[El-errata] ELSA-2018-1860 Low: Oracle Linux 6 samba security and bug fix update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Jun 26 13:19:43 PDT 2018


Oracle Linux Security Advisory ELSA-2018-1860

http://linux.oracle.com/errata/ELSA-2018-1860.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:

i386:
libsmbclient-3.6.23-51.0.1.el6.i686.rpm
libsmbclient-devel-3.6.23-51.0.1.el6.i686.rpm
samba-3.6.23-51.0.1.el6.i686.rpm
samba-client-3.6.23-51.0.1.el6.i686.rpm
samba-common-3.6.23-51.0.1.el6.i686.rpm
samba-doc-3.6.23-51.0.1.el6.i686.rpm
samba-domainjoin-gui-3.6.23-51.0.1.el6.i686.rpm
samba-swat-3.6.23-51.0.1.el6.i686.rpm
samba-winbind-3.6.23-51.0.1.el6.i686.rpm
samba-winbind-clients-3.6.23-51.0.1.el6.i686.rpm
samba-winbind-devel-3.6.23-51.0.1.el6.i686.rpm
samba-winbind-krb5-locator-3.6.23-51.0.1.el6.i686.rpm

x86_64:
libsmbclient-3.6.23-51.0.1.el6.i686.rpm
libsmbclient-3.6.23-51.0.1.el6.x86_64.rpm
libsmbclient-devel-3.6.23-51.0.1.el6.i686.rpm
libsmbclient-devel-3.6.23-51.0.1.el6.x86_64.rpm
samba-3.6.23-51.0.1.el6.x86_64.rpm
samba-client-3.6.23-51.0.1.el6.x86_64.rpm
samba-common-3.6.23-51.0.1.el6.i686.rpm
samba-common-3.6.23-51.0.1.el6.x86_64.rpm
samba-doc-3.6.23-51.0.1.el6.x86_64.rpm
samba-domainjoin-gui-3.6.23-51.0.1.el6.x86_64.rpm
samba-glusterfs-3.6.23-51.0.1.el6.x86_64.rpm
samba-swat-3.6.23-51.0.1.el6.x86_64.rpm
samba-winbind-3.6.23-51.0.1.el6.x86_64.rpm
samba-winbind-clients-3.6.23-51.0.1.el6.i686.rpm
samba-winbind-clients-3.6.23-51.0.1.el6.x86_64.rpm
samba-winbind-devel-3.6.23-51.0.1.el6.i686.rpm
samba-winbind-devel-3.6.23-51.0.1.el6.x86_64.rpm
samba-winbind-krb5-locator-3.6.23-51.0.1.el6.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/samba-3.6.23-51.0.1.el6.src.rpm



Description of changes:

[3.6.23-51.0.1]
- Remove use-after-free talloc_tos() inlined function problem (John 
Haxby) [orabug 18253258]

[3.6.24-51]
- resolves: #1513877 - Fix memory leak in winbind

[3.6.24-50]
- resolves: #1553018 - Fix CVE-2018-1050

[3.6.24-49]
- resolves: #1536053 - Fix regression with non-wide symlinks to directories

[3.6.24-48]
- resolves: #1519884 - Fix segfault in winbind when querying groups

[3.6.24-47]
- resolves: #1413484 - Fix guest login with signing required

[3.6.24-46]
- resolves: #1509455 - Fix regression of CVE-2017-2619

[3.6.24-45]
- resolves: #1491211 - CVE-2017-2619 CVE-2017-12150 CVE-2017-12163

[3.6.24-44]
- resolves: #1451105 - Fix trusted domain handling in winbind
- resolves: #1431000 - Fix crash while trying to authenticate with a 
disabled
                        account
- resolves: #1467395 - Add 'winbind request timeout' option

[3.6.23-43]
- resolves: #1450783 - Fix CVE-2017-7494

[3.6.23-42]
- resolves: #1391256 - Performance issues with vfs_dirsort and extended
                        attributes

[3.6.23-41]
- resolves: #1413672 - Auth regression after secret changed

[3.6.23-40]
- resolves: #1405356 - CVE-2016-2125 CVE-2016-2126

[3.6.23-39]
- resolves: #1297805 - Fix issues with printer unpublishing from AD

[3.6.23-38]
- resolves: #1347843 - Fix RPC queryUserList returning NO_MEMORY for
                        empty list

[3.6.23-37]
- resolves: #1380151 - Fix memory leak in idmap_ad module
- resolves: #1333561 - Fix smbclient connection issues to DFS shares
- resolves: #1372611 - Allow ntlmsssp session key setup without signing
                        (Workaround for broken NetApp and EMC NAS)

[3.6.23-35]
- resolves: #1282289 - Fix winbind memory leak with each cached creds login

[3.6.23-34]
- resolves: #1327697 - Fix netlogon credential checks
- resolves: #1327746 - Fix dcerpc trailer verificaton

[3.6.23-33]
- related: #1322687 - Update CVE patchset

[3.6.23-32]
- related: #1322687 - Update manpages

[3.6.23-31]
- related: #1322687 - Update CVE patchset

[3.6.23-30]
- related: #1322687 - Update CVE patchset

[3.6.23-29]
- resolves: #1322687 - Fix CVE-2015-5370
- resolves: #1322687 - Fix CVE-2016-2110
- resolves: #1322687 - Fix CVE-2016-2111
- resolves: #1322687 - Fix CVE-2016-2112
- resolves: #1322687 - Fix CVE-2016-2115
- resolves: #1322687 - Fix CVE-2016-2118 (Known as Badlock)

[3.6.23-28]
- resolves: #1305870 - Fix symlink verification

[3.6.23-27]
- resolves: #1314671 - Fix CVE-2015-7560

[3.6.23-26]
- resolves: #1211744 - Fix DFS client access with Windows Server 2008

[3.6.23-25]
- resolves: #1242614 - Fix unmappable S-1-18-1 sid truncates group lookups

[3.6.23-24]
- resolves: #1271763 - Fix segfault in NTLMv2_generate_names_blob()
- resolves: #1261265 - Add '--no-dns-updates' option for 'net ads join'

[3.6.23-23]
- resolves: #1290707 - CVE-2015-5299
- related: #1290707 - CVE-2015-5296
- related: #1290707 - CVE-2015-5252
- related: #1290707 - CVE-2015-5330

[3.6.23-22]
- resolves: #1232021 - Do not overwrite smb.conf manpage
- resolves: #1216060 - Document netbios name length limitations
- resolves: #1234249 - Fix 'map to guest = Bad Uid' option
- resolves: #1219570 - Fix 'secuirtiy = server' (obsolete) share access
- resolves: #1211657 - Fix stale cache entries if a printer gets renamed

[3.6.23-21]
- resolves: #1252180 - Fix 'force group' with 'winbind use default domain'.
- resolves: #1250100 - Fix segfault in pam_winbind if option parsing fails
- resolves: #1222985 - Fix segfault with 'mangling method = hash' option

[3.6.23-20]
- resolves: #1164269 - Fix rpcclient timeout command.

[3.6.23-19]
- resolves: #1201611 - Fix 'force user' with 'winbind use default domain'.

[3.6.23-18]
- resolves: #1194549 - Fix winbind caching issue and support SID 
compression.

[3.6.23-17]
- resolves: #1192211 - Fix restoring shadow copy snapshot with SMB2.

[3.6.23-16]
- resolves: #1117059 - Fix nss group enumeration with unresolved groups.

[3.6.23-15]
- resolves: #1165750 - Fix guid retrieval for published printers.
- resolves: #1163383 - Fix 'net ads join -k' with existing keytab entries.
- resolves: #1195456 - Fix starting daemons on read only filesystems.
- resolves: #1138552 - Fix CPU utilization when re-reading the printcap 
info.
- resolves: #1144916 - Fix smbclient NTLMv2 authentication.
- resolves: #1164336 - Document 'sharesec' command for
                        'access based share enum' option.

[3.6.23-14]
- related: #1191339 - Update patchset for CVE-2015-0240.

[3.6.23-13]
- resolves: #1191339 - CVE-2015-0240: RCE in netlogon.

[3.6.23-12]
- resolves: #1127723 - Fix samlogon secure channel recovery.

[3.6.23-11]
- resolves: #1129006 - Add config variables to set spoolss os version.

[3.6.23-10]
- resolves: #1124835 - Fix dropbox share.

[3.6.23-9]
- related: #1053886 - Fix receiving the gecos field with winbind.

