SAMBA and KB5028166

Issues related to applications and software problems
Post Reply
Whoever
Posts: 1351
Joined: 2013/09/06 03:12:10

SAMBA and KB5028166

Post by Whoever » 2023/08/03 20:42:41

This security update from Microsoft has broken PDC support in SAMBA.
https://bugzilla.samba.org/show_bug.cgi?id=15425

There are fixes underway in the SAMBA code, but will these make their way into CentOS 7? If not, will they go into CentOS Stream?

User avatar
TrevorH
Site Admin
Posts: 33039
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: SAMBA and KB5028166

Post by TrevorH » 2023/08/03 21:47:34

we are assured that an updated MS-NRPC will be published soon
Sounds like Microsoft are going to fix it.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

Whoever
Posts: 1351
Joined: 2013/09/06 03:12:10

Re: SAMBA and KB5028166

Post by Whoever » 2023/08/09 17:33:51

TrevorH wrote:
2023/08/03 21:47:34
we are assured that an updated MS-NRPC will be published soon
Sounds like Microsoft are going to fix it.
I don't think so. Microsoft just pushed out another update that contained the same breakage (KB5029244).

The "fix" is to update the specification, to document this new behavior.

Whoever
Posts: 1351
Joined: 2013/09/06 03:12:10

Re: SAMBA and KB5028166

Post by Whoever » 2023/09/16 23:44:56

RedHat has pushed an update for this issue (samba-4.10.16-25.el7_9 and similar). Will we see this in CentOS?

User avatar
TrevorH
Site Admin
Posts: 33039
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: SAMBA and KB5028166

Post by TrevorH » 2023/09/17 01:45:12

It's in the build pipeline somewhere already.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

Whoever
Posts: 1351
Joined: 2013/09/06 03:12:10

Re: SAMBA and KB5028166

Post by Whoever » 2023/09/21 03:04:09

TrevorH wrote:
2023/09/17 01:45:12
It's in the build pipeline somewhere already.
It seems to be taking a lot of time to make its way through the build pipeline.

HenrykD
Posts: 75
Joined: 2011/01/14 06:09:52
Location: Poland

Re: SAMBA and KB5028166

Post by HenrykD » 2023/09/21 12:09:54

Out of curiosity, I installed Samba 4.10.16-25.el7_9 packages from Oracle Linux 7 in CentOS 7 and it works.

When logging in to Windows 10 with the latest KB5030211 patch (KB5028166 in July, KB5029244 in August),
there is no trust issue message.

User avatar
TrevorH
Site Admin
Posts: 33039
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: SAMBA and KB5028166

Post by TrevorH » 2023/09/21 13:18:07

I would suspect that 4.10.16-25 is the fixed version. The current CentOS 7 one is 4.10.16-24 though -25 is in QA nad pending release.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

User avatar
TrevorH
Site Admin
Posts: 33039
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: SAMBA and KB5028166

Post by TrevorH » 2023/09/23 19:18:37

Released.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

Post Reply