #1817578 - support krb5 1.18

[4.11.2-13]
- resolves: #1802182 - Fix join using netbios name

[4.11.2-12]
- related: #1781232 - Improve debug output of smbclient
- resolves: #1794461 - Do not return bogus inode numbers in
cli_qpathinfo2()/cli_qpathinfo3() for SMB1
- resolves: #1794442 - Fix segfault in smbd_do_qfilepathinfo()

[4.11.2-11]
- resolves: #1778130 - Remove usage of DES encryption types in krb5

[4.11.2-10]
- resolves: #1790353 - Fix access check in DsRGetForestTrustInformation
- resolves: #1791209 - Fix CVE-2019-14907

[4.11.2-9]
- resolves: #1785134 - Fix libwbclient manual alternative settings

[4.11.2-8]
- resolves: #1781232 - Fix smbclient debug message

[4.11.2-7]
- related: #1637861 - Fix trust creation if weak crypto is disallowed

[4.11.2-6]
- resolves: #1637861 - Use GnuTLS for crypto

[4.11.2-4]
- related: #1754409 - Add patch to avoid overlinking with libnsl and libsocket
- related: #1754409 - Fix permissions for pidl
- related: #1754409 - Fix logrotate script
- related: #1754409 - Add missing README files

[4.11.2-3]
- related: #1754409 - Fix pidl packaging

[4.11.2-1]
- resolves: #1754409 - Rebase to Samba version 4.11.2
- resolves: #1776312 - Winbind is not restarted on upgrade
- resolves: #1764469 - Fix CVE-2019-10218
- resolves: #1746241 - Fix CVE-2019-10197
- resolves: #1710980 - Add support for KCM ccache in pam_winbind

[4.10.4-101]
- related: #1760824 - Removed additional issues with overlinking

[4.10.4-100]
- resolves: #1754575 - Avoid overlinking with librt and libpthread
- resolves: #1755440 - Fix forest trusts enumeration
- resolves: #1755445 - Fix CUPS username/password authentication with smbspool

[4.10.4-1]
- resolves: #1712378 - Fix smbspool CUPS backend
- resolves: #1696612 - Fix 'net ads join -U admin@parentdomain'

[4.10.4-0]
- related: #1638001 - Rebase to Samba version 4.10.4
- resolves: #1597298 - Build Samba with python3
- resolves: #1658558 - Add 'net ads leave --keep-account' option
- resolves: #1669004 - Fix systemd status notifications
- resolves: #1672167 - Fix printing cache timeout in debug output
- resolves: #1696525 - Fix CVE-2019-3880

[4.10.3-0]
- related: #1638001 - Rebase to Samba version 4.10.3

[4.10.2-1]
- related: #1638001 - Fix package upgrades

[4.10.2-0]
- resolves: #1638001 - Rebase Samba to version 4.10

[4.9.1-8]
- resolves: #1663421 - Fix perl interpreter dependencies

[4.9.1-7]
- resolves: #1658690 - Add smbc_setOptionProtocols()
- resolves: #1658678 - Fix spoolss client operations against Windows

[4.9.1-6]
- resolves: #1642092 - Harden [homes] share export
- resolves: #1648846 - Fix out of bound array access in ctdb
- resolves: #1657266 - Fix tmp directory creation in /run

[4.9.1-5]
- resolves: #1644327 - Segfault if wrong 'passdb backend' is configured
- resolves: #1647959 - Segfault in the debug system with hardended build

[4.9.1-4]
- related: #1614232 - Fix some spec file issues detected by rpmdiff

[4.9.1-3]
- Temporarily remove smbtorture from samba-test due to Python 2 linkage
- related: #1609661 - samba-test package cannot be installed due to unresolved dependencies

[4.9.1-2]
- related: #1614232 - Add CTDB examples with a config migration script

[4.9.1-1]
- resolves: #1614232 - Update to Samba 4.9.1

[4.9.0rc5-3]
- related: #1614232 - Update to Samba 4.9.0rc5
- resolves: #1610909 - Re-enable glubsterfs vfs module
- resolves: #1624170 - Build with -fstack-protectore-strong if available
- resolves: #1602685 - Fixed issues found by covscan

[4.9.0rc3-3]
- related: #1614232 - Update to Samba 4.9.0rc3
- resolves: #1554753 - Fix CVE-2018-1050
- resolves: #1617912 - Fix CVE-2018-10858
- resolves: #1617913 - Fix CVE-2018-10918
- resolves: #1617914 - Fix CVE-2018-10919
- resolves: #1617915 - Fix CVE-2018-1139
- resolves: #1612522 - Manpage fixes

[4.9.0rc2-2]
- Update to Samba 4.9.0rc2

[4.9.0rc1-2]
- Do not package Python 2 artefacts by default

[4.9.0rc1-1]
- Don't build dns and dsdb-related modules without AD DC

[4.9.0rc1-0]
- Update to Samba 4.9.0rc1

[4.8.3-2]
- Use %{__python2}, not 'python', as the Python2 interpreter
- Add workaround to allow building with Python 2
- Change unversioned python macros to python2
- Disable gluster temporarily

[4.8.3-1]
- Update to Samba 4.8.3
- Remove python(2|3)-subunit dependency

[2:4.8.2-1.1]
- Rebuilt for Python 3.7

[4.8.2-0]
- Update to Samba 4.8.2

[4.8.1-1]
- resolves: #1574177 - Fix smbspool command line argument handling

[4.8.1-0]
- Update to Samba 4.8.1

[4.8.0-7]
- resolves: #1554754, #1554756 - Security fixes for CVE-2018-1050 CVE-2018-1057
- resolves: #1555112 - Update to Samba 4.8.0

[4.8.0rc4-6]
- resolves: #1552652 - Fix usage of nc in ctdb tests and only recommned it

[4.8.0rc4-5]
- Update to Samba 4.8.0rc4

[4.8.0rc3-4]
- Update to Samba 4.8.0rc3

[2:4.8.0-0.3.rc2.1]
- Escape macros in %changelog

[4.8.0rc2-3]
- Update to Samba 4.8.0rc2

[2:4.8.0-0.2.rc1]
- Explicitly BR: rpcsvc-proto-devel

[2:4.8.0-0.1.rc1.1]
- Rebuilt for switch to libxcrypt

[4.8.0rc1-1]
- Update to Samba 4.8.0rc1

[4.7.4-1]
- resolves: #1508092 - Add missing dependency for tdbbackup

[4.7.4-0]
- Update to Samba 4.7.4

[4.7.3-3]
- resolves: #1520163 - Link libaesni-intel-samba4.so with -z noexecstack

[4.7.3-2]
- Fix deamon startup with systemd

[4.7.3-1]
- Enable AES acceleration on Intel compatible CPUs by default

[4.7.3-0]
- Update to Samba 4.7.3
- resolves: #1515692 - Security fix for CVE-2017-14746 and CVE-2017-15275

[4.7.2-0]
- resolves: #1513452 - Update to Samba 4.7.2

[4.7.1-2]
- Fix release number

[4.7.1-1]
- Remove old crufty coreutils requires

[4.7.1-0]
- resolves: #1508871 - Update to Samba 4.7.1

[4.7.0-18]
- Force samba-dc to use the same libldb version as LDB modules compiled
- resolves: #1507420 - LDB / Samba module version mismatch

[4.7.0-17]
- Move dsdb libs to python2-samba-dc

[4.7.0-16]
- Create python[2|3]-samba-dc packages

[4.7.0-15]
- related: #1499140 - Fix several dependency issues
- Fix building with MIT Kerberos 1.16

[4.7.0-14]
- resolves: #1499140 - Move libdfs-server-ad to the correct subpackage

[4.7.0-13]
- Move /usr/lib{64,}/samba/libdsdb-garbage-collect-tombstones-samba4.so to samba-dc-libs
- Rebuild in rawhide against new krb5 1.16 and docbook-xml

[4.7.0-12]
- Update to Samba 4.7.0
- resolves: #1493441 - Security fix for CVE-2017-12150 CVE-2017-12151 CVE-2017-12163

[4.7.0-0.11.rc6]
- Update to Samba 4.7.0rc6

[4.7.0-0.11.rc5]
- resolves: #1491137 - dcerpc/__init__.py is not packaged for py3

[4.7.0-0.10.rc5]
- resolves: #1476175 - Create seperate package for bind_dlz module

[4.7.0-0.9.rc5]
- Update to Samba 4.7.0rc5

[4.7.0-0.9.rc3]
- Add printadmin group for printer driver handling

[2:4.7.0-0.8.rc3.2]
- Rebuild with binutils fix for ppc64le (#1475636)

[2:4.7.0-0.8.rc3.1]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild

[4.7.0-0.8.rc3]
- resolves: #1301002 - Enable avahi support

[4.7.0-0.7.rc3]
- Update to Samba 4.7.0rc3

[4.7.0-0.7.rc1]
- Rename samba-python to python2-samba
- Update build requirement for libcephfs

[4.7.0-0.6.rc1]
- Use Python 2 explicitly for samba-tool and other Python-based tools
- Install samba.service as it is required for the AD DC case

[4.7.0-0.5.rc1]
- Convert more rpc modules to python3
- Explicitly specify Python artifacts in the spec to be able to catch unpackaged ones
- Split 'make test' Python code into separate python2-samba-test/python3-samba-test sub-packages
- Remove embedded python2-dns version, require python{2,3}-dns instead

[4.7.0-0.4.rc1]
- Add python3 support
- Fix %posttrans for libwbclient-devel

[4.7.0-0.3.rc1]
- Do not install conflicting file _ldb_text.py

[4.7.0-0.2.rc1]
- Fix requirement generation for shared libraries

[4.7.0-0.1.rc1]
- Build Samba with Active Directory support!