[3.6.23-8]
- resolves: #1110733 - Fix write operations as guest with 'security = 
share'.
- resolves: #1053886 - Fix receiving the gecos field with winbind.

[3.6.23-7]
- resolves: #1107777 - Fix SMB2 with "case sensitive = True"

[3.6.23-6]
- resolves: #1105500 - CVE-2014-0244: DoS in nmbd.
- resolves: #1108841 - CVE-2014-3493: DoS in smbd with unicode path names.

[3.6.23-5]
- related: #1061301 - Only link glusterfs libraries to vfs module.

[3.6.23-4]
- resolves: #1051656 - Fix gecos field copy debug warning.
- resolves: #1061301 - Add glusterfs vfs module.
- resolves: #1087472 - Fix libsmbclient crash when HOME variable isn't set.
- resolves: #1099443 - 'net ads testjoin' fails with IPv6.
- resolves: #1100670 - Fix 'force user' with 'security = ads'.
- resolves: #1096522 - Fix enabling SMB2 causes file operations to fail.

[3.6.23-3]
- resolves: #1081539 - Add timeout option to smbclient.

[3.6.23-2]
- resolves: #1022534 - Do not build Samba with fam support.
- resolves: #1059301 - Fix nbt query with many components.
- resolves: #1057332 - Fix force user with guest account.
- resolves: #1021706 - Fix %G substitution in 'template homedir'.
- resolves: #1040472 - Fix group expansion in service path.
- resolves: #1069570 - Fix memory leak reading printer list.
- resolves: #1067607 - Fix wbinfo -i with one-way trusts.
- resolves: #1050887 - Fix 100% CPU utilization in winbindd when trying to
                        free memory in winbindd_reinit_after_fork.
- resolves: #1029000 - Fix 'force user' with 'security = ads'.

[3.6.23-1]
- resolves: #1073356 - Fix CVE-2013-4496, CVE-2012-6150 and CVE-2013-6442.
- resolves: #1018038 - Fix CVE-2013-4408.

[3.6.22-1]
- resolves: #1003921 - Rebase Samba to 3.6.22.
- resolves: #1035332 - Fix force user with 'security = user'.

[3.6.9-165]
- resolves: #1028086 - Fix CVE-2013-4475.

[3.6.9-164]
- resolves: #1008574 - Fix offline logon cache not updating for cross child
                        domain group membership.

[3.6.9-163]
- resolves: #1015359 - Fix CVE-2013-0213 and CVE-2013-0214 in SWAT.

[3.6.9-162]
- resolves: #978007 - Fix "valid users" manpage documentation.

[3.6.9-161]
- resolves: #997338 - Fix smbstatus as non root user.
- resolves: #1003689 - Fix Windows 8 printer driver support.

[3.6.9-160]
- resolves: #948071 - Group membership is not correct on logins with new
                       AD groups.
- resolves: #953985 - User and group info not return from a Trusted Domain.

[3.6.9-159]
- resolves: #995109 - net ads join - segmentation fault if no realm has been
                       specified.
- List all vfs, auth and charset modules in the spec file.

[3.6.9-158]
- resolves: #984808 - CVE-2013-4124: DoS via integer overflow when reading
                       an EA list

[3.6.9-157]
- Fix Windows 8 Roaming Profiles.
- resolves: #990685

[3.6.9-156]
- Fix PIDL parsing with newer versions of gcc.
- Fix dereferencing a unique pointer in the WKSSVC server.
- resolves: #980382

[3.6.9-155]
- Check for system libtevent and require version 0.9.18.
- Use tevent epoll backend in winbind.
- resolves: #951175

[3.6.9-154]
- Add encoding option to 'net printing (migrate|dump)' command.
- resolves: #915455

[3.6.9-153]
- Fix overwrite of errno in check_parent_exists().
- resolves: #966489
- Fix dir code using dirfd() without vectoring trough VFS calls.
- resolves: #971283

[3.6.9-152]
- Fix 'map untrusted to domain' with NTLMv2.
- resolves: #961932
- Fix the username map optimization.
- resolves: #952268
- Fix 'net ads keytab add' not respecting the case.
- resolves: #955683
- Fix write operations as guest with security = share
- resolves: #953025
- Fix pam_winbind upn to username conversion if you have different 
seperator.
- resolves: #949613
- Change chkconfig order to start winbind before netfs.
- resolves: #948623
- Fix cache issue when resoliving groups without domain name.
- resolves: #927383

[3.6.9-151]
- Fix typo in winbind-krb-locator post uninstall script.
- related: #864950

[3.6.9-150]
- Fix typo in winbind-krb-locator post uninstall script.
- related: #864950

[3.6.9-149]
- Fix leaking sockets of SMB connections to a DC.
- resolves: #852175

[3.6.9-148]
- Fix work around for 'winbind use default domain'.
- resolves: #876262

[3.6.9-147]
- Rebuild with correct libtalloc and libtdb versions.
- related: #879578

[3.6.9-146]
- Fix large read requests cause server to issue malformed reply.
- resolves: #879578

[3.6.9-145]
- Failover if LogonSamLogon fails to connect to Netlogon.
- resolves: #875879

[3.6.9-144]
- Fix AES session key usage
- related: #748407

[3.6.9-143]
- Fix winbind rpm dependency
- related: #649479

[3.6.9-142]
- Rebase to version 3.6.9.
- related: #649479

[3.6.8-141]
- Fix AES kerberos key detection
- related: #748407

[3.6.8-140]
- Fix net ads join improperly using 'realm' to describe 'dns name'.
- resolves: #866570

[3.6.8-139]
- Move pam_winbind.conf to the package of the module.
- resolves: #867315

[3.6.8-138]
- Fix winbind krb5 locator RPM requires
- related: #864950

[3.6.8-137]
- Use alternatives to configure winbind_krb5_locator.so.
- Move wbinfo and ntlm_auth to the correct package so samba4 can
   correctly handle conflicts.
- resolves: #864950

[3.6.8-136]
- Fix loading the imap hash module.
- resolves: #864045
- Fix raw printing support.
- related: #857942

[3.6.8-135]
- ACL masks incorrectly applied when setting ACLs.
- resolves: #863173

[3.6.8-134]
- Use AES Kerberos keys also in smb session setup
- related: #748407

[3.6.8-133]
- Use AES Kerberos keys
- resolves: #748407

[3.6.8-132]
- Fix client timeouts during printer imports.
- resolves: #861935

[3.6.8-131]
- Handle error if invalid ports have been specified gracefully.
- resolves: #845760
- Fix printing regression with builtin forms.
- resolves: #860967

[3.6.8-130]
- Fix pam_winbind return code in error path
- resolves: #760109

[3.6.8-129]
- Fix rap printing spoolss access.
- resolves: #857942

[3.6.8-128]
- Rebase to version 3.6.8.
- related: #649479

[3.6.7-127]
- Rebase to version 3.6.7.
- related: #649479

[3.6.6-126]
- Rebase to version 3.6.6.
- resolves: #649479

[3.5.10-125]
- Security Release, fixes CVE-2012-2111
- resolves: #815689

[3.5.10-124]
- Avoid private krb5_locate_kdc usage
- resolves: #816123

[3.5.10-123]
- Disable PAM_RADIO_TYPE handling in pam_winbind
- resolves: #788089

[3.5.10-122]
- Fix posix acl set handling
- resolves: #808449

[3.5.10-121]
- Security Release, fixes CVE-2012-1182
- resolves: #804646

[3.5.10-120]
- Fix smbd crash with security = server
- resolves: #753143

[3.5.10-119]
- Increase log level for debug message
- resolves: #771812

[3.5.10-118]
- Fix winbind pwent enumeration
- resolves: #767659

[3.5.10-117]
- Add timeout to winbind cache entries
- resolves: #767656

[3.5.10-116]
- Fix potentially wrong DNS SRV queries
- resolves: #753747

[3.5.10-115]
- Fix smbclient return code
- resolves: #755347

[3.5.10-114]
- Fix join using kerberos patch
- related: #737808

[3.5.10-113]
- Fix winbindd manpage (remove -Y option)
- resolves: #748348

[3.5.10-112]
- Fix DFS breaks zip file extracting unless "follow symlinks = no" set
- resolves: #748325

[3.5.10-111]
- Fix AD LDAP schema "primaryGroupID" usage documentation
- resolves: #652609

[3.5.10-110]
- Fix IE9 on Windows 7 download to samba share
- resolves: #743892

[3.5.10-109]
- Handle case when all DNS servers are down in 'net ads dns register'
- related: #691423

