1 |
SME Server 7.2 Release Notes |
SME Server 7.4 Release Announcement |
2 |
============================ |
=================================== |
3 |
|
|
4 |
June 17 2007 |
October 20 2008 |
5 |
|
|
6 |
The SME Server development team is pleased to announce the release of |
The SME Server development team is pleased to announce the release of |
7 |
SME Server 7.2. This release is based on CentOS 4.5 and all packages |
SME Server 7.4. This release is based on CentOS 4.7 and all packages |
8 |
have been updated to the latest releases. |
have been updated to the latest releases. |
9 |
|
|
10 |
|
|
11 |
|
All SME Server users should upgrade to this release. |
12 |
|
|
13 |
|
The release should be obtained from your closest mirror, see |
14 |
|
http://wiki.contribs.org/SME_Server:Download |
15 |
|
|
16 |
|
Bug reports and reports of potential bugs should be raised |
17 |
|
in the bug tracker (and only there, please); |
18 |
|
|
19 |
|
http://bugs.contribs.org/ |
20 |
|
|
|
This release contains many new features, all released updates for |
|
|
SME Server 7.1 and fixes for many reported problems. Upgrades |
|
|
will be available by CD, the Software Installer and command line. |
|
21 |
|
|
22 |
All users should upgrade to this release. |
Please Note |
23 |
|
=========== |
24 |
|
It may take up to 48 hours for mirrors to finish syncing, |
25 |
|
during this time you may experience problems. |
26 |
|
|
|
Please report any issues with the SME Server to the bug tracker, |
|
|
and only there: |
|
27 |
|
|
28 |
http://www.contribs.org/bugzilla/ |
About SME Server |
29 |
|
================ |
30 |
|
|
31 |
|
SME Server is the leading Linux distribution for small and medium |
32 |
|
enterprises. SME Server is brought to you by SME Server, Inc. |
33 |
|
( http://www.smeserver.org/ ), a non-profit corporation that exists to |
34 |
|
provide marketing and legal support for SME Server. |
35 |
|
|
36 |
|
SME Server is freely available under the GNU General Public License |
37 |
|
and is only possible through the efforts of the SME Server community. |
38 |
|
However, the availability and quality of SME Server is dependent on |
39 |
|
meeting our expenses, such as hosting costs, server hardware, etc. |
40 |
|
|
41 |
|
As such, we ask for a small donation to offset costs and fund further |
42 |
|
development. |
43 |
|
|
44 |
|
Please visit http://www.smeserver.org/donate/ to donate. |
45 |
|
|
46 |
|
|
47 |
Thanks |
Thanks |
48 |
------ |
====== |
49 |
The development team would like to thank all of those involved in |
The development team would like to thank all of those involved in |
50 |
this release. However, this distribution cannot continue with the |
this release. However, this distribution cannot continue with the |
51 |
current level of support. |
current level of support. More people are required to help with |
52 |
|
bug triage and verification testing. |
53 |
|
|
54 |
|
|
55 |
|
This release contains many new features, all released updates for |
56 |
|
SME Server 7.3 and fixes for many reported problems. Upgrades |
57 |
|
will be available by CD, the Software Installer and command line. |
58 |
|
|
59 |
|
|
60 |
|
Upgrades |
61 |
|
======== |
62 |
|
- Always perform a backup prior to major system upgrades |
63 |
|
- An upgrade will preserve the existing data |
64 |
|
|
65 |
|
|
66 |
Changes in this release |
Changes in this release |
67 |
======================= |
======================= |
68 |
|
|
69 |
Virus/Spam Scanning |
Installer |
70 |
|
--------- |
71 |
|
- Fix grub label to keep consistent with the SME Server brand. |
72 |
|
|
73 |
|
Mail system changes |
74 |
------------------- |
------------------- |
75 |
- The FuzzyOCR spamassassin plugin has been enabled to detect image spam |
- Introduce a web interface to configure the pseudonym "visible" property |
76 |
- An X-Virus-Checked header is now added to mail when it is virus scanned |
(internal|external) |
77 |
- sa-update is now run daily to download the latest SpamAssassin rules |
- New feature now allows a "catch all" situation where you have the ability |
78 |
- The "freshclam: Update failed" mail now shows the recent history of |
to redirect "@virtualdomain1.com" to user "joe". |
79 |
the freshclam update process |
- Fix the "Ugly" log messages (Use of uninitialized value) when spam checking |
80 |
- The mail server now defers delivery if clamd is unavailable |
results in 0 hits. |
81 |
- Clamd and spamassassin have been updated to the latest releases |
- Emails sent to a null address like ""@domain without the username part |
82 |
|
are now rejected. |
83 |
Other mail system changes |
- qplogsumm is a optional feature that should be disabled by default. |
84 |
------------------------- |
- A request that the log information is reduced with the default loglevel |