[4.7.0-0.0.rc1]
- Update to Samba 4.7.0rc1

[4.6.5-0]
- Update to Samba 4.6.5

[2:4.6.4-1.1]
- Perl 5.26 rebuild

[4.6.4-1]
- #resolves: #1451486 - Add source tarball comment

[4.6.4-0]
- Update to Samba 4.6.4
- resolves: #1455050 - Security fix for CVE-2017-7494

[4.6.3-0]
- Update to Samba 4.6.3

[4.6.2-0]
- Update to Samba 4.6.2
- related: #1435156 - Security fix for CVE-2017-2619

[4.6.1-0]
- Update to Samba 4.6.1
- resolves: #1435156 - Security fix for CVE-2017-2619

[4.6.0-4]
- Export arcfour_crypt_blob to Python as samba.crypto.arcfour_encrypt
- Makes possible to run trust to AD in FreeIPA in FIPS mode

[4.6.0-3]
- auth/credentials: Always set the the realm if we set the principal from the ccache
- resolves: #1430761 - credentials_crb5: use gss_acquire_cred for client-side GSSAPI use case

[4.6.0-2]
- resolves: #1430761 - credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case

[4.6.0-1]
- Update to Samba 4.6.0

[4.6.0-0.3.rc4]
- Update to Samba 4.6.0rc4

[4.6.0-0.1.rc3]
- Update to Samba 4.6.0rc3

[4.6.0-0.1.rc2.1]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild

[4.6.0-0.1.rc2]
- Update to Samba 4.6.0rc2

[4.6.0-0.1.rc1]
- resolves: #1319098 - Add missing Requires for pre-required packages

[4.6.0-0.1.rc1]
- Update to Samba 4.6.0rc1

[4.5.3-0]
- Update to Samba 4.5.3
- resolves: #1405984 - CVE-2016-2123,CVE-2016-2125 and CVE-2016-2126

[4.5.2-0]
- Update to Samba 4.5.2

[-]
- rebuild (libldb)

[4.5.1-1]
- Fix glfs_realpath allocation in vfs_glusterfs

[4.5.1-0]
- Update to Samba 4.5.1

[4.5.0-3]
- resolves: 1375973 - Fix tevent incompatibility issue

[4.5.0-2]
- Fix smbspool alternatives handling during samba-client uninstall

[4.5.0-1]
- Update to Samba 4.5.0

[4.5.0rc3-0]
- Update to Samba 4.5.0rc3

[4.5.0rc2-0]
- Update to Samba 4.5.0rc2

[4.5.0rc1-0]
- Update to Samba 4.5.0rc1

[2:4.4.5-1.1]
- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages

[4.4.5-1]
- Update to Samba 4.4.5
- resolves: #1353504 - CVE-2016-2119

[4.4.4-4]
- resolves: #1348899 - Import of samba.ntacls fails

[4.4.4-3]
- resolves: #1337260 - Small fix to the example smb.conf file

[4.4.4-2]
- Fix resolving trusted domain users on domain member

[4.4.4-1]
- Update to Samba 4.4.4
- resolves: #1343529

[2:4.4.3-2]
- Fix libsystemd patch (#1125086) so that it actually works

[2:4.4.3-1.2]
- Rebuild to drop libsystemd-daemon dependency (#1125086)

[2:4.4.3-1.1]
- Perl 5.24 rebuild

[4.4.3-1]
- Update to Samba 4.4.3
- resolves: #1332178

[4.4.2-1]
- Update to Samba 4.4.2, fix badlock security bug
- resolves: #1326453 - CVE-2015-5370
- resolves: #1326453 - CVE-2016-2110
- resolves: #1326453 - CVE-2016-2111
- resolves: #1326453 - CVE-2016-2112
- resolves: #1326453 - CVE-2016-2113
- resolves: #1326453 - CVE-2016-2114
- resolves: #1326453 - CVE-2016-2115
- resolves: #1326453 - CVE-2016-2118

[4.4.0-1]
- Update to Samba 4.4.0

[4.4.0-0.8.rc5]
- Update to Samba 4.4.0rc5

[4.4.0-0.7.rc4]
- Update to Samba 4.4.0rc4
- resolves: #1315942 - CVE-2015-7560 Incorrect ACL get/set allowed on symlink path

[4.4.0-0.6.rc3]
- Update to Samba 4.4.0rc3

[4.4.0-0.5.rc2]
- Activate multi channel support (switched off by default)

[4.4.0-0.4.rc2]
- More spec file fixes
- resolves: #1306542 - scriptlet failure because of comments

[4.4.0-0.3.rc2]
- More spec file fixes

[4.4.0-0.2.rc2]
- More spec file fixes

[4.4.0-0.1.rc2]
- Update to Samba 4.4.0rc2

[2:4.4.0-0.1.rc1]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild

[4.4.0-0.0.rc1]
- Update to Samba 4.4.0rc1

[4.3.4-1]
- resolves: #1300038 - PANIC: Bad talloc magic value - wrong talloc version used/mixed

[4.3.4-0]
- resolves: #1261230 - Update to Samba 4.3.4

[4.3.3-0]
- Update to Samba 4.3.3
- resolves: #1292069
- CVE-2015-3223 Remote DoS in Samba (AD) LDAP server
- CVE-2015-5252 Insufficient symlink verification in smbd
- CVE-2015-5296 Samba client requesting encryption vulnerable to
downgrade attack
- CVE-2015-5299 Missing access control check in shadow copy code
- CVE-2015-7540 DoS to AD-DC due to insufficient checking of asn1
memory allocation

[4.3.2-2]
- revert dependencies to samba-common and -tools

[4.3.2-1]
- resolves: #1261230 - Update to Samba 4.3.2

[4.3.1-3]
- resolves: #1282931 - Fix DCE/RPC bind nak parsing

[4.3.1-2]
- Fix dependencies to samba-common

[4.3.1-1]
- resolves: #1261230 - Update to Samba 4.3.1

[4.3.0-3]
- Use separate lockdir

[4.3.0-2]
- resolves: #1270568 - Samba fails to start after update to 4.3.0

[4.3.0-1]
- resolves: #1088911 - Update to Samba 4.3.0

[4.3.0-0.1rc4]
- Update to Samba 4.3.0rc4

[4.3.0-0.1rc3]
- Update to Samba 4.3.0rc3

[4.2.3-0]
- resolves: #1088911 - Update to Samba 4.2.3

[4.2.2-1]
- resolves: #1227911 - Enable tar support for smbclient
- resolves: #1234908 - Own the /var/lib/samba directory
- Enable hardened build

[2:4.2.2-0.2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild

[2:4.2.2-0.1]
- Perl 5.22 rebuild

[4.2.2-0]
- Update to Samba 4.2.2

[4.2.1-8]
- Fixes: #1219832: Samba 4.2 broke FreeIPA trusts to AD
- Remove usage of deprecated API from gnutls

[4.2.1-7]
- Fix LSASD daemon
- resolves: #1217346 - FreeIPA trusts to AD broken due to Samba 4.2 failure to run LSARPC pipe externally

[4.2.1-6]
- Remove samba-common-tools from samba-client package as it brings back Python 2.7

[4.2.1-5]
- Require samba-common-tools in samba package
- Require samba-common-tools in samba-client package
- resolves: #1215631 - /usr/bin/net moved to samba-common-tools but the package is not required by samba

[4.2.1-4]
- Fix systemd library detection (incomplete patch upstream)

[4.2.1-3]
- resolves: #1214973 - Fix libwbclient alternatives link.

[4.2.1-2]
- Add vfs snapper module.

[4.2.1-1]
- Update to Samba 4.2.1
- resolves: #1213373 - Fix DEBUG macro issues in public headers

[4.2.0-3]
- resolves: #1207381 - Fix libsystemd detection.

[4.2.0-2]
- Fix the AD build.
- Create samba-client-libs subpackage.
- Fix multiarch issues by splitting the samba-common package.

[4.2.0-1]
- Update to Samba 4.2.0

[4.2.0-0.5.rc5]
- Update to Samba 4.2.0rc5

[4.2.0-0.4.rc4]
- Update to Samba 4.2.0rc4
- resolves: #1154600 - Install missing samba pam.d configuration file.

[4.2.0-0.6.rc3]
- Fix awk as a dependency (and require gawk)

[4.2.0-0.5.rc3]
- Add dependencies for ctdb.

[4.2.0-0.4.rc3]
- Apply the DEBUG patch

[4.2.0-0.3.rc3]
- Fix issues with conflicting DEBUG macros.

[4.2.0-0.2.rc3]
- Improve dependencies of vfs-glusterfs and vfs-cephfs.
- Remove unused python_libdir.
- Fix malformed changelog entries.

[4.2.0-0.2.rc3]
- Fix ctdb and libcephfs dependencies.

[4.2.0-0.1.rc3]
- Update to Samba 4.2.0rc3
+ Samba provides ctdb packages now.