[3.5.10-108]
- Fix winbind lookup rid
- resolves: #743211

[3.5.10-107]
- Fix "force create mode" regression
- resolves: #740832

[3.5.10-106]
- Fix krb5 usage in smb client code
- related: #737808

[3.5.10-105]
- Fix support for old samba 3.0 domain controllers
- resolves: #741934

[3.5.10-104]
- Allow to use default krb5 credential cache in 'net' using -k
- resolves: #737808

[3.5.10-103]
- Fix idmap initialization debug message
- resolves: #739186

[3.5.10-102]
- Document -k option in the 'net' manpage
- resolves: #737810

[3.5.10-101]
- Remove patch leftover from rpmlint fix
- related: #730680

[3.5.10-100]
- Fix rpmlint errors
- resolves: #730680

[3.5.10-99]
- Fix wbinfo manpage
- resolves: #719365

[3.5.10-98]
- Fix cleartext authentication after applying Windows security patch 
KB2536276
- resolves: #719355

[3.5.10-97]
- Fix several issues discovered by coverity scan
- resolves: #717294

[3.5.10-96]
- Rebase to security update release 3.5.10
- related: #722561

[3.5.9-95]
- Fix file descriptor leak in pam_winbind.c
- resolves: #725281

[3.5.9-94]
- Security Release, fixes CVE-2011-2694, CVE-2011-2522
- resolves: #722561

[3.5.9-93]
- Update to 3.5.9
- related: #694543

[3.5.8-92]
- Fix server principal name guessing
- resolves: #703412

[3.5.8-91]
- Fix lsa lookupsids calls over ncacn_ip_tcp that caused getent passwd 
queries
   to fail
- resolves: #709641

[3.5.8-90]
- Fix cups location publishing
- resolves: #709617

[3.5.8-89]
- Fix printcap handling and cups spooler interaction
- resolves: #709070
- Fix spoolss form index mixup (wrong papersize)
- resolves: #703393

[3.5.8-88]
- Update to 3.5.8
- resolves: #694543

[3.5.6-87]
- Fix DNS updates when having multiple DNS servers
- resolves: #691423

[3.5.6-86]
- Security Release, fixes CVE-2011-0719
- resolves: #678335

[3.5.6-85]
- Fix krb5 access to some 3rd party cifs servers
- resolves: #667675

[3.5.6-84]
- Add %verify(not md5 size mtime) to smb.conf
- resolves: #628955

[3.5.6-83]
- Update to 3.5.6 bugfix release
- resolves: #660667

[3.5.4-82]
- Add configtest parameter to smb init script
- resolves: #614853

[3.5.4-81]
- Add Posix fallocate performance patch (strict allocate = yes)
- resolves: #659884

[3.5.4-80]
- Fix inconsistent getpwnam name lookup
- resolves: #645173

[3.5.4-79]
- Fix smbd changing mode of files after rename
- resolves: #629374

[3.5.4-78]
- Fix 'default case' manpage documentation
- resolves: #639141

[3.5.4-77]
- Fix nmb init script description
- resolves: #641368

[3.5.4-76]
- Fix SPNEGO parsing for Windows 7
- resolves: #651947

[3.5.4-75]
- Fix charset handling
- resolves: #650244

[3.5.4-74]
- Add "winbind max clients" configure option
- resolves: #650245

[3.5.4-73]
- Fix libsmbclient SMB signing
- resolves: #654426

[3.5.4-72]
- Put winbind krb5 locator plugin into a separate rpm
- resolves: #629396

[3.5.4-71]
- Fix typos in default smb.conf (selinux et al.)
- resolves: #596345, #626473

[3.5.4-70]
- Fix cupsaddsmb upload for Win9x drivers
- resolves: #640888

[3.5.4-69]
- Security Release, fixes CVE-2010-3069
- resolves: #632265

[3.5.4-68]
- Fix winbind offline mode
- resolves: #626407

[3.5.4-67]
- Further fixes for winbind secure channel
- related: #622627

[3.5.4-66]
- Fix winbind secure channel (samlogonex)
- resolves: #622627

[3.5.4-65]
- Update to 3.5.4
- resolves: #608875

[3.5.2-64]
- Silence strict aliasing warning
- resolves: #605309

[3.5.2-63]
- Keep old machine password for kerberos clients
- resolves: #599544

[3.5-2-62]
- Add explicit subpackage dependencies to samba-winbind-clients
- resolves: #594339

[3.5.2-61]
- Fix pidfile fd leak (avoids selinux AVC message)
- resolves: #582250

[3.5.2-60]
- Fix winbind over ipv6
- resolves: #580643

[3.5.2-59]
- Make sure nmb and smb initscripts return LSB compliant return codes
- resolves: #530954

[3.5.2-58]
- Fix smbclient with security=share
- resolves: #590021

[3.5.2-57]
- Update to 3.5.2
- resolves: #583773

[3.5.1-56]
- Update to 3.5.1
- Security update that resolves CVE-2010-0728
- Remove cifs.upcall and mount.cifs entirely
- related: #556558

[3.5.0rc3-55]
- Raise required tdb version to 1.2.1
- Build with recent external libtdb
- related: #556558

[3.5.0rc3-53]
- Update to 3.5.0rc3
- related: #556558

[3.3.4-51]
- Security Release, fixes CVE-2009-3297
- resolves: #559274

[3.4.4-50]
- Update to 3.4.4
- related: #543948

[3.4.2-49]
- Add missing defattrs in specfile
- Fix upstream tarball url in specfile
- Cleanup unapplied patch
- related: #543948

[3.4.2-48]
- add pam_winbind.conf(5) manpage
- resolves: #528919

[3.4.2-47]
- Spec file cleanup
- Fix sources upstream location
- Remove conditionals to build talloc and tdb, now they are completely 
indepent
   packages in Fedora
- Add defattr() where missing
- Turn all tabs into 4 spaces
- Remove unused migration script
- Split winbind-clients out of main winbind package to avoid multilib to 
include
   huge packages for no good reason

[3.4.2-0.46]
- Update to 3.4.2
- Security Release, fixes CVE-2009-2813, CVE-2009-2948 and CVE-2009-2906

[3.4.1-0.45]
- Use password-auth common PAM configuration instead of system-auth

[3.4.1-0.44]
- Update to 3.4.1

[3.4.0-0.43]
- Fix cli_read()
- resolves: #516165

[3.4.0-0.42]
- Fix required talloc version number
- resolves: #516086

[0:3.4.0-0.41.1]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild

[3.4.0-0.41]
- Fix Bug #6551 (vuid and tid not set in sessionsetupX and tconX)
- Specify required talloc and tdb version for BuildRequires

[3.4.0-0.40]
- Update to 3.4.0

[3.4.0rc1-0.39]
- Update to 3.4.0rc1

[3.4.0pre2-0.38]
- Update to 3.4.0pre2

[3.4.0pre1-0.37]
- Update to 3.4.0pre1

[3.3.4-0.36]
- Update to 3.3.4

[3.3.3-0.35]
- Enable build of idmap_tdb2 for clustered setups

[3.3.3-0.34]
- Update to 3.3.3

[3.3.2-0.33]
- Fix nmbd init script nmbd reload was causing smbd not nmbd to reload the
   configuration
- Fix upstream bug 6224, nmbd was waiting 5+ minutes before running 
elections on
   startup, causing your own machine not to show up in the network for 5 
minutes
   if it was the only client in that workgroup (fix committed upstream)

[3.3.2-0.31]
- Update to 3.3.2
- resolves: #489547

[3.3.1-0.30]
- Add libcap-devel to requires list (resolves: #488559)

[3.3.1-0.29]
- Make the talloc and ldb packages optionsl and disable their build within
   the samba3 package, they are now built as part of the samba4 package
   until they will both be released as independent packages.

