The branch, master has been updated via 8925b0c [PATCH] s3-WHATSNEW 3.5.9 Add information on kerberos change from ec99588 Update latest stable release.
http://gitweb.samba.org/?p=samba-web.git;a=shortlog;h=master - Log ----------------------------------------------------------------- commit 8925b0ceed6bfb6109a5283ce040fd705421a427 Author: Andrew Bartlett <abart...@samba.org> Date: Fri Jun 17 22:06:10 2011 +0200 [PATCH] s3-WHATSNEW 3.5.9 Add information on kerberos change This patch modifies the release notes after the release, so the hints are not included in the 3.5.9 tarball. ----------------------------------------------------------------------- Summary of changes: history/samba-3.5.9.html | 15 +++++++++++++++ 1 files changed, 15 insertions(+), 0 deletions(-) Changeset truncated at 500 lines: diff --git a/history/samba-3.5.9.html b/history/samba-3.5.9.html index 8450077..feb9b58 100755 --- a/history/samba-3.5.9.html +++ b/history/samba-3.5.9.html @@ -25,6 +25,21 @@ Major enhancements in Samba 3.5.9 include: o Sgid bit lost on folder rename (bug #7996). o ACL can get lost when files are being renamed (bug #7987). o Respect "allow trusted domains = no" in Winbind (bug #6966). +o Samba now follows Windows behaviour as a kerberos client, + requesting a CIFS/ ticket (bug #7893). + +New Kerberos behaviour +---------------------- + +A new parameter 'client use spnego principal' defaults to 'no' and +means Samba will use CIFS/hostname to obtain a kerberos ticket, acting +more like Windows when using Kerberos against a CIFS server in +smbclient, Winbind and other Samba client tools. This will change +which servers we will successfully negotiate Kerberos connections to. +This is due to Samba no longer trusting a server-provided hint which +is not available from Windows 2008 or later. For correct operation +with all clients, all aliases for a server should be recorded as a as +a servicePrincipalName on the server's record in AD. Changes since 3.5.8: -- Samba Website Repository