[4.2.0-0.3.rc2]
- resolves: #1174412 - Build VFS Ceph module.
- resolves: #1169067 - Move libsamba-cluster-support.so to samba-libs package.
- resolves: #1016122 - Move smbpasswd to samba-common package.

[4.2.0-0.2.rc2]
- Use alternatives for libwbclient.
- Add cwrap to BuildRequires.

[4.2.0-0.1.rc2]
- Update to Samba 4.2.0rc2.

[4.1.12-5]
- resolves: #1033595 - Fix segfault in winbind.

[4.1.12-1]
- Update to Samba 4.1.12.

[2:4.1.11-1.4]
- Perl 5.20 mass

[2:4.1.11-1.3]
- Perl 5.20 rebuild

[2:4.1.11-1.2]
- Rebuilt for rpm dependency generator failure (#1131892)

[0:4.1.11-1.1]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild

[4.1.11-1]
- Update to upstream Samba 4.1.11 release
- resolves: #1126015 - Fix CVE-2014-3560

[4.1.9-3]
- Update to Samba 4.1.9.
- resolves: #1112251 - Fix CVE-2014-0244 and CVE-2014-3493.

[4.1.8-3]
- Update to Samba 4.1.8.
- resolves: #1102528 - CVE-2014-0178.

[2:4.1.6-3.1]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild

[4.1.6-3]
- Add systemd integration to the service daemons.

[4.1.6-2]
- Created a samba-test-libs package.

[4.1.6-1]
- Fix CVE-2013-4496 and CVE-2013-6442.
- Fix installation of pidl.

[4.1.5-1]
- Update to Samba 4.1.5.

[4.1.4-1]
- Update to Samba 4.1.4.

[4.1.3-3]
- resolves: #1042845 - Do not build with libbsd.

[4.1.3-2]
- resolves: #1019469 - Fix winbind debug message NULL pointer derreference.

[4.1.3-1]
- Update to Samba 4.1.3.
- resolves: #1039454 - CVE-2013-4408.
- resolves: #1039500 - CVE-2012-6150.

[4.1.2-1]
- Update to Samba 4.1.2.

[4.1.1-3]
- resolves: #948509 - Fix manpage correctness.

[4.1.1-2]
- related: #884169 - Fix strict aliasing warnings.

[4.1.1-1]
- resolves: #1024544 - Fix CVE-2013-4475.
- Update to Samba 4.1.1.

[4.1.0-5]
- related: #884169 - Fix the upgrade path.

[4.1.0-4]
- related: #884169 - Add direct dependency to samba-libs in the
glusterfs package.
- resolves: #996567 - Fix userPrincipalName composition.
- related: #884169 - Fix memset call with zero length in in ntdb.

[4.1.0-3]
- resolves: #1020329 - Build glusterfs VFS plguin.

[4.1.0-2]
- resolves: #1018856 - Fix installation of pam_winbind after upgrade.
- related: #1010722 - Split out a samba-winbind-modules package.
- related: #985609

[4.1.0-1]
- related: #985609 - Update to Samba 4.1.0.

[2:4.1.0-0.8]
- related: #985609 - Update to Samba 4.1.0rc4.
- resolves: #1010722 - Split out a samba-winbind-modules package.

[2:4.1.0-0.7]
- related: #985609 - Update to Samba 4.1.0rc3.
- resolves: #1005422 - Add support for KEYRING ccache type in pam_winbindd.

[2:4.1.0-0.6]
- resolves: #717484 - Enable profiling data support.

[2:4.1.0-0.5]
- resolves: #996160 - Fix winbind with trusted domains.

[2:4.1.0-0.4]
- resolves: #996160 - Fix winbind nbt name lookup segfault.

[2:4.1.0-0.3]
- related: #985609 - Update to Samba 4.1.0rc2.

[2:4.1.0-0.2.rc1.1]
- Perl 5.18 rebuild

[2:4.1.0-0.2]
- resolves: #985985 - Fix file conflict between samba and wine.
- resolves: #985107 - Add support for new default location for Kerberos
credential caches.

[2:4.1.0-0.1.rc1.1]
- Perl 5.18 rebuild

[2:4.1.0-0.1]
- Update to Samba 4.1.0rc1.

[2:4.0.7-2]
- resolves: #972692 - Build with PIE and full RELRO.
- resolves: #884169 - Add explicit dependencies suggested by rpmdiff.
- resolves: #981033 - Local user's krb5cc deleted by winbind.
- resolves: #984331 - Fix samba-common tmpfiles configuration file in wrong
directory.

[2:4.0.7-1]
- Update to Samba 4.0.7.

[2:4.0.6-3]
- Add UPN enumeration to passdb internal API (bso #9779).

[2:4.0.6-2]
- resolves: #966130 - Fix build with MIT Kerberos.
- List vfs modules in spec file.

[2:4.0.6-1]
- Update to Samba 4.0.6.
- Remove SWAT.

[2:4.0.5-1]
- Update to Samba 4.0.5.
- Add UPN enumeration to passdb internal API (bso #9779).
- resolves: #928947 - samba-doc is obsolete now.
- resolves: #948606 - LogRotate should be optional, and not a hard 'Requires'.

[2:4.0.4-3]
- resolves: #919405 - Fix and improve large_readx handling for broken clients.
- resolves: #924525 - Don't use waf caching.

[2:4.0.4-2]
- resolves: #923765 - Improve packaging of README files.

[2:4.0.4-1]
- Update to Samba 4.0.4.

[2:4.0.3-4]
- resolves: #919333 - Create /run/samba too.

[2:4.0.3-3]
- Fix the cache dir to be /var/lib/samba to support upgrades.

[2:4.0.3-2]
- resolves: #907915 - libreplace.so => not found

[2:4.0.3-1]
- Update to Samba 4.0.3.
- resolves: #907544 - Add unowned directory /usr/lib64/samba.
- resolves: #906517 - Fix pidl code generation with gcc 4.8.
- resolves: #908353 - Fix passdb backend ldapsam as module.

[2:4.0.2-1]
- Update to Samba 4.0.2.
- Fixes CVE-2013-0213.
- Fixes CVE-2013-0214.
- resolves: #906002
- resolves: #905700
- resolves: #905704
- Fix conn->share_access which is reset between user switches.
- resolves: #903806
- Add missing example and make sure we don't introduce perl dependencies.
- resolves: #639470

[2:4.0.1-1]
- Update to Samba 4.0.1.
- Fixes CVE-2013-0172.

[2:4.0.0-174]
- Fix typo in winbind-krb-locator post uninstall script.

[2:4.0.0-173]
- Update to Samba 4.0.0.

[2:4.0.0-171.rc6]
- Fix typo in winbind-krb-locator post uninstall script.

[2:4.0.0-170.rc6]
- Update to Samba 4.0.0rc6.
- Add /etc/pam.d/samba for swat to work correctly.
- resolves #882700

[2:4.0.0-169.rc5]
- Make sure ncacn_ip_tcp client code looks for NBT_NAME_SERVER name types.

[2:4.0.0-168.rc5]
- Reduce dependencies of samba-devel and create samba-test-devel package.

[2:4.0.0-167.rc5]
- Use workaround for winbind default domain only when set.
- Build with old ctdb support.

[2:4.0.0-166.rc5]
- Update to Samba 4.0.0rc5.

[2:4.0.0-165.rc4]
- Fix library dependencies of libnetapi.

[2:4.0.0-164.rc4]
- resolves: #872818 - Fix perl dependencies.

[2:4.0.0-163.rc4]
- Update to Samba 4.0.0rc4.

[2:4.0.0-162.rc3]
- resolves: #870630 - Fix scriptlets interpeting a comment as argument.

[2:4.0.0-161.rc3]
- Add missing Requries for python modules.
- Add NetworkManager dispatcher script for winbind.

[2:4.0.0-160.rc3]
- resolves: #867893 - Move /var/log/samba to samba-common package for
winbind which requires it.

[2:4.0.0-159.rc3]
- Compile default auth methods into smbd.

[2:4.0.0-158.rc3]
- Move pam_winbind.conf and the manpages to the right package.

[2:4.0.0-157.rc3]
* resolves: #866959 - Build auth_builtin as static module.

[2:4.0.0-156.rc3]
- Update systemd Requires to reflect latest packaging guidelines.

[2:4.0.0-155.rc3]
- Add back the AES patches which didn't make it in rc3.

[2:4.0.0-154.rc3]
- Update to 4.0.0rc3.
- resolves: #805562 - Unable to share print queues.
- resolves: #863388 - Unable to reload smbd configuration with systemctl.

[2:4.0.0-153.rc2]
- Use alternatives to configure winbind_krb5_locator.so
- Fix Requires for winbind.

[2:4.0.0-152.rc2]
- Add kerberos AES support.
- Fix printing initialization.

[2:4.0.0-151.rc2]
- Update to 4.0.0rc2.

[2:4.0.0-150.rc1]
- Fix Obsoletes/Provides for update from samba4.
- Bump release number to be bigger than samba4.

[2:4.0.0-96.rc1]
- Package smbprint again.

[2:4.0.0-95.rc1]
- Update to 4.0.0rc1.

[2:3.6.7-94.2]
- Update to 3.6.7

[2:3.6.6-93.2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild

[2:3.6.6-93]
- Fix printing tdb upgrade for 3.6.6
- resolves: #841609

[2:3.6.6-92]
- Call ldconfig at libwbclient and -winbind-clients post(un)install time.
- Fix empty localization files, use %find_lang to find and %lang-mark them.
- Escape macros in %changelog.
- Fix source tarball URL.