85 |
- Attempts to mail to invalid users now show "Relaying denied" |
setting of 6 in qpsmtpd. |
86 |
instead of "Invalid recipient" |
- Support for sending mail to ISP via Secure SMTP |
87 |
- The qpsmtpd "terse" log plugin is now used, which results in a single |
- Enable the auth plugin for local lan connections |
88 |
line summarising each mail |
- Migrate (remove) "ordb.net" from the RBL lists to prevent mail bouncing. |
89 |
- The qplogsumm.pl tool has been added, which generates mail system |
- Remove blackhole.securitysage.com as service no longer in use. |
90 |
plugin statistics in /var/log/qpsmtpd/state |
- Remove sbl-xbl.spamhaus.org from default lists and use a more improved |
91 |
- The DNS blacklist plugin would occasionally return "False positive" |
list in zen.spamhaus.org. |
92 |
results for multiple overlapping requests. This has been corrected. |
|
93 |
- It is now possible to tune the memory limit for qpsmtpd |
Console |
94 |
|
------- |
95 |
Disk redundancy |
- Improved validation will check password on first enter password screen |
96 |
--------------- |
before verifying if too simple then asking to verify and proceed to |
97 |
- The default disk layout has changed. A hot spare drive is |
configuration of server. |
98 |
automatically created if the system has more than three drives. |
- Passwords should be validated for strength on first entry rather than |
99 |
A new boot option "nospare" has been added if you are certain that |
waiting for the second confirmation entry. |
100 |
you do not want to create the spare. You should only use this option |
- The console should validate passwords using the common method, |
101 |
if you are aware of the consequences of running without a hot spare. |
using esmith::util::validatePassword |
102 |
- Errors from add_drive_to_raid are now displayed in the console |
- The last item in the server console, "Exit from server console", is removed |
103 |
- Adding drives with invalid partition tables now works without a reboot |
as it is redundant. |
104 |
- Attempts to manually add RAID devices to systems without RAID shows an error |
- Display frames in console server-manager. |
105 |
|
When browsing server-manager through console pressing 'H' goes to |
106 |
Remote Access |
http://localhost/server-manager |
|
------------- |
|
|
- It is now possible to set the TCP port for SSH sessions from the |
|
|
Remote Access panel. Note: Changing this port affects SSH, SFTP and SCP |
|
|
- Issues with SFTP remote access have been corrected |
|
|
- Users can be assigned fixed IP addresses with PPTP |
|
|
db accounts setprop fredfrog PPTPIP 192.168.1.5 |
|
|
signal-event remoteaccess-update |
|
|
- The PPTP link timeout has been increased to better handle unreliable links |
|
|
- PPTP has been upgraded to the latest release |
|
107 |
|
|
108 |
Backups |
Backups |
109 |
------- |
------- |
110 |
- USB backup and restore has been added to the console |
- Backups now use dar which allows for daily full or incremental backup |
111 |
- The tape reminder mail can now be sent to a user other than admin |
- Removed 'restore from desktop' functionality |
112 |
config setprop backup reminderEmail fredfrog |
- The error codes from tar are now logged, in line with flexbackup, and do not |
113 |
- Backup to desktop no longer affects the BackupType set for tape backups |
cause a backup to fail. |
114 |
- Restores of MySQL databases with binary 'blobs' up to 16MB are now |
- A Iomeage USB REV-drive was by default mounted in /media as a cdrom device. |
115 |
supported by default (previous was 1MB). To change the setting: |
It is now automagically mounted as an usbdisk so it can be used as a backup |
116 |
config setprop mysqld MaxAllowedPacket 20MB |
device without manual intervention. |
117 |
|
|
118 |
Localisation |
Localisation |
119 |
------------ |
------------ |
120 |
- Swedish translations have been added |
As part of a major update with translations we have added six new |
121 |
- The Spanish translations have been updated |
languages and made it much easier to add other languages in the |
122 |
- The online manual link now points to the manual in the chosen browser |
future. |
123 |
language, if such a manual exists |
|
124 |
- The en-au and en-nz browser languages are now supported |
We now support the following languages in the server-manager: Danish, |
125 |
|
Dutch, English, French, Greek, German, Hungarian, Indonesian, Italian, |
126 |
|
Portuguese, Slovenian, Spanish and Swedish. |
127 |
|
|
128 |
|
We have made major strides to assist the non-English community by |
129 |
|
using a tool called pootle. This is a web based translation tool that |
130 |
|
will allow new languages to be added and existing languages to be more |
