Samba Kerberos authentication fails in MIT realms since 12.0-U6.1

Description

Since 12.0-U6.1 Samba authentication fails when using Kerberos in an MIT realm.

Upstream bug report: https://bugzilla.samba.org/show_bug.cgi?id=14922
Upstream fix: https://gitlab.com/samba-team/samba/-/commit/1e61de8306604a0d3858342df8a1d2412d8d418b

The fix is already included in Samba version 4.13.15 and 4.14.11, so I'm opening this issue to be sure that next TrueNAS release will include one of these version and not stay on 4.13.14.

It would be nice if this upgrade was released soon, because currently people using Kerberos authentication in an MIT realm, e.g., FreeIPA, have to stay on a Samba version vulnerable to CVE-2020-25717.

Thanks a lot!


To help discoverability when searching for this issue, here is the related error in {{{}/var/log/{}}}samba4/log.smdb

 

 

Problem/Justification

None

Impact

None

Activity

Bug Clerk 
December 20, 2021 at 7:22 PM

Andrew Walker 
December 17, 2021 at 11:29 AM

Thanks for filing this. We were planning to update before next release.

Complete

Details

Assignee

Reporter

Time remaining

0m

Components

Fix versions

Affects versions

Priority

Katalon Platform

Created December 17, 2021 at 9:56 AM
Updated February 1, 2022 at 6:25 PM
Resolved January 7, 2022 at 9:59 PM