[2:3.6.6-91]
- Update to 3.6.6

[2:3.6.5-90]
- Fix ldonfig.
- Require systemd for samba-common package.
- resolves: #829197

[2:3.6.5-89]
- Fix usrmove paths.
- resolves: #829197

[2:3.6.5-88]
- Move tmpfiles.d config to common package as it is needed for smbd and
winbind.
- Make sure tmpfiles get created after installation.

[2:3.6.5-87]
- Correctly use system iniparser library

[2:3.6.5-86]
- Bump Epoch to fix a problem with a Samba4 update in testing.

[1:3.6.5-85]
- Security Release, fixes CVE-2012-2111
- resolves: #817551

[1:3.6.4-84]
- Fix creation of /var/run/samba.
- resolves: #751625

[1:3.6.4-83]
- Avoid private krb5_locate_kdc usage
- resolves: #754783

[1:3.6.4-82]
- Update to 3.6.4
- Fixes CVE-2012-1182

[1:3.6.3-81]
- Fix provides for of libwclient-devel for samba-winbind-devel.

[1:3.6.3-80]
- Add commented out 'max protocol' to the default config.

[1:3.6.3-79]
- Create a libwbclient package.
- Replace winbind-devel with libwbclient-devel package.

[1:3.6.3-78]
- Update to 3.6.3
- Fixes CVE-2012-0817

[1:3.6.1-77.1]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild

[1:3.6.1-77]
- Fix winbind cache upgrade.
- resolves: #760137

[1:3.6.1-76]
- Fix piddir to match with systemd files.
- Fix crash bug in the debug system.
- resolves: #754525

[1:3.6.1-75]
- Fix systemd dependencies
- resolves: #751397

[1:3.6.1-74]
- Update to 3.6.1

[1:3.6.0-73]
- Fix nmbd startup
- resolves: #741630

[1:3.6.0-72]
- convert to systemd
- restore epoch from f15

[3.6.0-71]
- Update to 3.6.0 final

[3.6.0rc3-70]
- Update to 3.6.0rc3

[3.6.0rc2-69]
- Update to 3.6.0rc2

[3.6.0rc1-68]
- Update to 3.6.0rc1

[3.6.0pre3-67]
- Update to 3.6.0pre3

[3.6.0pre2-66]
- Update to 3.6.0pre2

[3.6.0pre1-65]
- Enable quota support

[0:3.6.0-64pre1.1]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild

[3.6.0pre1-64]
- Add %ghost entry for /var/run using tmpfs
- resolves: #656685

[3.6.0pre1-63]
- Put winbind krb5 locator plugin into a separate rpm
- resolves: #627181

[3.6.0pre1-62]
- Update to 3.6.0pre1

[3.5.4-61]
- Update to 3.5.4

[3.5.3-60]
- Update to 3.5.3
- Make sure nmb and smb initscripts return LSB compliant return codes
- Fix winbind over ipv6

[3.5.2-59]
- Update to 3.5.2

[3.5.1-58]
- Security update to 3.5.1
- Fixes CVE-2010-0728

[3.5.0-57]
- Remove cifs.upcall and mount.cifs entirely

[3.5.0-56]
- Update to 3.5.0

[3.5.0rc3-55]
- Update to 3.5.0rc3

[3.5.0rc2-54]
- Update to 3.5.0rc2

[3.5.0rc1-53]
- separate out CIFS tools into cifs-utils package

[3.5.0rc1-52]
- Update to 3.5.0rc1

[3.5.0pre2-51]
- Update to 3.5.0pre2
- Remove umount.cifs

[3.4.3-49]
- Various updates to inline documentation in default smb.conf file
- resolves: #483703

[3.4.3-48]
- Update to 3.4.3

[3.4.2-47]
- Spec file cleanup
- Fix sources upstream location
- Remove conditionals to build talloc and tdb, now they are completely indepent
packages in Fedora
- Add defattr() where missing
- Turn all tabs into 4 spaces
- Remove unused migration script
- Split winbind-clients out of main winbind package to avoid multilib to include
huge packages for no good reason

[3.4.2-0.46]
- Update to 3.4.2
- Security Release, fixes CVE-2009-2813, CVE-2009-2948 and CVE-2009-2906

[3.4.1-0.45]
- Use password-auth common PAM configuration instead of system-auth

[3.4.1-0.44]
- Update to 3.4.1

[3.4.0-0.43]
- Fix cli_read()
- resolves: #516165

[3.4.0-0.42]
- Fix required talloc version number
- resolves: #516086

[0:3.4.0-0.41.1]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild

[3.4.0-0.41]
- Fix Bug #6551 (vuid and tid not set in sessionsetupX and tconX)
- Specify required talloc and tdb version for BuildRequires

[3.4.0-0.40]
- Update to 3.4.0

[3.4.0rc1-0.39]
- Update to 3.4.0rc1

[3.4.0pre2-0.38]
- Update to 3.4.0pre2

[3.4.0pre1-0.37]
- Update to 3.4.0pre1

[3.3.4-0.36]
- Update to 3.3.4

[3.3.3-0.35]
- Enable build of idmap_tdb2 for clustered setups

[3.3.3-0.34]
- Update to 3.3.3

[3.3.2-0.33]
- Fix nmbd init script nmbd reload was causing smbd not nmbd to reload the
configuration
- Fix upstream bug 6224, nmbd was waiting 5+ minutes before running elections on
startup, causing your own machine not to show up in the network for 5 minutes
if it was the only client in that workgroup (fix committed upstream)

[3.3.2-0.31]
- Update to 3.3.2
- resolves: #489547

[3.3.1-0.30]
- Add libcap-devel to requires list (resolves: #488559)

[3.3.1-0.29]
- Make the talloc and ldb packages optionsl and disable their build within
the samba3 package, they are now built as part of the samba4 package
until they will both be released as independent packages.

[3.3.1-0.28]
- Enable cluster support

[3.3.1-0.27]
- Update to 3.3.1

[3.3.0-0.26]
- Rename ldb* tools to ldb3* to avoid conflicts with newer ldb releases

[3.3.0-0.25]
- Update to 3.3.0 final
- Add upstream fix for ldap connections to AD (Bug #6073)
- Remove bogus perl dependencies (resolves: #473051)

[3.3.0-0rc1.24]
- Update to 3.3.0rc1

[3.2.5-0.23]
- Security Release, fixes CVE-2008-4314

[3.2.4-0.22]
- Update to 3.2.4
- resolves: #456889
- move cifs.upcall to /usr/sbin

[3.2.3-0.21]
- Security fix for CVE-2008-3789

[3.2.2-0.20]
- Update to 3.2.2

[3.2.1-0.19]
- Add fix for CUPS problem, fixes bug #453951

[3.2.1-0.18]
- Update to 3.2.1

[3.2.0-2.17]
- Update to 3.2.0 final
- resolves: #452622

[3.2.0-1.rc2.16]
- Update to 3.2.0rc2
- resolves: #449522
- resolves: #448107

[3.2.0-1.rc1.15]
- Fix security=server
- resolves: #449038, #449039

[3.2.0-1.rc1.14]
- Add fix for CVE-2008-1105
- resolves: #446724

[3.2.0-1.rc1.13]
- Update to 3.2.0rc1

[3.2.0-1.pre3.12]
- make it possible to print against Vista and XP SP3 as servers
- resolves: #439154

[3.2.0-1.pre3.11]
- Add 'net ads join createcomputer=ou1/ou2/ou3' fix (BZO #5465)

[3.2.0-1.pre3.10]
- Add smbclient fix (BZO #5452)

[3.2.0-1.pre3.9]
- Update to 3.2.0pre3

[3.2.0-1.pre2.8]
- Add fixes for libsmbclient and support for r/o relocations

[3.2.0-1.pre2.7]
- Fix libnetconf, libnetapi and msrpc DSSETUP call

[3.2.0-1.pre2.6]
- Create separate packages for samba-winbind and samba-winbind-devel
- Add cifs.spnego helper

[3.2.0-1.pre2.3]
- Update to 3.2.0pre2
- Add talloc and tdb lib and devel packages
- Add domainjoin-gui package

[3.2.0-0.pre1.3]
- Try to fix GCC 4.3 build
- Add --with-dnsupdate flag and also make sure other flags are required just to
be sure the features are included without relying on autodetection to be
successful

[0:3.2.0-1.pre1.2]
- Autorebuild for GCC 4.3

[3.2.0-0.pre1.2]
- Rebuild for openldap bump

[3.2.0-0.pre1.1.fc9]
- 32/64bit padding fix (affects multilib installations)

[3.2.0-0.pre1.fc9]
- New major relase, minor switched from 0 to 2
- License change, the code is now GPLv3+
- Numerous improvements and bugfixes included
- package libsmbsharemodes too
- remove smbldap-tools as they are already packaged separately in Fedora
- Fix bug 245506

[3.0.26a-1.fc8]
- rebuild with AD DNS Update support

[3.0.26a-0.fc8]
- upgrade to the latest upstream realease
- includes security fixes released today in 3.0.26

[3.0.25c-4.fc8]
- add fix reported upstream for heavy idmap_ldap memleak

[3.0.25c-3.fc8]
- fix a few places were 'open' is used an interfere with the new glibc

[3.0.25c-2.fc8]
- remove old source
- add patch to fix samba bugzilla 4772

[3.0.25c-0.fc8]
- update to 3.0.25c

[3.0.25b-3.fc8]
- handle cases defined in #243766

[3.0.25b-2.fc8]
- update to 3.0.25b
- better error codes for init scripts: #244823

* Tue May 29 2007 Gunther Deschner
- fix pam_smbpass patch.