131 |
|
easily maintained. |
132 |
|
|
133 |
|
We have cleaned up a lot of the packages as a part of getting them to |
134 |
|
work with pootle. Another big change as part of this upgrade is the |
135 |
|
switch from ISO-8859-1 (Latin) charset to UTF-8 (Universal) charset, |
136 |
|
this will allow us to support languages that don't use latin |
137 |
|
characters (like Greek). |
138 |
|
|
139 |
|
Other fixes include updated translations for the existing languages. |
140 |
|
|
141 |
Software Installer |
Software Installer |
142 |
------------------ |
------------------ |
143 |
- The pacific.net.au mirror has been added as a mirror location. Many |
- smeextras repository added, it is used for building the installer and ISO |
144 |
thanks to all of our mirrors. |
- The yum-update event now includes the yum-import-keys action to allow |
145 |
- It is possible to limit visibility of updates to specific patterns or |
users to update yum packages and configuration without rebooting, |
146 |
repositories (see http://bugs.contribs.org/show_bug.cgi?id=2416 for details) |
which enables updating when there is a compatibility problem. |
147 |
|
- Correct yum-update-dbs action to adjust yum service properly. |
148 |
|
- The BaseURL property has been removed for repos with mirrorlists. |
149 |
|
- The message "This system is up to date." is displayed if no updates are |
150 |
|
available. |
151 |
|
|
152 |
Webmail |
Webmail |
153 |
------- |
------- |
154 |
- Horde, imp, turbo and ingo have been updated to the latest versions |
- Horde, imp, turbo and ingo have been updated to the latest versions |
155 |
|
- Support the ability to save user kronolith free/busy information to the LDAP |
156 |
Console |
database. |
157 |
------- |
- Servers with a custom template for 110AppRegistryHorde found webmail no |
158 |
- Further validation has been added for the Gateway IP to ensure that |
longer worked. |
159 |
it is on the same network as the External IP address |
- The name of the webmail installation is now configurable. |
160 |
|
To use - config setprop horde Name xxxx ; signal-event email-update. |
161 |
|
|
162 |
Server manager |
Server manager |
163 |
-------------- |
-------------- |
164 |
- The new session-based login to the server-manager now works correctly |
- The name of the log file being viewed via the Server Manager 'View log |
165 |
on servers where port 80 is blocked |
files' is now displayed as the first line. |
166 |
- The user-password panel now correctly enforces the user password policy |
- Disabling the daily update check in the server-manager did not stop the |
167 |
- I-bay assignment when a name appears in Domains and Hostnames and Addresses |
check4updates task sending mail to the server administrator. |
168 |
now gives preference to the domain setting |
- Server-manager > printers > add printer - now advises users to avoid |
169 |
|
certain names and descriptions as this causes printer state to be incorrect. |
170 |
UPS |
- Fix the Unknown heading in server-manager after an update. |
171 |
--- |
- Fix inconsistency within the navigation.xx files which no longer adds extra |
172 |
- More template options are available to support more UPS models |
spaces and newlines in panel headers. |
173 |
(see http://bugs.contribs.org/show_bug.cgi?id=2791 for details) |
- The Anti-virus (ClamAV) panel text was updated to remove the word 'entire' |
174 |
|
as this could be misleading. |
175 |
|
- Allow server-manager to successfully create a one character user account. |
176 |
|
- After adding a user and trying to set password via server-manager or |
177 |
|
user-password using the ";" sign you encountered a "white screen of |
178 |
|
death". This was due to the version of perl-Object-Persistence being used. |
179 |
|
- Remove the last 'pleasewait' message is it’s no longer needed. |
180 |
|
- The button to add a new user in the server-manager was missing due to a |
181 |
|
problem with the free/busy code in usermanager causing the panel to exit. |
182 |
|
|
183 |
Other fixes and updates |
Other fixes and updates |
184 |
----------------------- |
----------------------- |
185 |
- Many changes have been made in preparation for migration to CentOS5 |
- Updated Samba resolves various file sharing problems |
186 |
- We are now using the CentOS 4 php-pear modules instead of our own builds |
- The length of an Ibay name is now configurable via maxIbayNameLength |
187 |
- runit was upgraded to the latest release |
- The Samba "unix extensions" are turned off for Mac compatibility |
188 |
- The runsvctrl command has been replaced by the much simpler 'sv' command |
- radiusd.conf allows support for additional authentication methods |
189 |
- The server-only firewall code now respects UDPPort configuration settings |