[3.3.1-0.28]
- Enable cluster support

[3.3.1-0.27]
- Update to 3.3.1

[3.3.0-0.26]
- Rename ldb* tools to ldb3* to avoid conflicts with newer ldb releases

[3.3.0-0.25]
- Update to 3.3.0 final
- Add upstream fix for ldap connections to AD (Bug #6073)
- Remove bogus perl dependencies (resolves: #473051)

[3.3.0-0rc1.24]
- Update to 3.3.0rc1

[3.2.5-0.23]
- Security Release, fixes CVE-2008-4314

[3.2.4-0.22]
- Update to 3.2.4
- resolves: #456889
- move cifs.upcall to /usr/sbin

[3.2.3-0.21]
- Security fix for CVE-2008-3789

[3.2.2-0.20]
- Update to 3.2.2

[3.2.1-0.19]
- Add fix for CUPS problem, fixes bug #453951

[3.2.1-0.18]
- Update to 3.2.1

[3.2.0-2.17]
- Update to 3.2.0 final
- resolves: #452622

[3.2.0-1.rc2.16]
- Update to 3.2.0rc2
- resolves: #449522
- resolves: #448107

[3.2.0-1.rc1.15]
- Fix security=server
- resolves: #449038, #449039

[3.2.0-1.rc1.14]
- Add fix for CVE-2008-1105
- resolves: #446724

[3.2.0-1.rc1.13]
- Update to 3.2.0rc1

[3.2.0-1.pre3.12]
- make it possible to print against Vista and XP SP3 as servers
- resolves: #439154

[3.2.0-1.pre3.11]
- Add "net ads join createcomputer=ou1/ou2/ou3" fix (BZO #5465)

[3.2.0-1.pre3.10]
- Add smbclient fix (BZO #5452)

[3.2.0-1.pre3.9]
- Update to 3.2.0pre3

[3.2.0-1.pre2.8]
- Add fixes for libsmbclient and support for r/o relocations

[3.2.0-1.pre2.7]
- Fix libnetconf, libnetapi and msrpc DSSETUP call

[3.2.0-1.pre2.6]
- Create separate packages for samba-winbind and samba-winbind-devel
- Add cifs.spnego helper

[3.2.0-1.pre2.3]
- Update to 3.2.0pre2
- Add talloc and tdb lib and devel packages
- Add domainjoin-gui package

[3.2.0-0.pre1.3]
- Try to fix GCC 4.3 build
- Add --with-dnsupdate flag and also make sure other flags are required 
just to
   be sure the features are included without relying on autodetection to be
   successful

[0:3.2.0-1.pre1.2]
- Autorebuild for GCC 4.3

[3.2.0-0.pre1.2]
- Rebuild for openldap bump

[3.2.0-0.pre1.1.fc9]
- 32/64bit padding fix (affects multilib installations)

[3.2.0-0.pre1.fc9]
- New major relase, minor switched from 0 to 2
- License change, the code is now GPLv3+
- Numerous improvements and bugfixes included
- package libsmbsharemodes too
- remove smbldap-tools as they are already packaged separately in Fedora
- Fix bug 245506

[3.0.26a-1.fc8]
- rebuild with AD DNS Update support

[3.0.26a-0.fc8]
- upgrade to the latest upstream realease
- includes security fixes released today in 3.0.26

[3.0.25c-4.fc8]
- add fix reported upstream for heavy idmap_ldap memleak

[3.0.25c-3.fc8]
- fix a few places were "open" is used an interfere with the new glibc

[3.0.25c-2.fc8]
- remove old source
- add patch to fix samba bugzilla 4772

[3.0.25c-0.fc8]
- update to 3.0.25c

[3.0.25b-3.fc8]
- handle cases defined in #243766

[3.0.25b-2.fc8]
- update to 3.0.25b
- better error codes for init scripts: #244823

* Tue May 29 2007 Günther Deschner <gdeschner at redhat.com>
- fix pam_smbpass patch.

* Fri May 25 2007 Simo Sorce <ssorce at redhat.com>
- update to 3.0.25a as it contains many fixes
- add a fix for pam_smbpass made by Günther but committed upstream after 
3.0.25a was cut.

* Mon May 14 2007 Simo Sorce <ssorce at redhat.com>
- final 3.0.25
- includes security fixes for CVE-2007-2444,CVE-2007-2446,CVE-2007-2447

* Mon Apr 30 2007 Günther Deschner <gdeschner at redhat.com>
- move to 3.0.25rc3

* Thu Apr 19 2007 Simo Sorce <ssorce at redhat.com>
- fixes in the spec file
- moved to 3.0.25rc1
- addedd patches (merged upstream so they will be removed in 3.0.25rc2)

[3.0.24-12.fc7]
- fixes in smb.conf
- advice in smb.conf to put scripts in /var/lib/samba/scripts
- create /var/lib/samba/scripts so that selinux can be happy
- fix Vista problems with msdfs errors

[3.0.24-11.fc7]
- enable PAM and NSS dlopen checks during build
- fix unresolved symbols in libnss_wins.so (bug #198230)

[3.0.24-10.fc7]
- set passdb backend = tdbsam as default in smb.conf
- remove samba-docs dependency from swat, that was a mistake
- put back COPYING and other files in samba-common
- put examples in samba not in samba-docs
- leave only stuff under docs/ in samba-doc

[3.0.24-9.fc7]
- integrate most of merge review proposed changes (bug #226387)
- remove libsmbclient-devel-static and simply stop shipping the
   static version of smbclient as it seem this is deprecated and
   actively discouraged

[3.0.24-8.fc7]
- fix for bug #176649

* Mon Mar 26 2007 Simo Sorce <ssorce at redhat.com>
- remove patch for bug 106483 as it introduces a new bug that prevents
   the use of a credentials file with the smbclient tar command
- move the samba private dir from being the same as the config dir
   (/etc/samba) to /var/lib/samba/private

[3.0.24-7.fc7]
- make winbindd start earlier in the init process, at the same time
   ypbind is usually started as well
- add a sepoarate init script for nmbd called nmb, we need to be able
   to restart nmbd without dropping al smbd connections unnecessarily

* Fri Mar 23 2007 Simo Sorce <ssorce at redhat.com>
- add samba.schema to /etc/openldap/schema

* Thu Mar 22 2007 Florian La Roche <laroche at redhat.com>
- adjust the Requires: for the scripts, add "chkconfig --add smb"

[3.0.24-6.fc7]
- do not put comments inline on smb.conf options, they may be read
   as part of the value (for example log files names)

[3.0.24-5.fc7]
- actually use the correct samba.pamd file not the old samba.pamd.stack file
- fix logifles and use upstream convention of log.* instead of our old *.log
   Winbindd creates its own log.* files anyway so we will be more consistent
- install our own (enhanced) default smb.conf file
- Fix pam_winbind acct_mgmt PAM result code (prevented local users from
   logging in). Fixed by Guenther.
- move some files from samba to samba-common as they are used with winbindd
   as well

[3.0.24-4.fc7]
- fix arch macro which reported Vista to Samba clients.

[3.0.24-3.fc7]
- Directories reorg, tdb files must go to /var/lib, not
   to /var/cache, add migration script in %post common
- Split out libsmbclient, devel and doc packages
- Remove libmsrpc.[h|so] for now as they are not really usable
- Remove kill -HUP from rotate, samba use -HUP for other things
   noit to reopen logs

[3.0.24-2.fc7]
- New upstream release
- Fix packaging issue wrt idmap modules used only by smbd
- Addedd Vista Patchset for compatibility with Windows Vista
- Change default of "msdfs root", it seem to cause problems with
   some applications and it has been proposed to change it for
   3.0.25 upstream

[3.0.23c-2]
- New upstream release.

[3.0.23b-2]
- New upstream release.

[3.0.23a-3]
- Fix the -logfiles patch to close
   bz#199607 Samba compiled with wrong log path.
   bz#199206 smb.conf has incorrect log file path

[3.0.23a-2]
- Upgrade to new upstream 3.0.23a
- include upstream samr_alias patch

[3.0.23-2]
- New upstream release.
- Use modified filter-requires-samba.sh from packaging/RHEL/setup/
   to get rid of bogus dependency on perl(Unicode::MapUTF8)
- Update the -logfiles and -smb.conf patches to work with 3.0.23

[3.0.23-0.RC3]
- New upstream RC release.
- Update the -logfiles, and -passwd patches for
   3.0.23rc3
- Include the change to smb.init from Bastien Nocera <bnocera at redhat.com>)
   to close
   bz#182560 Wrong retval for initscript when smbd is dead
- Update this spec file to build with 3.0.23rc3
- Remove the -install.mount.smbfs patch, since we don't install
   mount.smbfs any more.

[2.0.21c-3]
- rebuilt with new gnutls

[2.0.21c-2]
- New upstream version.