* Fri May 25 2007 Simo Sorce
- update to 3.0.25a as it contains many fixes
- add a fix for pam_smbpass made by Gunther but committed upstream after 3.0.25a was cut.

* Mon May 14 2007 Simo Sorce
- final 3.0.25
- includes security fixes for CVE-2007-2444,CVE-2007-2446,CVE-2007-2447

* Mon Apr 30 2007 Gunther Deschner
- move to 3.0.25rc3

* Thu Apr 19 2007 Simo Sorce
- fixes in the spec file
- moved to 3.0.25rc1
- addedd patches (merged upstream so they will be removed in 3.0.25rc2)

[3.0.24-12.fc7]
- fixes in smb.conf
- advice in smb.conf to put scripts in /var/lib/samba/scripts
- create /var/lib/samba/scripts so that selinux can be happy
- fix Vista problems with msdfs errors

[3.0.24-11.fc7]
- enable PAM and NSS dlopen checks during build
- fix unresolved symbols in libnss_wins.so (bug #198230)

[3.0.24-10.fc7]
- set passdb backend = tdbsam as default in smb.conf
- remove samba-docs dependency from swat, that was a mistake
- put back COPYING and other files in samba-common
- put examples in samba not in samba-docs
- leave only stuff under docs/ in samba-doc

[3.0.24-9.fc7]
- integrate most of merge review proposed changes (bug #226387)
- remove libsmbclient-devel-static and simply stop shipping the
static version of smbclient as it seem this is deprecated and
actively discouraged

[3.0.24-8.fc7]
- fix for bug #176649

* Mon Mar 26 2007 Simo Sorce
- remove patch for bug 106483 as it introduces a new bug that prevents
the use of a credentials file with the smbclient tar command
- move the samba private dir from being the same as the config dir
(/etc/samba) to /var/lib/samba/private

[3.0.24-7.fc7]
- make winbindd start earlier in the init process, at the same time
ypbind is usually started as well
- add a sepoarate init script for nmbd called nmb, we need to be able
to restart nmbd without dropping al smbd connections unnecessarily

* Fri Mar 23 2007 Simo Sorce
- add samba.schema to /etc/openldap/schema

* Thu Mar 22 2007 Florian La Roche
- adjust the Requires: for the scripts, add 'chkconfig --add smb'

[3.0.24-6.fc7]
- do not put comments inline on smb.conf options, they may be read
as part of the value (for example log files names)

[3.0.24-5.fc7]
- actually use the correct samba.pamd file not the old samba.pamd.stack file
- fix logifles and use upstream convention of log.* instead of our old *.log
Winbindd creates its own log.* files anyway so we will be more consistent
- install our own (enhanced) default smb.conf file
- Fix pam_winbind acct_mgmt PAM result code (prevented local users from
logging in). Fixed by Guenther.
- move some files from samba to samba-common as they are used with winbindd
as well

[3.0.24-4.fc7]
- fix arch macro which reported Vista to Samba clients.

[3.0.24-3.fc7]
- Directories reorg, tdb files must go to /var/lib, not
to /var/cache, add migration script in %post common
- Split out libsmbclient, devel and doc packages
- Remove libmsrpc.[h|so] for now as they are not really usable
- Remove kill -HUP from rotate, samba use -HUP for other things
noit to reopen logs

[3.0.24-2.fc7]
- New upstream release
- Fix packaging issue wrt idmap modules used only by smbd
- Addedd Vista Patchset for compatibility with Windows Vista
- Change default of 'msdfs root', it seem to cause problems with
some applications and it has been proposed to change it for
3.0.25 upstream

[3.0.23c-2]
- New upstream release.

[3.0.23b-2]
- New upstream release.

[3.0.23a-3]
- Fix the -logfiles patch to close
bz#199607 Samba compiled with wrong log path.
bz#199206 smb.conf has incorrect log file path

[3.0.23a-2]
- Upgrade to new upstream 3.0.23a
- include upstream samr_alias patch

[3.0.23-2]
- New upstream release.
- Use modified filter-requires-samba.sh from packaging/RHEL/setup/
to get rid of bogus dependency on perl(Unicode::MapUTF8)
- Update the -logfiles and -smb.conf patches to work with 3.0.23

[3.0.23-0.RC3]
- New upstream RC release.
- Update the -logfiles, and -passwd patches for
3.0.23rc3
- Include the change to smb.init from Bastien Nocera )
to close
bz#182560 Wrong retval for initscript when smbd is dead
- Update this spec file to build with 3.0.23rc3
- Remove the -install.mount.smbfs patch, since we don't install
mount.smbfs any more.

[2.0.21c-3]
- rebuilt with new gnutls

[2.0.21c-2]
- New upstream version.

[3.0.21b-2]
- New upstream version.
- Since the rawhide kernel has dropped support for smbfs, remove smbmount
and smbumount. Users should use mount.cifs instead.
- Upgrade to 3.0.21b

[0:3.0.20b-2.1.1]
- bump again for double-long bug on ppc(64)

* Fri Dec 09 2005 Jesse Keating
- rebuilt

[3.0.20b-2]
- turn on -DLDAP_DEPRECATED to allow access to ldap functions that have
been depricated in 2.3.11, but which don't have well-documented
replacements (ldap_simple_bind_s(), for example).
- Upgrade to 3.0.20b, which includes all the previous upstream patches.
- Updated the -warnings patch for 3.0.20a.
- Include --with-shared-modules=idmap_ad,idmap_rid to close
bz#156810 --with-shared-modules=idmap_ad,idmap_rid
- Include the new samba.pamd from Tomas Mraz (tmraz@redhat.com) to close
bz#170259 pam_stack is deprecated

[3.0.20-3]
- epochs from deps, req exact release
- rebuild against new openssl

[3.0.20-2]
- New upstream release
Includes five upstream patches -bug3010_v1, -groupname_enumeration_v3,
-regcreatekey_winxp_v1, -usrmgr_groups_v1, and -winbindd_v1
This obsoletes the -pie and -delim patches
the -warning and -gcc4 patches are obsolete too
The -man, -passwd, and -smbspool patches were updated to match 3.0.20pre1
Also, the -quoting patch was implemented differently upstream
There is now a umount.cifs executable and manpage
We run autogen.sh as part of the build phase
The testprns command is now gone
libsmbclient now has a man page
- Include -bug106483 patch to close
bz#106483 smbclient: -N negates the provided password, despite documentation
- Added the -warnings patch to quiet some compiler warnings.
- Removed many obsolete patches from CVS.

[3.0.14a-2]
- New upstream release.
- the -64bit-timestamps, -clitar, -establish_trust, user_rights_v1,
winbind_find_dc_v2 patches are now obsolete.

[3.0.13-2]
- New upstream release
- add my -quoting patch, to fix swat with strings that contain
html meta-characters, and to use correct quote characters in
lists, closing bz#134310
- include the upstream winbindd_2k3sp1 patch
- include the -smbclient patch.
- include the -hang patch from upstream.

* Thu Mar 24 2005 Florian La Roche
- add a 'exit 0' to the postun of the main samba package

[3.0.11-5]
- rebuild with openssl-0.9.7e

[3.0.11-4]
- Use the updated filter-requires-samba.sh file, so we don't accidentally
pick up a dependency on perl(Crypt::SmbHash)

[3.0.11-3]
- add -gcc4 patch to compile with gcc 4.
- remove the now obsolete -smbclient-kerberos.patch
- Include four upstream patches from
http://samba.org/~jerry/patches/post-3.0.11/
(Slightly modified the winbind_find_dc_v2 patch to apply easily with
rpmbuild).

[3.0.11-2]
- include -smbspool patch to close bz#104136

[3.0.10-4]
- Update the -man patch to fix ntlm_auth.1 too.
- Move pam_smbpass.so to the -common package, so both the 32
and 64-bit versions will be installed on multiarch platforms.
This closes bz#143617
- Added new -delim patch to fix mount.cifs so it can accept
passwords with commas in them (via environment or credentials
file) to close bz#144198

[3.0.10-3]
- Rebuilt for new readline.

[3.0.10-2]
- New upstream release that closes CAN-2004-1154 bz#142544
- Include the -64bit patch from Nalin. This closes bz#142873
- Update the -logfiles patch to work with 3.0.10
- Create /var/run/winbindd and make it part of the -common rpm to close
bz#142242

[3.0.9-2]
- New upstream release. This obsoletes the -secret patch.
Include my changetrustpw patch to make 'net ads changetrustpw' stop
aborting. This closes #134694
- Remove obsolete triggers for ancient samba versions.
- Move /var/log/samba to the -common rpm. This closes #76628
- Remove the hack needed to get around the bad docs files in the
3.0.8 tarball.
- Change the comment in winbind.init to point at the correct pidfile.
This closes #76641

[3.0.8-4]
- fix unresolved symbols in libsmbclient which caused applications
such as KDE's konqueror to fail when accessing smb:// URLs. #139894

[3.0.8-3.1]
- Rescue the install.mount.smbfs patch from Juanjo Villaplana
(villapla@si.uji.es) to prevent building the srpm from trashing your
installed /usr/bin/smbmount

[3.0.8-3]
- Include the corrected docs tarball, and use it instead of the
obsolete docs from the upstream 3.0.8 tarball.
- Update the logfiles patch to work with the updated docs.