- Ability to modify pseudonyms with special characters |
190 |
- The "use client driver" setting in smb.conf was corrected |
- Prevent NameServer being set to current IP of SME Server |
191 |
- An apostrophe in the last name caused aliases to be undeletable |
- Allow support for server side includes for ibays when a directory is |
192 |
- The hostnames description on the Hostnames and Addresses page was corrected |
browsed. |
193 |
- Some log warnings from FormMagick were removed |
- Made mtu/mru settings configurable and default to 1400 |
194 |
- Unused openldap PID files are no longer created |
- Increased the templating in php.ini |
195 |
- Various minor text corrections to the console |
- Fixed timezone detection issues for certain timezones during certificate |
196 |
- The version number has been removed from the installer splash screen |
generation |
197 |
- It is no longer possible to quit form the initial configuration wizard |
- Added support for cciss RAID controller |
198 |
before configuring the system |
- Enable a new feature to allow admin to have own password not shared with |
199 |
- The radius templates have been reorganised to simplify extension |
root. |
200 |
- The templates.metadata settings can now be provided by a directory of files |
- nut is now started after the network to avoid mails to the admin mailbox |
201 |
- templates.metadata now provides an option to delete unwanted expansions |
about lost communication. |
202 |
- The /etc/pam.d/login fragments have been corrected |
- e-smith-openssh contained unused template fragments were removed. |
203 |
- The gauge console widget now allows the --clear action to be optional |
- ibays can now be set as non-browsable (hidden), but accessible via their |
204 |
- The e-smith-service wrapper initscript filename match has been tightened |
UNC. An ibay can be hidden by setting the Browsable property to disabled. |
205 |
- Empty dnscache forwarder entries are ignored |
- Suspicious string scanning (supscan) has been disabled due |
206 |
- The CD no longer says "DVD" in the media check screen |
to being CPU and I/O intensive and prone to producing false positives.. |
207 |
- Many old dungog contribs were incompatible, untested or replaced with |
- The audittool script has been updated to also identify modified events. |
208 |
SME Server 7.x features. These packages are now automatically removed |
- If a custom motd was used this could have been sent with the smolt data, now |
209 |
on upgrades |
only the version from e-smith-release is sent. |
210 |
|
- The wrong URL was shown for the smolt profile, it has been updated to |
211 |
|
http://smolt.contribs.org/ |
212 |
|
- Patch djbdns around TCP bug: http://alkemio.org/dns_transmit-bug.html |
213 |
|
- Change license of djbdns to "Public Domain' - |
214 |
|
http://cr.yp.to/distributors.html |
215 |
|
- Do not display symlinks via ftp. |
216 |
|
- New LPRng where both inbuilt filters as well as smbprint filters work. |
217 |
|
- Resolved false positives that were being reported by rkhunter. |
218 |
|
- Move the clamav scan schedule to the correct crontab file for ease of use. |
219 |
|
- Use yum installonlyn plugin to keep only the last 5 kernels. |
220 |
|
- Change Wpad URL to match system domain to enable the Wpad feature. |
221 |
|
- dnscache will now ignore referrals when in forwardonly mode. |
222 |
|
- On servers with no ibays and less than two users the shadow-copy-rotate |
223 |
|
script would fail. |
224 |
|
- Correct the step-ticker to pool.ntp.org hosts. |
225 |
|
- Hide normally hidden files from view when using roaming profiles. |
226 |
|
- The dungog yum repository has been obsoleted as the packages are in |
227 |
|
smecontribs. |
228 |
|
- When a user is deleted from the server-manager his/her pseudonyms should not |
229 |
|
appear in any configuration file. |
230 |
|
|
231 |
|
|
232 |
|
General features |
233 |
|
================ |
234 |
|
- Based on CentOS 4.7 and all available updates |
235 |
|
|
236 |
|
|
237 |
|
There are a few differnces from previous releases <=7.2 |
238 |
|
======================================================= |
239 |
|
|
240 |
|
After installing for the very first time: |
241 |
|
----------------------------------------- |
242 |
|
- First night you may receive an email from cron about sa_updates. |
243 |
|
- First night you should receive a large email saying a bunch of |
244 |
|
groups/users were removed/added (rkhunter email notification). |
245 |
|
- Any time you change users/groups you will receive an email the next day |
246 |
|
about those changes (rkhunter email notification). |
247 |
|
|
248 |
$Id: README.txt,v 1.16 2006/12/26 22:53:34 gordonr Exp $ |
$Id: README.txt,v 1.20 2008/01/01 17:18:13 slords Exp $ |