[3.0.21b-2]
- New upstream version.
- Since the rawhide kernel has dropped support for smbfs, remove smbmount
   and smbumount.  Users should use mount.cifs instead.
- Upgrade to 3.0.21b

[0:3.0.20b-2.1.1]
- bump again for double-long bug on ppc(64)

* Fri Dec 09 2005 Jesse Keating <jkeating at redhat.com>
- rebuilt

[3.0.20b-2]
- turn on -DLDAP_DEPRECATED to allow access to ldap functions that have
   been depricated in 2.3.11, but which don't have well-documented
   replacements (ldap_simple_bind_s(), for example).
- Upgrade to 3.0.20b, which includes all the previous upstream patches.
- Updated the -warnings patch for 3.0.20a.
- Include  --with-shared-modules=idmap_ad,idmap_rid to close
   bz#156810 --with-shared-modules=idmap_ad,idmap_rid
- Include the new samba.pamd from Tomas Mraz (tmraz at redhat.com) to close
   bz#170259 pam_stack is deprecated

[3.0.20-3]
- epochs from deps, req exact release
- rebuild against new openssl

[3.0.20-2]
- New upstream release
   Includes five upstream patches -bug3010_v1, -groupname_enumeration_v3,
     -regcreatekey_winxp_v1, -usrmgr_groups_v1, and -winbindd_v1
   This obsoletes the -pie and -delim patches
   the -warning and -gcc4 patches are obsolete too
   The -man, -passwd, and -smbspool patches were updated to match 3.0.20pre1
   Also, the -quoting patch was implemented differently upstream
   There is now a umount.cifs executable and manpage
   We run autogen.sh as part of the build phase
   The testprns command is now gone
   libsmbclient now has a man page
- Include -bug106483 patch to close
   bz#106483 smbclient: -N negates the provided password, despite 
documentation
- Added the -warnings patch to quiet some compiler warnings.
- Removed many obsolete patches from CVS.

[3.0.14a-2]
- New upstream release.
- the -64bit-timestamps, -clitar, -establish_trust, user_rights_v1,
   winbind_find_dc_v2 patches are now obsolete.

[3.0.13-2]
- New upstream release
- add my -quoting patch, to fix swat with strings that contain
   html meta-characters, and to use correct quote characters in
   lists, closing bz#134310
- include the upstream winbindd_2k3sp1 patch
- include the -smbclient patch.
- include the -hang patch from upstream.

* Thu Mar 24 2005 Florian La Roche <laroche at redhat.com>
- add a "exit 0" to the postun of the main samba package

[3.0.11-5]
- rebuild with openssl-0.9.7e

[3.0.11-4]
- Use the updated filter-requires-samba.sh file, so we don't accidentally
   pick up a dependency on perl(Crypt::SmbHash)

[3.0.11-3]
- add -gcc4 patch to compile with gcc 4.
- remove the now obsolete -smbclient-kerberos.patch
- Include four upstream patches from
   http://samba.org/~jerry/patches/post-3.0.11/
   (Slightly modified the winbind_find_dc_v2 patch to apply easily with
   rpmbuild).

[3.0.11-2]
- include -smbspool patch to close bz#104136

[3.0.10-4]
- Update the -man patch to fix ntlm_auth.1 too.
- Move pam_smbpass.so to the -common package, so both the 32
   and 64-bit versions will be installed on multiarch platforms.
   This closes bz#143617
- Added new -delim patch to fix mount.cifs so it can accept
   passwords with commas in them (via environment or credentials
   file) to close bz#144198

[3.0.10-3]
- Rebuilt for new readline.

[3.0.10-2]
- New upstream release that closes CAN-2004-1154  bz#142544
- Include the -64bit patch from Nalin.  This closes bz#142873
- Update the -logfiles patch to work with 3.0.10
- Create /var/run/winbindd and make it part of the -common rpm to close
   bz#142242

[3.0.9-2]
- New upstream release.  This obsoletes the -secret patch.
   Include my changetrustpw patch to make "net ads changetrustpw" stop
   aborting.  This closes #134694
- Remove obsolete triggers for ancient samba versions.
- Move /var/log/samba to the -common rpm.  This closes #76628
- Remove the hack needed to get around the bad docs files in the
   3.0.8 tarball.
- Change the comment in winbind.init to point at the correct pidfile.
   This closes #76641

[3.0.8-4]
- fix unresolved symbols in libsmbclient which caused applications
   such as KDE's konqueror to fail when accessing smb:// URLs. #139894

[3.0.8-3.1]
- Rescue the install.mount.smbfs patch from Juanjo Villaplana
   (villapla at si.uji.es) to prevent building the srpm from trashing your
   installed /usr/bin/smbmount

[3.0.8-3]
- Include the corrected docs tarball, and use it instead of the
   obsolete docs from the upstream 3.0.8 tarball.
- Update the logfiles patch to work with the updated docs.

[3.0.8-2]
- New upstream version fixes CAN-2004-0930.  This obsoletes the
   disable-sendfile, salt, signing-shortkey and fqdn patches.
- Add my <fenlason at redhat.com> ugly non-ascii-domain patch.
- Updated the pie patch for 3.0.8.
- Updated the logfiles patch for 3.0.8.

[3.0.8-0.pre2]
- New upstream version
- Add Nalin's signing-shortkey patch.

[3.0.8-0.pre1.3]
- disable the -salt patch, because it causes undefined references in
   libsmbclient that prevent gnome-vfs from building.

[3.0.8-0.pre1.2]
- Re-enable the x_fclose patch that was accidentally disabled
   in 3.0.8-0.pre1.1.  This closes #135832
- include Nalin's -fqdn and -salt patches.

[3.0.8-0.pre1.1]
- Include disable-sendfile patch to default "use sendfile" to "no".
   This closes #132779

* Wed Oct 06 2004 Jay Fenlason <fenlason at redhat.com>
- Include patch from Steven Lawrance (slawrance at yahoo.com) that modifies
   smbmnt to work with 32-bit uids.

[3.0.8-0.pre1]
- new upstream release.  This obsoletes the ldapsam_compat patches.

[3.0.7-4]
- Update docs section to not carryover the docs/manpages directory
   This moved many files from /usr/share/doc/samba-3.0.7/docs/* to
   /usr/share/doc/samba-3.0.7/*
- Modify spec file as suggested by Rex Dieter (rdieter at math.unl.edu)
   to correctly create libsmbclient.so.0 and to use %_initrddir instead
   of rolling our own.  This closes #132642
- Add patch to default "use sendfile" to no, since sendfile appears to
   be broken
- Add patch from Volker Lendecke <vl at samba.org> to help make
   ldapsam_compat work again.
- Add patch from "Vince Brimhall" <vbrimhall at novell.com> for ldapsam_compat
   These two patches close bugzilla #132169

[3.0.7-3]
- Upgrade to 3.0.7, which fixes CAN-2004-0807 CAN-2004-0808
   This obsoletes the 3.0.6-schema patch.
- Update BuildRequires line to include openldap-devel openssl-devel
   and cups-devel

[3.0.6-3]
- New upstream version.
- Include post 3.0.6 patch from "Gerald (Jerry) Carter" <jerry at samba.org>
   to fix a duplicate in the LDAP schema.
- Include 64-bit timestamp patch from Ravikumar (rkumar at hp.com)
   to allow correct timestamp handling on 64-bit platforms and fix #126109.
- reenable the -pie patch.  Samba is too widely used, and too vulnerable
   to potential security holes to disable an important security feature
   like -pie.  The correct fix is to have the toolchain not create broken
   executables when programs compiled -pie are stripped.
- Remove obsolete patches.
- Modify this spec file to put libsmbclient.{a,so} in the right place on
   x86_64 machines.

[3.0.5-3]
- Removed '-pie' patch - 3.0.5 uses -fPIC/-PIC, and the combination
- resulted in executables getting corrupt stacks, causing smbmnt to
- get a SIGBUS in the mount() call (bug 127420).

[3.0.5-2]
- Upgrade to 3.0.5, which is a regression from 3.0.5pre1 for a
   security fix.
- Include the 3.0.4-backport patch from the 3E branch.  This restores
   some of the 3.0.5pre1 and 3.0.5rc1 functionality.

[3.0.5-0.pre1.1]
- Backport base64_decode patche to close CAN-2004-0500
- Backport hash patch to close CAN-2004-0686
- use_authtok patch from Nalin Dahyabhai <nalin at redhat.com>
- smbclient-kerberos patch from Alexander Larsson <alexl at redhat.com>
- passwd patch uses "*" instead of "x" for "hashed" passwords for
   accounts created by winbind.  "x" means "password is in /etc/shadow" to
   brain-damaged pam_unix module.

[3.0.5.0pre1.0]
- New upstream version
- use % { SOURCE1 } instead of a hardcoded path
- include -winbind patch from Gerald (Jerry) Carter (jerry at samba.org)
   https://bugzilla.samba.org/show_bug.cgi?id=1315
   to make winbindd work against Windows versions that do not have
   128 bit encryption enabled.
- Moved %{_bindir}/net to the -common package, so that folks who just
   want to use winbind, etc don't have to install -client in order to
   "net join" their domain.
- New upstream version obsoletes the patches added in 3.0.3-5
- Remove smbgetrc.5 man page, since we don't ship smbget.

* Tue Jun 15 2004 Elliot Lee <sopwith at redhat.com>
- rebuilt

[3.0.3-5]
- Patch to allow password changes from machines patched with
   Microsoft hotfix MS04-011.
- Include patches for https://bugzilla.samba.org/show_bug.cgi?id=1302
   and https://bugzilla.samba.org/show_bug.cgi?id=1309

[3.0.3-4]
- Samba 3.0.3 released.

[3.0.3-3.rc1]
- New upstream version
- updated spec file to make libsmbclient.so executable.  This closes
   bugzilla #121356

[3.0.3-2.pre2]
- New upstream version - Updated configure line to remove --with-fhs and 
to explicitly set all
   the directories that --with-fhs was setting.  We were overriding most of
   them anyway.  This closes #118598

[3.0.3-1.pre1]
- New upstream version.
- Updated -pie and -logfiles patches for 3.0.3pre1
- add krb5-devel to buildrequires, fixes #116560
- Add patch from Miloslav Trmac (mitr at volny.cz) to allow non-root to run
   "service smb status".  This fixes #116559

* Tue Mar 02 2004 Elliot Lee <sopwith at redhat.com>
- rebuilt

[3.0.2a-1]
- Upgrade to 3.0.2a

[3.0.2-7]
- fix ownership in -common package

* Fri Feb 13 2004 Elliot Lee <sopwith at redhat.com>
- rebuilt

* Fri Feb 13 2004 Jay Fenlason <fenlason at redhat.com>
- Change all requires lines to list an explicit epoch.  Closes #102715
- Add an explicit Epoch so that %{epoch} is defined.

[3.0.2-5]
- New upstream version: 3.0.2 final includes security fix for #114995
   (CAN-2004-0082)
- Edit postun script for the -common package to restart winbind when
   appropriate.  Fixes bugzilla #114051.

[3.0.2-3rc2]
- add %dir entries for %{_libdir}/samba and %{_libdir}/samba/charset
- Upgrade to new upstream version
- build mount.cifs for the new cifs filesystem in the 2.6 kernel.

[3.0.2-1rc1]
- Upgrade to new upstream version

[3.0.1-1]
- Update to 3.0.1
- Removed testparm patch as it's already merged
- Removed Samba.7* man pages
- Fixed .buildroot patch
- Fixed .pie patch
- Added new /usr/bin/tdbdump file

[3.0.0-15]
- New 3.0.0 final release
- merge nmbd-netbiosname and testparm patches from 3E branch
- updated the -logfiles patch to work against 3.0.0
- updated the pie patch
- update the VERSION file during build
- use make -j if avaliable
- merge the winbindd_privileged change from 3E
- merge the "rm /usr/lib" patch that allows Samba to build on 64-bit
   platforms despite the broken Makefile

* Mon Aug 18 2003 Jay Fenlason <fenlason at redhat.com>
- Merge from samba-3E-branch after samba-3.0.0rc1 was released

[3.0.0-3beta3]
- Merge from 3.0.0-2beta3.3E
- (Correct log file names (#100981).)
- (Fix pidfile directory in samab.log)
- (Remove obsolete samba-3.0.0beta2.tar.bz2.md5 file)
- (Move libsmbclient to the -common package (#99449))

[2.2.8a-4]
- rebuild

* Wed Jun 04 2003 Elliot Lee <sopwith at redhat.com>
- rebuilt

[2.2.8a-2]
- add libsmbclient.so for gnome-vfs-extras
- Edit specfile to specify /var/run for pid files
- Move /tmp/.winbindd/socket to /var/run/winbindd/socket

* Wed May 14 2003 Florian La Roche <Florian.LaRoche at redhat.de>
- add proper ldconfig calls

[2.2.8a-1]
- upgrade to 2.2.8a
- remove old .md5 files
- add "pid directory = /var/run" to the smb.conf file.  Fixes #88495
- Patch from jra at dp.samba.org to fix a delete-on-close regression

[2.2.8-0]
- Upgrade to 2.2.8
- removed commented out patches.
- removed old patches and .md5 files from the repository.
- remove duplicate /sbin/chkconfig --del winbind which causes
   warnings when removing samba.
- Fixed minor bug in smbprint that causes it to fail when called with
   more than 10 parameters: the accounting file (and spool directory
   derived from it) were being set wrong due to missing {}.  This closes
   bug #86473.
- updated smb.conf patch, includes new defaults to close bug #84822.

* Mon Feb 24 2003 Elliot Lee <sopwith at redhat.com>
- rebuilt

[2.2.7a-5]
- remove swat.desktop file

[2.2.7a-4]
- relink libnss_wins.so with SHLD="%{__cc} -lnsl" to force libnss_wins.so to
   link with libnsl, avoiding unresolved symbol errors on functions in 
libnsl

[2.2.7a-3]
- edited spec file to put .so files in the correct directories
   on 64-bit platforms that have 32-bit compatability issues
   (sparc64, x86_64, etc).  This fixes bugzilla #83782.
- Added samba-2.2.7a-error.patch from twaugh.  This fixes
   bugzilla #82454.

* Wed Jan 22 2003 Tim Powers <timp at redhat.com>
- rebuilt

[2.2.7a-1]
- Update to 2.2.7a
- Change default printing system to CUPS
- Turn on pam_smbpass
- Turn on msdfs

[2.2.7-5]
- use internal dep generator.

[2.2.7-4]
- don't use rpms internal dep generator

[2.2.7-3]
- Fix missing doc files.
- Fix multilib issues

[2.2.7-2]
- update to 2.2.7
- add patch for LFS in smbclient (<tcallawa at redhat.com>)

[2.2.5-10]
- logrotate fixes (#65007)

[2.2.5-9]
- /usr/lib was used in place of %{_libdir} in three locations (#72554)

[2.2.5-8]
- Initscript fix (#70720)

[2.2.5-7]
- Enable VFS support and compile the "recycling" module (#69796)
- more selective includes of the examples dir

[2.2.5-6]
- Fix the lpq parser for better handling of LPRng systems (#69352)

[2.2.5-5]
- desktop file fixes (#69505)

[2.2.5-4]
- Enable ACLs

[2.2.5-3]
- Make it not depend on Net::LDAP - those are doc files and examples

* Fri Jun 21 2002 Tim Powers <timp at redhat.com>
- automated rebuild

[2.2.5-1]
- 2.2.5

[2.2.4-5]
- Move the post/preun of winbind into the -common subpackage,
   where the script is (#66128)

[2.2.4-4]
- Fix pidfile locations so it runs properly again (2.2.4
   added a new directtive - #65007)

* Thu May 23 2002 Tim Powers <timp at redhat.com>
- automated rebuild

[2.2.4-2]
- Fix #64804

[2.2.4-1]
- 2.2.4
- Removed some zero-length and CVS internal files
- Make it build

[2.2.3a-6]
- Don't use /etc/samba.d in smbadduser, it should be /etc/samba

[2.2.3a-5]
- Add libsmbclient.a w/headerfile for KDE (#62202)

[2.2.3a-4]
- Make the logrotate script look the correct place for the pid files

[2.2.3a-3]
- include interfaces.o in pam_smbpass.so, which needs symbols from 
interfaces.o
   (patch posted to samba-list by Ilia Chipitsine)

[2.2.3a-2]
- Rebuild

[2.2.3a-1]
- 2.2.3a

[2.2.3-1]
- 2.2.3

[2.2.2-8]
- New pam configuration file for samba

[2.2.2-7]
- Enable PAM session controll and password sync

[2.2.2-6]
- Move winbind files to samba-common. Add separate initscript for
   winbind
- Fixes for winbind - protect global variables with mutex, use
   more secure getenv

[2.2.2-5]
- Teach smbadduser about "getent passwd"
- Fix more pid-file references
- Add (conditional) winbindd startup to the initscript, configured in
   /etc/sysconfig/samba

[2.2.2-4]
- Fix pid-file reference in logrotate script
- include pam and nss modules for winbind

[2.2.2-3]
- Add "--with-utmp" to configure options (#55372)
- Include winbind, pam_smbpass.so, rpcclient and smbcacls
- start using /var/cache/samba, we need to keep state and there is
   more than just locks involved

[2.2.2-2]
- add "reload" to the usage string in the startup script

[2.2.2-1]
- 2.2.2

[2.2.1a-5]
- Add patch from Jeremy Allison to fix IA64 alignment problems (#51497)

* Mon Aug 13 2001 Trond Eivind Glomsrød <teg at redhat.com>
- Don't include smbpasswd in samba, it's in samba-common (#51598)
- Add a disabled "obey pam restrictions" statement - it's not
   active, as we use encrypted passwords, but if the admin turns
   encrypted passwords off the choice is available. (#31351)

* Wed Aug 08 2001 Trond Eivind Glomsrød <teg at redhat.com>
- Use /var/cache/samba instead of /var/lock/samba
- Remove "domain controller" keyword from smb.conf, it's
   deprecated (from #13704)
- Sync some examples with smb.conf.default
- Fix password synchronization (#16987)

* Fri Jul 20 2001 Trond Eivind Glomsrød <teg at redhat.com>
- Tweaks of BuildRequires (#49581)

* Wed Jul 11 2001 Trond Eivind Glomsrød <teg at redhat.com>
- 2.2.1a bugfix release

* Tue Jul 10 2001 Trond Eivind Glomsrød <teg at redhat.com>
- 2.2.1, which should work better for XP

* Sat Jun 23 2001 Trond Eivind Glomsrød <teg at redhat.com>
- 2.2.0a security fix
- Mark lograte and pam configuration files as noreplace

* Fri Jun 22 2001 Trond Eivind Glomsrød <teg at redhat.com>
- Add the /etc/samba directory to samba-common

* Thu Jun 21 2001 Trond Eivind Glomsrød <teg at redhat.com>
- Add improvements to the smb.conf as suggested in #16931

* Tue Jun 19 2001 Trond Eivind Glomsrød <teg at redhat.com>
(these changes are from the non-head version)
- Don't include /usr/sbin/samba, it's the same as the initscript
- unset TMPDIR, as samba can't write into a TMPDIR owned
   by root (#41193)
- Add pidfile: lines for smbd and nmbd and a config: line
   in the initscript  (#15343)
- don't use make -j
- explicitly include /usr/share/samba, not just the files in it

* Tue Jun 19 2001 Bill Nottingham <notting at redhat.com>
- mount.smb/mount.smbfs go in /sbin, *not* %{_sbindir}

* Fri Jun 08 2001 Preston Brown <pbrown at redhat.com>
- enable encypted passwords by default

* Thu Jun 07 2001 Helge Deller <hdeller at redhat.de>
- build as 2.2.0-1 release
- skip the documentation-directories docbook, manpages and yodldocs
- don't include *.sgml documentation in package
- moved codepage-directory to /usr/share/samba/codepages
- make it compile with glibc-2.2.3-10 and kernel-headers-2.4.2-2

* Mon May 21 2001 Helge Deller <hdeller at redhat.de>
- updated to samba 2.2.0
- moved codepages to %{_datadir}/samba/codepages
- use all available CPUs for building rpm packages
- use %{_xxx} defines at most places in spec-file
- "License:" replaces "Copyright:"
- dropped excludearch sparc
- de-activated japanese patches 100 and 200 for now
   (they need to be fixed and tested wth 2.2.0)
- separated swat.desktop file from spec-file and added
   german translations
- moved /etc/sysconfig/samba to a separate source-file
- use htmlview instead of direct call to netscape in
   swat.desktop-file

* Mon May 07 2001 Bill Nottingham <notting at redhat.com>
- device-remove security fix again (<tridge at samba.org>)

* Fri Apr 20 2001 Bill Nottingham <notting at redhat.com>
- fix tempfile security problems, officially (<tridge at samba.org>)
- update to 2.0.8

* Sun Apr 08 2001 Bill Nottingham <notting at redhat.com>
- turn of SSL, kerberos

* Thu Apr 05 2001 Bill Nottingham <notting at redhat.com>
- fix tempfile security problems (patch from <Marcus.Meissner at caldera.de>)

* Thu Mar 29 2001 Bill Nottingham <notting at redhat.com>
- fix quota support, and quotas with the 2.4 kernel (#31362, #33915)

* Mon Mar 26 2001 Nalin Dahyabhai <nalin at redhat.com>
- tweak the PAM code some more to try to do a setcred() after initgroups()
- pull in all of the optflags on i386 and sparc
- don't explicitly enable Kerberos support -- it's only used for password
   checking, and if PAM is enabled it's a no-op anyway

* Mon Mar 05 2001 Tim Waugh <twaugh at redhat.com>
- exit successfully from preun script (bug #30644).

* Fri Mar 02 2001 Nalin Dahyabhai <nalin at redhat.com>
- rebuild in new environment

* Wed Feb 14 2001 Bill Nottingham <notting at redhat.com>
- updated japanese stuff (#27683)

* Fri Feb 09 2001 Bill Nottingham <notting at redhat.com>
- fix trigger (#26859)

* Wed Feb 07 2001 Bill Nottingham <notting at redhat.com>
- add i18n support, japanese patch (#26253)

* Wed Feb 07 2001 Trond Eivind Glomsrød <teg at redhat.com>
- i18n improvements in initscript (#26537)

* Wed Jan 31 2001 Bill Nottingham <notting at redhat.com>
- put smbpasswd in samba-common (#25429)

* Wed Jan 24 2001 Bill Nottingham <notting at redhat.com>
- new i18n stuff

* Sun Jan 21 2001 Bill Nottingham <notting at redhat.com>
- rebuild

* Thu Jan 18 2001 Bill Nottingham <notting at redhat.com>
- i18n-ize initscript
- add a sysconfig file for daemon options (#23550)
- clarify smbpasswd man page (#23370)
- build with LFS support (#22388)
- avoid extraneous pam error messages (#10666)
- add Urban Widmark's bug fixes for smbmount (#19623)
- fix setgid directory modes (#11911)
- split swat into subpackage (#19706)

* Wed Oct 25 2000 Nalin Dahyabhai <nalin at redhat.com>
- set a default CA certificate path in smb.conf (#19010)
- require openssl >= 0.9.5a-20 to make sure we have a ca-bundle.crt file

* Mon Oct 16 2000 Bill Nottingham <notting at redhat.com>
- fix swat only_from line (#18726, others)
- fix attempt to write outside buildroot on install (#17943)

* Mon Aug 14 2000 Bill Nottingham <notting at redhat.com>
- add smbspool back in (#15827)
- fix absolute symlinks (#16125)

* Sun Aug 06 2000 Philipp Knirsch <pknirsch at redhat.com>
- bugfix for smbadduser script (#15148)

* Mon Jul 31 2000 Matt Wilson <msw at redhat.com>
- patch configure.ing (patch11) to disable cups test
- turn off swat by default

* Fri Jul 28 2000 Bill Nottingham <notting at redhat.com>
- fix condrestart stuff

* Fri Jul 21 2000 Bill Nottingham <notting at redhat.com>
- add copytruncate to logrotate file (#14360)
- fix init script (#13708)

* Sat Jul 15 2000 Bill Nottingham <notting at redhat.com>
- move initscript back
- remove 'Using Samba' book from %doc
- move stuff to /etc/samba (#13708)
- default configuration tweaks (#13704)
- some logrotate tweaks

* Wed Jul 12 2000 Prospector <bugzilla at redhat.com>
- automatic rebuild

* Tue Jul 11 2000 Bill Nottingham <notting at redhat.com>
- fix logrotate script (#13698)

* Thu Jul 06 2000 Bill Nottingham <notting at redhat.com>
- fix initscripts req (prereq /etc/init.d)

* Wed Jul 05 2000 Than Ngo <than at redhat.de>
- add initdir macro to handle the initscript directory
- add a new macro to handle /etc/pam.d/system-auth

* Thu Jun 29 2000 Nalin Dahyabhai <nalin at redhat.com>
- enable Kerberos 5 and SSL support
- patch for duplicate profile.h headers

* Thu Jun 29 2000 Bill Nottingham <notting at redhat.com>
- fix init script

* Tue Jun 27 2000 Bill Nottingham <notting at redhat.com>
- rename samba logs (#11606)

* Mon Jun 26 2000 Bill Nottingham <notting at redhat.com>
- initscript munging

* Fri Jun 16 2000 Bill Nottingham <notting at redhat.com>
- configure the swat stuff usefully
- re-integrate some specfile tweaks that got lost somewhere

* Thu Jun 15 2000 Bill Nottingham <notting at redhat.com>
- rebuild to get rid of cups dependency

* Wed Jun 14 2000 Nalin Dahyabhai <nalin at redhat.com>
- tweak logrotate configurations to use the PID file in /var/lock/samba

* Sun Jun 11 2000 Bill Nottingham <notting at redhat.com>
- rebuild in new environment

* Thu Jun 01 2000 Nalin Dahyabhai <nalin at redhat.com>
- change PAM setup to use system-auth

* Mon May 08 2000 Bill Nottingham <notting at redhat.com>
- fixes for ia64

* Sat May 06 2000 Bill Nottingham <notting at redhat.com>
- switch to %configure

* Wed Apr 26 2000 Nils Philippsen <nils at redhat.de>
- version 2.0.7

* Sun Mar 26 2000 Florian La Roche <Florian.LaRoche at redhat.com>
- simplify preun

* Thu Mar 16 2000 Bill Nottingham <notting at redhat.com>
- fix yp_get_default_domain in autoconf
- only link against readline for smbclient
- fix log rotation (#9909)

* Fri Feb 25 2000 Bill Nottingham <notting at redhat.com>
- fix trigger, again.

* Mon Feb 07 2000 Bill Nottingham <notting at redhat.com>
- fix trigger.

* Fri Feb 04 2000 Bill Nottingham <notting at redhat.com>
- turn on quota support

* Mon Jan 31 2000 Cristian Gafton <gafton at redhat.com>
- rebuild to fox dependencies
- man pages are compressed

* Fri Jan 21 2000 Bill Nottingham <notting at redhat.com>
- munge post scripts slightly

* Wed Jan 19 2000 Bill Nottingham <notting at redhat.com>
- turn on mmap again. Wheee.
- ship smbmount on alpha

* Mon Dec 06 1999 Bill Nottingham <notting at redhat.com>
- turn off mmap. ;)

* Wed Dec 01 1999 Bill Nottingham <notting at redhat.com>
- change /var/log/samba to 0700
- turn on mmap support

* Thu Nov 11 1999 Bill Nottingham <notting at redhat.com>
- update to 2.0.6

* Fri Oct 29 1999 Bill Nottingham <notting at redhat.com>
- add a %defattr for -common

* Tue Oct 05 1999 Bill Nottingham <notting at redhat.com>
- shift some files into -client
- remove /home/samba from package.

* Tue Sep 28 1999 Bill Nottingham <notting at redhat.com>
- initscript oopsie. killproc <name> -HUP, not other way around.

* Sun Sep 26 1999 Bill Nottingham <notting at redhat.com>
- script cleanups. Again.

* Wed Sep 22 1999 Bill Nottingham <notting at redhat.com>
- add a patch to fix dropped reconnection attempts

* Mon Sep 06 1999 Jeff Johnson <jbj at redhat.com>
- use cp rather than mv to preserve /etc/services perms (#4938 et al).
- use mktemp to generate /etc/tmp.XXXXXX file name.
- add prereqs on sed/mktemp/killall (need to move killall to /bin).
- fix trigger syntax (i.e. "samba < 1.9.18p7" not "samba < samba-1.9.18p7")

* Mon Aug 30 1999 Bill Nottingham <notting at redhat.com>
- sed "s|nawk|gawk|" /usr/bin/convert_smbpasswd

* Sat Aug 21 1999 Bill Nottingham <notting at redhat.com>
- fix typo in mount.smb

* Fri Aug 20 1999 Bill Nottingham <notting at redhat.com>
- add a %trigger to work around (sort of) broken scripts in
   previous releases

* Mon Aug 16 1999 Bill Nottingham <notting at redhat.com>
- initscript munging

* Mon Aug 09 1999 Bill Nottingham <notting at redhat.com>
- add domain parsing to mount.smb

* Fri Aug 06 1999 Bill Nottingham <notting at redhat.com>
- add a -common package, shuffle files around.

* Fri Jul 23 1999 Bill Nottingham <notting at redhat.com>
- add a chmod in %postun so /etc/services & inetd.conf don't become 
unreadable

* Wed Jul 21 1999 Bill Nottingham <notting at redhat.com>
- update to 2.0.5
- fix mount.smb - smbmount options changed again.........
- fix postun. oops.
- update some stuff from the samba team's spec file.

* Fri Jun 18 1999 Bill Nottingham <notting at redhat.com>
- split off clients into separate package
- don't run samba by default

* Mon Jun 14 1999 Bill Nottingham <notting at redhat.com>
- fix one problem with mount.smb script
- fix smbpasswd on sparc with a really ugly kludge

* Thu Jun 10 1999 Dale Lovelace <dale at redhat.com>
- fixed logrotate script

* Tue May 25 1999 Bill Nottingham <notting at redhat.com>
- turn of 64-bit locking on 32-bit platforms

* Thu May 20 1999 Bill Nottingham <notting at redhat.com>
- so many releases, so little time
- explicitly uncomment 'printing = bsd' in sample config

* Tue May 18 1999 Bill Nottingham <notting at redhat.com>
- update to 2.0.4a
- fix mount.smb arg ordering

* Fri Apr 16 1999 Bill Nottingham <notting at redhat.com>
- go back to stop/start for restart (-HUP didn't work in testing)

* Fri Mar 26 1999 Bill Nottingham <notting at redhat.com>
- add a mount.smb to make smb mounting a little easier.
- smb filesystems apparently don't work on alpha. Oops.

* Thu Mar 25 1999 Bill Nottingham <notting at redhat.com>
- always create codepages

* Tue Mar 23 1999 Bill Nottingham <notting at redhat.com>
- logrotate changes

* Sun Mar 21 1999 Cristian Gafton <gafton at redhat.com>
- auto rebuild in the new build environment (release 3)

* Fri Mar 19 1999 Preston Brown <pbrown at redhat.com>
- updated init script to use graceful restart (not stop/start)

* Tue Mar 09 1999 Bill Nottingham <notting at redhat.com>
- update to 2.0.3

* Thu Feb 18 1999 Bill Nottingham <notting at redhat.com>
- update to 2.0.2

* Mon Feb 15 1999 Bill Nottingham <notting at redhat.com>
- swat swat

* Tue Feb 09 1999 Bill Nottingham <notting at redhat.com>
- fix bash2 breakage in post script

* Fri Feb 05 1999 Bill Nottingham <notting at redhat.com>
- update to 2.0.0

* Mon Oct 12 1998 Cristian Gafton <gafton at redhat.com>
- make sure all binaries are stripped

* Thu Sep 17 1998 Jeff Johnson <jbj at redhat.com>
- update to 1.9.18p10.
- fix %triggerpostun.

* Tue Jul 07 1998 Erik Troan <ewt at redhat.com>
- updated postun triggerscript to check $0
- clear /etc/codepages from %preun instead of %postun

* Mon Jun 08 1998 Erik Troan <ewt at redhat.com>
- made the %postun script a tad less agressive; no reason to remove
   the logs or lock file (after all, if the lock file is still there,
   samba is still running)
- the %postun and %preun should only exectute if this is the final
   removal
- migrated %triggerpostun from Red Hat's samba package to work around
   packaging problems in some Red Hat samba releases

* Sun Apr 26 1998 John H Terpstra <jht at samba.anu.edu.au>
- minor tidy up in preparation for release of 1.9.18p5
- added findsmb utility from SGI package

* Wed Mar 18 1998 John H Terpstra <jht at samba.anu.edu.au>
- Updated version and codepage info.
- Release to test name resolve order

* Sat Jan 24 1998 John H Terpstra <jht at samba.anu.edu.au>
- Many optimisations (some suggested by Manoj Kasichainula <manojk at io.com>
- Use of chkconfig in place of individual symlinks to /etc/rc.d/init/smb
- Compounded make line
- Updated smb.init restart mechanism
- Use compound mkdir -p line instead of individual calls to mkdir
- Fixed smb.conf file path for log files
- Fixed smb.conf file path for incoming smb print spool directory
- Added a number of options to smb.conf file
- Added smbadduser command (missed from all previous RPMs) - Doooh!
- Added smbuser file and smb.conf file updates for username map





More information about the El-errata mailing list