[3.0.8-2]
- New upstream version fixes CAN-2004-0930. This obsoletes the
disable-sendfile, salt, signing-shortkey and fqdn patches.
- Add my ugly non-ascii-domain patch.
- Updated the pie patch for 3.0.8.
- Updated the logfiles patch for 3.0.8.

[3.0.8-0.pre2]
- New upstream version
- Add Nalin's signing-shortkey patch.

[3.0.8-0.pre1.3]
- disable the -salt patch, because it causes undefined references in
libsmbclient that prevent gnome-vfs from building.

[3.0.8-0.pre1.2]
- Re-enable the x_fclose patch that was accidentally disabled
in 3.0.8-0.pre1.1. This closes #135832
- include Nalin's -fqdn and -salt patches.

[3.0.8-0.pre1.1]
- Include disable-sendfile patch to default 'use sendfile' to 'no'.
This closes #132779

* Wed Oct 06 2004 Jay Fenlason
- Include patch from Steven Lawrance (slawrance@yahoo.com) that modifies
smbmnt to work with 32-bit uids.

[3.0.8-0.pre1]
- new upstream release. This obsoletes the ldapsam_compat patches.

[3.0.7-4]
- Update docs section to not carryover the docs/manpages directory
This moved many files from /usr/share/doc/samba-3.0.7/docs/* to
/usr/share/doc/samba-3.0.7/*
- Modify spec file as suggested by Rex Dieter (rdieter@math.unl.edu)
to correctly create libsmbclient.so.0 and to use %_initrddir instead
of rolling our own. This closes #132642
- Add patch to default 'use sendfile' to no, since sendfile appears to
be broken
- Add patch from Volker Lendecke to help make
ldapsam_compat work again.
- Add patch from 'Vince Brimhall' for ldapsam_compat
These two patches close bugzilla #132169

[3.0.7-3]
- Upgrade to 3.0.7, which fixes CAN-2004-0807 CAN-2004-0808
This obsoletes the 3.0.6-schema patch.
- Update BuildRequires line to include openldap-devel openssl-devel
and cups-devel

[3.0.6-3]
- New upstream version.
- Include post 3.0.6 patch from 'Gerald (Jerry) Carter'
to fix a duplicate in the LDAP schema.
- Include 64-bit timestamp patch from Ravikumar (rkumar@hp.com)
to allow correct timestamp handling on 64-bit platforms and fix #126109.
- reenable the -pie patch. Samba is too widely used, and too vulnerable
to potential security holes to disable an important security feature
like -pie. The correct fix is to have the toolchain not create broken
executables when programs compiled -pie are stripped.
- Remove obsolete patches.
- Modify this spec file to put libsmbclient.{a,so} in the right place on
x86_64 machines.

[3.0.5-3]
- Removed '-pie' patch - 3.0.5 uses -fPIC/-PIC, and the combination
- resulted in executables getting corrupt stacks, causing smbmnt to
- get a SIGBUS in the mount() call (bug 127420).

[3.0.5-2]
- Upgrade to 3.0.5, which is a regression from 3.0.5pre1 for a
security fix.
- Include the 3.0.4-backport patch from the 3E branch. This restores
some of the 3.0.5pre1 and 3.0.5rc1 functionality.

[3.0.5-0.pre1.1]
- Backport base64_decode patche to close CAN-2004-0500
- Backport hash patch to close CAN-2004-0686
- use_authtok patch from Nalin Dahyabhai
- smbclient-kerberos patch from Alexander Larsson
- passwd patch uses '*' instead of 'x' for 'hashed' passwords for
accounts created by winbind. 'x' means 'password is in /etc/shadow' to
brain-damaged pam_unix module.

[3.0.5.0pre1.0]
- New upstream version
- use % { SOURCE1 } instead of a hardcoded path
- include -winbind patch from Gerald (Jerry) Carter (jerry@samba.org)
https://bugzilla.samba.org/show_bug.cgi?id=1315
to make winbindd work against Windows versions that do not have
128 bit encryption enabled.
- Moved %{_bindir}/net to the -common package, so that folks who just
want to use winbind, etc don't have to install -client in order to
'net join' their domain.
- New upstream version obsoletes the patches added in 3.0.3-5
- Remove smbgetrc.5 man page, since we don't ship smbget.

* Tue Jun 15 2004 Elliot Lee
- rebuilt

[3.0.3-5]
- Patch to allow password changes from machines patched with
Microsoft hotfix MS04-011.
- Include patches for https://bugzilla.samba.org/show_bug.cgi?id=1302
and https://bugzilla.samba.org/show_bug.cgi?id=1309

[3.0.3-4]
- Samba 3.0.3 released.

[3.0.3-3.rc1]
- New upstream version
- updated spec file to make libsmbclient.so executable. This closes
bugzilla #121356

[3.0.3-2.pre2]
- New upstream version
- Updated configure line to remove --with-fhs and to explicitly set all
the directories that --with-fhs was setting. We were overriding most of
them anyway. This closes #118598

[3.0.3-1.pre1]
- New upstream version.
- Updated -pie and -logfiles patches for 3.0.3pre1
- add krb5-devel to buildrequires, fixes #116560
- Add patch from Miloslav Trmac (mitr@volny.cz) to allow non-root to run
'service smb status'. This fixes #116559

* Tue Mar 02 2004 Elliot Lee
- rebuilt

[3.0.2a-1]
- Upgrade to 3.0.2a

[3.0.2-7]
- fix ownership in -common package

* Fri Feb 13 2004 Elliot Lee
- rebuilt

* Fri Feb 13 2004 Jay Fenlason
- Change all requires lines to list an explicit epoch. Closes #102715
- Add an explicit Epoch so that %{epoch} is defined.

[3.0.2-5]
- New upstream version: 3.0.2 final includes security fix for #114995
(CAN-2004-0082)
- Edit postun script for the -common package to restart winbind when
appropriate. Fixes bugzilla #114051.

[3.0.2-3rc2]
- add %dir entries for %{_libdir}/samba and %{_libdir}/samba/charset
- Upgrade to new upstream version
- build mount.cifs for the new cifs filesystem in the 2.6 kernel.

[3.0.2-1rc1]
- Upgrade to new upstream version

[3.0.1-1]
- Update to 3.0.1
- Removed testparm patch as it's already merged
- Removed Samba.7* man pages
- Fixed .buildroot patch
- Fixed .pie patch
- Added new /usr/bin/tdbdump file

[3.0.0-15]
- New 3.0.0 final release
- merge nmbd-netbiosname and testparm patches from 3E branch
- updated the -logfiles patch to work against 3.0.0
- updated the pie patch
- update the VERSION file during build
- use make -j if avaliable
- merge the winbindd_privileged change from 3E
- merge the 'rm /usr/lib' patch that allows Samba to build on 64-bit
platforms despite the broken Makefile

* Mon Aug 18 2003 Jay Fenlason
- Merge from samba-3E-branch after samba-3.0.0rc1 was released

[3.0.0-3beta3]
- Merge from 3.0.0-2beta3.3E
- (Correct log file names (#100981).)
- (Fix pidfile directory in samab.log)
- (Remove obsolete samba-3.0.0beta2.tar.bz2.md5 file)
- (Move libsmbclient to the -common package (#99449))

[2.2.8a-4]
- rebuild

* Wed Jun 04 2003 Elliot Lee
- rebuilt

[2.2.8a-2]
- add libsmbclient.so for gnome-vfs-extras
- Edit specfile to specify /var/run for pid files
- Move /tmp/.winbindd/socket to /var/run/winbindd/socket

* Wed May 14 2003 Florian La Roche
- add proper ldconfig calls

[2.2.8a-1]
- upgrade to 2.2.8a
- remove old .md5 files
- add 'pid directory = /var/run' to the smb.conf file. Fixes #88495
- Patch from jra@dp.samba.org to fix a delete-on-close regression

[2.2.8-0]
- Upgrade to 2.2.8
- removed commented out patches.
- removed old patches and .md5 files from the repository.
- remove duplicate /sbin/chkconfig --del winbind which causes
warnings when removing samba.
- Fixed minor bug in smbprint that causes it to fail when called with
more than 10 parameters: the accounting file (and spool directory
derived from it) were being set wrong due to missing {}. This closes
bug #86473.
- updated smb.conf patch, includes new defaults to close bug #84822.

* Mon Feb 24 2003 Elliot Lee
- rebuilt

[2.2.7a-5]
- remove swat.desktop file

[2.2.7a-4]
- relink libnss_wins.so with SHLD='%{__cc} -lnsl' to force libnss_wins.so to
link with libnsl, avoiding unresolved symbol errors on functions in libnsl

[2.2.7a-3]
- edited spec file to put .so files in the correct directories
on 64-bit platforms that have 32-bit compatability issues
(sparc64, x86_64, etc). This fixes bugzilla #83782.
- Added samba-2.2.7a-error.patch from twaugh. This fixes
bugzilla #82454.

* Wed Jan 22 2003 Tim Powers
- rebuilt

[2.2.7a-1]
- Update to 2.2.7a
- Change default printing system to CUPS
- Turn on pam_smbpass
- Turn on msdfs

[2.2.7-5]
- use internal dep generator.

[2.2.7-4]
- don't use rpms internal dep generator

[2.2.7-3]
- Fix missing doc files.
- Fix multilib issues

[2.2.7-2]
- update to 2.2.7
- add patch for LFS in smbclient ()

[2.2.5-10]
- logrotate fixes (#65007)

[2.2.5-9]
- /usr/lib was used in place of %{_libdir} in three locations (#72554)

[2.2.5-8]
- Initscript fix (#70720)

[2.2.5-7]
- Enable VFS support and compile the 'recycling' module (#69796)
- more selective includes of the examples dir

[2.2.5-6]
- Fix the lpq parser for better handling of LPRng systems (#69352)

[2.2.5-5]
- desktop file fixes (#69505)

[2.2.5-4]
- Enable ACLs

[2.2.5-3]
- Make it not depend on Net::LDAP - those are doc files and examples

* Fri Jun 21 2002 Tim Powers
- automated rebuild

[2.2.5-1]
- 2.2.5

[2.2.4-5]
- Move the post/preun of winbind into the -common subpackage,
where the script is (#66128)

[2.2.4-4]
- Fix pidfile locations so it runs properly again (2.2.4
added a new directtive - #65007)

* Thu May 23 2002 Tim Powers
- automated rebuild

[2.2.4-2]
- Fix #64804

[2.2.4-1]
- 2.2.4
- Removed some zero-length and CVS internal files
- Make it build

[2.2.3a-6]
- Don't use /etc/samba.d in smbadduser, it should be /etc/samba

[2.2.3a-5]
- Add libsmbclient.a w/headerfile for KDE (#62202)

[2.2.3a-4]
- Make the logrotate script look the correct place for the pid files

[2.2.3a-3]
- include interfaces.o in pam_smbpass.so, which needs symbols from interfaces.o
(patch posted to samba-list by Ilia Chipitsine)

[2.2.3a-2]
- Rebuild

[2.2.3a-1]
- 2.2.3a

[2.2.3-1]
- 2.2.3

[2.2.2-8]
- New pam configuration file for samba

[2.2.2-7]
- Enable PAM session controll and password sync

[2.2.2-6]
- Move winbind files to samba-common. Add separate initscript for
winbind
- Fixes for winbind - protect global variables with mutex, use
more secure getenv

[2.2.2-5]
- Teach smbadduser about 'getent passwd'
- Fix more pid-file references
- Add (conditional) winbindd startup to the initscript, configured in
/etc/sysconfig/samba

[2.2.2-4]
- Fix pid-file reference in logrotate script
- include pam and nss modules for winbind

[2.2.2-3]
- Add '--with-utmp' to configure options (#55372)
- Include winbind, pam_smbpass.so, rpcclient and smbcacls
- start using /var/cache/samba, we need to keep state and there is
more than just locks involved

[2.2.2-2]
- add 'reload' to the usage string in the startup script

[2.2.2-1]
- 2.2.2

[2.2.1a-5]
- Add patch from Jeremy Allison to fix IA64 alignment problems (#51497)

* Mon Aug 13 2001 Trond Eivind Glomsrod
- Don't include smbpasswd in samba, it's in samba-common (#51598)
- Add a disabled 'obey pam restrictions' statement - it's not
active, as we use encrypted passwords, but if the admin turns
encrypted passwords off the choice is available. (#31351)

* Wed Aug 08 2001 Trond Eivind Glomsrod
- Use /var/cache/samba instead of /var/lock/samba
- Remove 'domain controller' keyword from smb.conf, it's
deprecated (from #13704)
- Sync some examples with smb.conf.default
- Fix password synchronization (#16987)

* Fri Jul 20 2001 Trond Eivind Glomsrod
- Tweaks of BuildRequires (#49581)

* Wed Jul 11 2001 Trond Eivind Glomsrod
- 2.2.1a bugfix release

* Tue Jul 10 2001 Trond Eivind Glomsrod
- 2.2.1, which should work better for XP

* Sat Jun 23 2001 Trond Eivind Glomsrod
- 2.2.0a security fix
- Mark lograte and pam configuration files as noreplace

* Fri Jun 22 2001 Trond Eivind Glomsrod
- Add the /etc/samba directory to samba-common

* Thu Jun 21 2001 Trond Eivind Glomsrod
- Add improvements to the smb.conf as suggested in #16931

* Tue Jun 19 2001 Trond Eivind Glomsrod
- (these changes are from the non-head version)
- Don't include /usr/sbin/samba, it's the same as the initscript
- unset TMPDIR, as samba can't write into a TMPDIR owned
by root (#41193)
- Add pidfile: lines for smbd and nmbd and a config: line
in the initscript (#15343)
- don't use make -j
- explicitly include /usr/share/samba, not just the files in it

* Tue Jun 19 2001 Bill Nottingham
- mount.smb/mount.smbfs go in /sbin, *not* %{_sbindir}

* Fri Jun 08 2001 Preston Brown
- enable encypted passwords by default

* Thu Jun 07 2001 Helge Deller
- build as 2.2.0-1 release
- skip the documentation-directories docbook, manpages and yodldocs
- don't include *.sgml documentation in package
- moved codepage-directory to /usr/share/samba/codepages
- make it compile with glibc-2.2.3-10 and kernel-headers-2.4.2-2

* Mon May 21 2001 Helge Deller
- updated to samba 2.2.0
- moved codepages to %{_datadir}/samba/codepages
- use all available CPUs for building rpm packages
- use %{_xxx} defines at most places in spec-file
- 'License:' replaces 'Copyright:'
- dropped excludearch sparc
- de-activated japanese patches 100 and 200 for now
(they need to be fixed and tested wth 2.2.0)
- separated swat.desktop file from spec-file and added
german translations
- moved /etc/sysconfig/samba to a separate source-file
- use htmlview instead of direct call to netscape in
swat.desktop-file

* Mon May 07 2001 Bill Nottingham
- device-remove security fix again ()

* Fri Apr 20 2001 Bill Nottingham
- fix tempfile security problems, officially ()
- update to 2.0.8

* Sun Apr 08 2001 Bill Nottingham
- turn of SSL, kerberos

* Thu Apr 05 2001 Bill Nottingham
- fix tempfile security problems (patch from )

* Thu Mar 29 2001 Bill Nottingham
- fix quota support, and quotas with the 2.4 kernel (#31362, #33915)

* Mon Mar 26 2001 Nalin Dahyabhai
- tweak the PAM code some more to try to do a setcred() after initgroups()
- pull in all of the optflags on i386 and sparc
- don't explicitly enable Kerberos support -- it's only used for password
checking, and if PAM is enabled it's a no-op anyway

* Mon Mar 05 2001 Tim Waugh
- exit successfully from preun script (bug #30644).

* Fri Mar 02 2001 Nalin Dahyabhai
- rebuild in new environment

* Wed Feb 14 2001 Bill Nottingham
- updated japanese stuff (#27683)

* Fri Feb 09 2001 Bill Nottingham
- fix trigger (#26859)

* Wed Feb 07 2001 Bill Nottingham
- add i18n support, japanese patch (#26253)

* Wed Feb 07 2001 Trond Eivind Glomsrod
- i18n improvements in initscript (#26537)

* Wed Jan 31 2001 Bill Nottingham
- put smbpasswd in samba-common (#25429)

* Wed Jan 24 2001 Bill Nottingham
- new i18n stuff

* Sun Jan 21 2001 Bill Nottingham
- rebuild

* Thu Jan 18 2001 Bill Nottingham
- i18n-ize initscript
- add a sysconfig file for daemon options (#23550)
- clarify smbpasswd man page (#23370)
- build with LFS support (#22388)
- avoid extraneous pam error messages (#10666)
- add Urban Widmark's bug fixes for smbmount (#19623)
- fix setgid directory modes (#11911)
- split swat into subpackage (#19706)

* Wed Oct 25 2000 Nalin Dahyabhai
- set a default CA certificate path in smb.conf (#19010)
- require openssl >= 0.9.5a-20 to make sure we have a ca-bundle.crt file

* Mon Oct 16 2000 Bill Nottingham
- fix swat only_from line (#18726, others)
- fix attempt to write outside buildroot on install (#17943)

* Mon Aug 14 2000 Bill Nottingham
- add smbspool back in (#15827)
- fix absolute symlinks (#16125)

* Sun Aug 06 2000 Philipp Knirsch
- bugfix for smbadduser script (#15148)

* Mon Jul 31 2000 Matt Wilson
- patch configure.ing (patch11) to disable cups test
- turn off swat by default

* Fri Jul 28 2000 Bill Nottingham
- fix condrestart stuff

* Fri Jul 21 2000 Bill Nottingham
- add copytruncate to logrotate file (#14360)
- fix init script (#13708)

* Sat Jul 15 2000 Bill Nottingham
- move initscript back
- remove 'Using Samba' book from %doc
- move stuff to /etc/samba (#13708)
- default configuration tweaks (#13704)
- some logrotate tweaks

* Wed Jul 12 2000 Prospector
- automatic rebuild

* Tue Jul 11 2000 Bill Nottingham
- fix logrotate script (#13698)

* Thu Jul 06 2000 Bill Nottingham
- fix initscripts req (prereq /etc/init.d)

* Wed Jul 05 2000 Than Ngo
- add initdir macro to handle the initscript directory
- add a new macro to handle /etc/pam.d/system-auth

* Thu Jun 29 2000 Nalin Dahyabhai
- enable Kerberos 5 and SSL support
- patch for duplicate profile.h headers

* Thu Jun 29 2000 Bill Nottingham
- fix init script

* Tue Jun 27 2000 Bill Nottingham
- rename samba logs (#11606)

* Mon Jun 26 2000 Bill Nottingham
- initscript munging

* Fri Jun 16 2000 Bill Nottingham
- configure the swat stuff usefully
- re-integrate some specfile tweaks that got lost somewhere

* Thu Jun 15 2000 Bill Nottingham
- rebuild to get rid of cups dependency

* Wed Jun 14 2000 Nalin Dahyabhai
- tweak logrotate configurations to use the PID file in /var/lock/samba

* Sun Jun 11 2000 Bill Nottingham
- rebuild in new environment

* Thu Jun 01 2000 Nalin Dahyabhai
- change PAM setup to use system-auth

* Mon May 08 2000 Bill Nottingham
- fixes for ia64

* Sat May 06 2000 Bill Nottingham
- switch to %configure

* Wed Apr 26 2000 Nils Philippsen
- version 2.0.7

* Sun Mar 26 2000 Florian La Roche
- simplify preun

* Thu Mar 16 2000 Bill Nottingham
- fix yp_get_default_domain in autoconf
- only link against readline for smbclient
- fix log rotation (#9909)

* Fri Feb 25 2000 Bill Nottingham
- fix trigger, again.

* Mon Feb 07 2000 Bill Nottingham
- fix trigger.

* Fri Feb 04 2000 Bill Nottingham
- turn on quota support

* Mon Jan 31 2000 Cristian Gafton
- rebuild to fox dependencies
- man pages are compressed

* Fri Jan 21 2000 Bill Nottingham
- munge post scripts slightly

* Wed Jan 19 2000 Bill Nottingham
- turn on mmap again. Wheee.
- ship smbmount on alpha

* Mon Dec 06 1999 Bill Nottingham
- turn off mmap. ;)

* Wed Dec 01 1999 Bill Nottingham
- change /var/log/samba to 0700
- turn on mmap support

* Thu Nov 11 1999 Bill Nottingham
- update to 2.0.6

* Fri Oct 29 1999 Bill Nottingham
- add a %defattr for -common

* Tue Oct 05 1999 Bill Nottingham
- shift some files into -client
- remove /home/samba from package.

* Tue Sep 28 1999 Bill Nottingham
- initscript oopsie. killproc -HUP, not other way around.

* Sun Sep 26 1999 Bill Nottingham
- script cleanups. Again.

* Wed Sep 22 1999 Bill Nottingham
- add a patch to fix dropped reconnection attempts

* Mon Sep 06 1999 Jeff Johnson
- use cp rather than mv to preserve /etc/services perms (#4938 et al).
- use mktemp to generate /etc/tmp.XXXXXX file name.
- add prereqs on sed/mktemp/killall (need to move killall to /bin).
- fix trigger syntax (i.e. 'samba < 1.9.18p7' not 'samba < samba-1.9.18p7')

* Mon Aug 30 1999 Bill Nottingham
- sed 's|nawk|gawk|' /usr/bin/convert_smbpasswd

* Sat Aug 21 1999 Bill Nottingham
- fix typo in mount.smb

* Fri Aug 20 1999 Bill Nottingham
- add a %trigger to work around (sort of) broken scripts in
previous releases

* Mon Aug 16 1999 Bill Nottingham
- initscript munging

* Mon Aug 09 1999 Bill Nottingham
- add domain parsing to mount.smb

* Fri Aug 06 1999 Bill Nottingham
- add a -common package, shuffle files around.

* Fri Jul 23 1999 Bill Nottingham
- add a chmod in %postun so /etc/services & inetd.conf don't become unreadable

* Wed Jul 21 1999 Bill Nottingham
- update to 2.0.5
- fix mount.smb - smbmount options changed again.........
- fix postun. oops.
- update some stuff from the samba team's spec file.

* Fri Jun 18 1999 Bill Nottingham
- split off clients into separate package
- don't run samba by default

* Mon Jun 14 1999 Bill Nottingham
- fix one problem with mount.smb script
- fix smbpasswd on sparc with a really ugly kludge

* Thu Jun 10 1999 Dale Lovelace
- fixed logrotate script

* Tue May 25 1999 Bill Nottingham
- turn of 64-bit locking on 32-bit platforms

* Thu May 20 1999 Bill Nottingham
- so many releases, so little time
- explicitly uncomment 'printing = bsd' in sample config

* Tue May 18 1999 Bill Nottingham
- update to 2.0.4a
- fix mount.smb arg ordering

* Fri Apr 16 1999 Bill Nottingham
- go back to stop/start for restart (-HUP didn't work in testing)

* Fri Mar 26 1999 Bill Nottingham
- add a mount.smb to make smb mounting a little easier.
- smb filesystems apparently don't work on alpha. Oops.

* Thu Mar 25 1999 Bill Nottingham
- always create codepages

* Tue Mar 23 1999 Bill Nottingham
- logrotate changes

* Sun Mar 21 1999 Cristian Gafton
- auto rebuild in the new build environment (release 3)

* Fri Mar 19 1999 Preston Brown
- updated init script to use graceful restart (not stop/start)

* Tue Mar 09 1999 Bill Nottingham
- update to 2.0.3

* Thu Feb 18 1999 Bill Nottingham
- update to 2.0.2

* Mon Feb 15 1999 Bill Nottingham
- swat swat

* Tue Feb 09 1999 Bill Nottingham
- fix bash2 breakage in post script

* Fri Feb 05 1999 Bill Nottingham
- update to 2.0.0

* Mon Oct 12 1998 Cristian Gafton
- make sure all binaries are stripped

* Thu Sep 17 1998 Jeff Johnson
- update to 1.9.18p10.
- fix %triggerpostun.

* Tue Jul 07 1998 Erik Troan
- updated postun triggerscript to check db_8.RHSA-2023-7139
- clear /etc/codepages from %preun instead of %postun

* Mon Jun 08 1998 Erik Troan
- made the %postun script a tad less agressive; no reason to remove
the logs or lock file (after all, if the lock file is still there,
samba is still running)
- the %postun and %preun should only exectute if this is the final
removal
- migrated %triggerpostun from Red Hat's samba package to work around
packaging problems in some Red Hat samba releases

* Sun Apr 26 1998 John H Terpstra
- minor tidy up in preparation for release of 1.9.18p5
- added findsmb utility from SGI package

* Wed Mar 18 1998 John H Terpstra
- Updated version and codepage info.
- Release to test name resolve order

* Sat Jan 24 1998 John H Terpstra
- Many optimisations (some suggested by Manoj Kasichainula
- Use of chkconfig in place of individual symlinks to /etc/rc.d/init/smb
- Compounded make line
- Updated smb.init restart mechanism
- Use compound mkdir -p line instead of individual calls to mkdir
- Fixed smb.conf file path for log files
- Fixed smb.conf file path for incoming smb print spool directory
- Added a number of options to smb.conf file
- Added smbadduser command (missed from all previous RPMs) - Doooh!
- Added smbuser file and smb.conf file updates for username map


Related CVEs


CVE-2023-34968
CVE-2023-34967
CVE-2023-34966
CVE-2022-2127

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) evolution-mapi-3.28.3-8.el8.src.rpm78517d788c26e16c25ffc7a7e67a1931-ol8_aarch64_appstream
openchange-2.3-32.0.1.el8.src.rpm683885484157df55b73177e70b9de8f4-ol8_aarch64_appstream
openchange-2.3-32.0.1.el8.src.rpm683885484157df55b73177e70b9de8f4-ol8_aarch64_distro_builder
evolution-mapi-3.28.3-8.el8.aarch64.rpm6a792c353f30a072345dcafd92e92157-ol8_aarch64_appstream
evolution-mapi-langpacks-3.28.3-8.el8.noarch.rpm282140bfcd213942c150aa94c997046a-ol8_aarch64_appstream
openchange-2.3-32.0.1.el8.aarch64.rpm7c5cd0f19a668d151fbf5bf2ce3e2d70-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) evolution-mapi-3.28.3-8.el8.src.rpm78517d788c26e16c25ffc7a7e67a1931-ol8_x86_64_appstream
openchange-2.3-32.0.1.el8.src.rpm683885484157df55b73177e70b9de8f4-ol8_x86_64_appstream
openchange-2.3-32.0.1.el8.src.rpm683885484157df55b73177e70b9de8f4-ol8_x86_64_distro_builder
evolution-mapi-3.28.3-8.el8.x86_64.rpm63eb48b5f01fe4729795e67ab217d84f-ol8_x86_64_appstream
evolution-mapi-langpacks-3.28.3-8.el8.noarch.rpm282140bfcd213942c150aa94c997046a-ol8_x86_64_appstream
openchange-2.3-32.0.1.el8.i686.rpm334f80fc7a121702c66eca33d66f19ae-ol8_x86_64_appstream
openchange-2.3-32.0.1.el8.x86_64.rpmd871b785aea353a011c6e34358fda288-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete