/[smeserver]/cdrom.image/sme8/README.txt
ViewVC logotype

Diff of /cdrom.image/sme8/README.txt

Parent Directory Parent Directory | Revision Log Revision Log | View Revision Graph Revision Graph | View Patch Patch

Revision 1.10 by wellsi, Thu Sep 29 06:11:45 2011 UTC Revision 1.21 by wellsi, Sun Oct 6 15:40:54 2013 UTC
# Line 1  Line 1 
1  SME Server 8.0 Beta 7 Release Notes  SME Server 8.1Beta2 Release Notes
2  ===================================  ============================
3    
4  30 September 2011  10 October 2013
5    
6  The SME Server development team is pleased to announce the release of  The SME Server development team is pleased to announce the release of
7  SME Server 8.0beta7 which is based on CentOS 5.7 and will be the next  SME Server 8.1 Beta 2 which is based on CentOS 5.9
 major release of SME Server. This is the final planned Beta for SME 8.  
8    
9  Bug reports and reports of potential bugs should be raised in the bug  Bug reports and reports of potential bugs should be raised in the bug
10  tracker (and only there, please);  tracker (and only there, please);
11    
12      http://bugs.contribs.org/      http://bugs.contribs.org/
13    
 ***************************  
 Testers Please Note the following...  
   
 1. SME Server users should not upgrade production servers to this  
    release but those who can are encouraged to load the beta to a  
    dedicated test machine and take part in the testing phase.  
   
 2. CentOS 5 has dropped support for i586 and therefore SME Server 8  
    will not work on i586 hardware. [See bugzilla:2845]. i586 hardware  
    means processors before and including Intel Pentium, Pentium MMX;  
    AMD K5, K6, K6-II, K6-III and Via C3. i686 architecture processors  
    are Intel Pentium Pro, Pentium II, Pentium III; AMD Athlon,  
    Athlon XP and later.  
   
 3. Some notes on SME 8 including help on upgrades can be found at  
    http://wiki.contribs.org/SME_Server_8  
   
 4. Upgrading from previous releases should only be done on clean  
    machines without contribs or other modifications.  
   
 5. Testers are now encouraged to test upgrade paths and to start testing  
    contribs. They are not certain to work so only try on test servers.  
    Please raise all issues found in the bug tracker.  
   
 6. Please note it may take up to 48 hours for mirrors to finish syncing,  
    during this time you may experience problems.  
    You can download SME8.0 Beta 7 from  
    http://mirror.contribs.org/smeserver/releases/testing/8/iso/i386/  
    or for other methods see http://wiki.contribs.org/SME_Server_8  
   
 ***************************  
   
14  About SME Server  About SME Server
15  ================  ================
16    
# Line 64  Thanks and a plea for help Line 31  Thanks and a plea for help
31  ==========================  ==========================
32    
33  The development team would like to thank all of those who have involved  The development team would like to thank all of those who have involved
34  themselves with this beta release. At this stage in development the role  themselves with this release.
35  of testers is vital; the final release date and the stability and  
36  quality of the new version depend on full and thorough testing by all  Notes
37  levels of users, right from beginners who may be confused by, and draw  =====
38  the developers attention to, insufficiently transparent system design,  
39  up to seasoned and skilled users who can probe the system deeply. Bug  1. CentOS 5 has dropped support for i586 and therefore SME Server 8.1
40  triage and verification testing needs lots of community involvement;     will not work on i586 hardware. [See bugzilla:2845]. i586 hardware
41  please try to spare some time to this vital aspect of our community's     means processors before and including Intel Pentium, Pentium MMX;
42  future.     AMD K5, K6, K6-II, K6-III and Via C3. i686 architecture processors
43       are Intel Pentium Pro, Pentium II, Pentium III; AMD Athlon,
44  This release, which is based on a major update of the Centos Core,     Athlon XP and later.
45  contains many new features. Please run Software Installer in Server  
46  Manager regularly during testing to be sure your system reflects the  2. Some notes on SME 8.1 including help on upgrades can be found at
47  latest stage of development.     http://wiki.contribs.org/SME_Server_8
48    
49    3. Please note it may take up to 48 hours for mirrors to finish syncing,
50       during this time you may experience problems.
51       You can download SME8.1 from
52       http://mirror.contribs.org/smeserver/releases/testing/8/iso/i386/
53       or for other methods see http://wiki.contribs.org/SME_Server_8
54    
55    
56    Changes from Beta 1
57    ===================
58    
59    nodmraid is now the default install option as many issues have been seen with dmraid.
60    Installer warning updated to clarify all attached disks will be reformatted.
61    SME Server changes to initscripts included.
62    
 Major changes in beta 7  
 =======================  
 * Require authentication for all emails, including local.  
 * Optional - to use ext4 instead of ext3 for file systems  
   (except for /boot). At the boot prompt use "ext4" or "sme ext4".  
   *** ext4 is considered experimental, so use with caution ***  
 * Optional - LDAP authentication can be enabled. Once enabled it cannot  
   be disabled, so experiment with care.  
   To enable: db configuration setprop ldap Authentication enabled  
63    
64  Changes in this release  Changes in this release
65  =======================  =======================
66    
67  This section of this README file lists all package changes carried out  Packages altered by Centos, Redhat, and Fedora-associated developers are
68  by SME-associated developers since SME Server 8.0 Beta 6.  not included.
69    
 The package changelogs often included earlier changes and changes  
 carried out by non-SME-associated developers; these were removed to  
 shorten the list. Packages recently altered by Centos, Redhat, and  
 Fedora-associated developers are not included.  
70    
71  Backups  Backups
72  -------  -------
73  - Improve how Backup to Workstation handles full remote disks.  - Workstation Backup allows the day of the week to be specified on which a full backup occurs. This now works correctly for all days of the week.
74  - Do not make backup fail when due to a modified file.  - To increase reliability of backups to a Microsoft Vista drive, a one second delay was added to the backup. This issue is not seen on the newer Microsoft OS.
75  - Localise the choices for 'Select the type of share for backup  - Allow user setting of compression level for Desktop and Console Backups.
76    destination' in the Configure Workstation Backup panel.    For example: config setprop backupconsole CompressionLevel -6
77  - Improve the wording of the 'Backup or restore' server-manager panel.    The default is -6, where -1 is fastest and -9 is optimal compression.
78    Replace term "USB disk" with "removable disk" as this is not  - In the console, under item 8, refer to removable media instead of USB device.
79    restricted to only USB disks.  - After a restore from the console the post-upgrade event was not being performed.
80  - Improve wording of workstation backup email regarding the set number.  - Add an option to use Wake on LAN before starting Workstation Backup.
81  - Do not modify the workstation backup location 'SmbShare' during  - Workstation Backup, report cifs mount errors.
82    software update.  - Workstation Backup, be compatible with destinations that include spaces.
83  - Include disk usage in Workstation Backup email.  - Workstation Backup, remove temporary directory on success .
84  - A new database property, OpenFilesLimit, allows customisation of  - Workstation Backup, add a choice to delete old backup before or after backup.
   open_files_limit option in my.cnf. This can allow backups to succeed  
   if a MySQL database has a very large number of tables.  
85    
86  File Server  File Server
87  -----------  -----------
88  - Change separator character in general Samba configuration file.  - Add support for Windows 8 domain joining & user login with a new registry file.
89  - Changes in Samba's "Recycle VFS exclude" syntax (for ibays).    /server-resources/regedit/win8samba.reg
90    - New optional samba property smb{WideLinks}, valid values are 'no' or 'yes'. The current samba default is 'no'.  
91      see http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#WIDELINKS
92      For example to enable samba Wide Links
93      # config setprop smb WideLinks yes
94    - Add windows network performance enhancements registry file that can help Windows slow logons.
95      /server-resources/regedit/windows_samba_performance.reg
96    - Two new optional samba properties smb{ServerMaxProtocol} & smb{ClientMaxProtocol}.
97      For example: # config setprop smb ServerMaxProtocol NT1
98    - Remove the samba_audit specific logrotate configuration which was causing an email to be sent to the admin every night.
99    - Enable smb auditing per ibay, it is disabled by default.
100      Auditing is enabled via
101      # db accounts setprop ibayname Audit enabled
102      # signal-event ibay-modify ibayname
103    - Prevent emailing about the normal, weekly, checks of RAID arrays
104    - Update ServerName (Samba netbios name) when SystemName is updated
105    - Workaround a deficiency in the proftpd package where it does not handle long lines correctly in its configuration file. This caused FTP to fail when large numbers of local networks were configured.
106    - Ensure Deny from all is on its own line in 15LimitLOGIN
107    
108    
109  LDAP (Optional in SME 8, and considered experimental)  LDAP (Optional in SME 8.1, and considered experimental)
110  ----  ----
111  - Create samba account during event for machine.  - Fix init-account script when LDAP auth is enabled.
112  - Keep uid/gid for computer accounts in synch for Unix/Samba/LDAP.  - Fix group creation/modification when LDAP auth is enabled.
113  - Fixed syntax error in create-machine-account.  - The ldap.init script which starts just after the ldap service waits for slapd to be to available. The logic to check if slapd is ready was corrected.
114  - Fix samba-group-mapping for users without group membership.  - Add missing dependency on openldap-servers.
115  - Fix cpu critical patch missing '  - The ldap log files can take significant space on servers with a lot of users. This update will ensure old BDB log files are removed.
116  - LDAP admin password needs to be loaded in secrets.tdb  
 - Change authentication from passwd/shadow files to the pam database.  
 - Turba searches on LDAP address book fixed.  
 - Properly handle account with accents in first- or lastname with  
   regards to LDAP.  
 - Fix create user gid parameter.  
 - Path for gpasswd command fixed in "init-accounts" script.  
 - All ibay account commands as system accounts in LDAP.  
 - Create ibay accounts as system accounts in LDAP.  
 - Use cpu commands to manage Ibays accounts if ldap is master.  
 - Make cpu calls critical only with ldap{Auth} is enabled.  
 - Check slapd.conf syntax before trying to dump the database.  
 - Simplify ldap-update call by calling ldif-fix  
 - Change script order: ldap-update should be called after  
   domain-group-maps.  
 - LDAP ou field is taken from Dept not Department.  
 - LDAP changes: Add rfc2739.schema back in and include in config.  
 - Use ldapmodify to load ldif, add -a if no changetype.  
 - Remove bogus junk attribute from ldif templates.  
 - Change startup order for ldap.  
 - ldap should store locked passwords for expired passwords.  
 - Add ldap as an auth type to radius  
 - Radius should use LDAP backend (if LDAP auth is enabled).  
117    
118  Localisation  Localisation
119  ------------  ------------
120  - Latest localisation updates applied.  - Latest translations included.
121    
122    
123  Mail Server  Mail Server
124  -----------  -----------
125  - Require SMTP authentication by default when sending to an external  - Fetchmail multidrop mode follows TCPPort setting.
126    address.  - Avoid use of unitialised variables in smtp migrate fragments.
127  - Fix TLS security defaults, TLS Ciphers for qpsmtpd can be configured.  - Allow smtp_auth_proxy to use port 587 with STARTTLS.
128  - Change enabled to transparent for mail proxy.  - Due to SMTP servers not handling SMTP Auth well enable the use of a blacklist to remove the troublesome methods.
129  - Enable authentication for smtp traffic and migrate if necessary.    For example to remove CRAM-MD5:
130  - Fix pseudonym modification for "local network only" accounts.    # db configuration setprop smtp-auth-proxy Blacklist CRAM-MD5
131  - Add smtp auth into web interface, not just when enabled.    # sv t /service/smtp-auth-proxy
132  - Fix require_resolvable_fromhost doesn't work    More than one method can be removed:
133  - Fix qpsmtpd plugin fatal errors when incoming mail message has no    # db configuration setprop smtp-auth-proxy Blacklist "CRAM-MD5 DIGEST-MD5"
134    headers.    # sv t /service/smtp-auth-proxy
135  - Serialize configure_peers to prevent errors.  - imap-relocate-maildirs action was removed.It was no longer necessary and was sometimes very slow.
136  - Fix SMTP proxy wording in server-manager.  - The soft memory limits for pop3 and pop3s were increased. Two new optional database properties pop3{MemLimit} and pop3s{MemLimit}
137  - Fix SMTP auth wording in server-manager.    For example to increase the memory limit
138  - New feature: Allow for individual configuration for the number of    # config setprop pop3s MemLimit 50000000
139    mail logfiles.    # expand-template /var/service/pop3s/env/MEMLIMIT
140      # config setprop pop3 MemLimit 50000000
141      # expand-template /var/service/pop3/env/MEMLIMIT
142    - New optional qmail property qmail{ConcurrencyLocal} and default for /var/qmail/control/concurrencylocal changed to 20.
143      For example to decrease the local concurrecny limit
144      # config setprop qmail ConcurrencyLocal 6
145    - Modify domain style pseudonym pointing to user with dot in name.
146    - Accept messages with no body and no trailing \n after headers.
147    - Prevent email delivery failure with required updates for perl-Net-DNS and qpsmtpd.
148    - New optional spamassassin property spamassassin{MaxMessageSize} to allow for spamassassin qpsmtpd's plugin size limit to be changed.
149      For example to also scan larger files
150      # config setprop spamassassin MaxMessageSize 1500000
151    - Make CipherSuite secure by default and tls ciphers defaults to disallow SSLv2.
152    - Fix how qpsmtpd tags spam email.
153    - Add template to extend the functionality of SSL verified certificate to IMAP and SSMTP transactions
154    - Update ClamAV to release 0.97.8.
155    - Load TextCat plugin if ok_languages is enabled.
156    
157    
158  Server manager  Server manager
159  --------------  --------------
160  - Enhance IP address syntax checking in remote access panel.  - Do not load mod_ssl for httpd-admin as it is not needed and creates log noise.
161    - If the browser used to access the server-manager used lower case for %escapes a blank screen would be shown. The server manager URL processing is now case-insensitive for %escapes.
162    - Fix more uninitialized warnings in log (httpd/admin_error_log) from HTML.pm.
163    - Remove log noise (httpd/admin-error-log) when accessing the Create Starter Web panel in server-manager
164    
165    
166  Webmail and Groupware  Webmail and Groupware
167  ---------------------  ---------------------
168  - Update to Horde 3.3.11, imp 4.3.9, Ingo 1.2.5 & Turba 2.3.5  
169  - Add option to verify from address in webmail if setting up additional  - If IMAP is disabled in the server manager email panel, IMAP will now listen to the loopback interface to allow webmail to function.
170    identities.  - Webmail no longer uses SSL over loopback interface.
171    
172    
173  Web Server  Web Server
174  ----------  ----------
175  - Disable SSLv2 by default.  - Disable index listing of Apache icons folder.
176  - make user 'apache' an alias for user 'www'.  - PHP's magic_quotes are deprecated so should no longer be used. The php.ini will now have "magic_quotes Off" instead of fully removing it as the default is ON.
177    - Change wording of Software Update button.
178    
179    
180  Other fixes and updates  Other fixes and updates
181  -----------------------  -----------------------
182  - Option to select ext4 instead of ext3 for filesystems at boot prompt  - Remove old System Name from the Hosts DB
183  - Enable quotas on ext4 filesystems as well.  - Fix warning in /var/log/messages by correctly initialising the relevant variable. The warning related to the HW Address of a NIC.
184  - Only allow backup to (removable) storage media that are not read only.  - user-modify-unix script could take many minutes, it has now been optimised to take only seconds
185  - Improve error handling when trying to install without NIC.  - The memory limit for pppoe was increased to 100Mb.
186  - Only remove dangling symlinks in weak-updates directories.  - On upgrading from SME Server 7 to SME Server 8 an email could be sent to the admin everyday due to a modified /etc/updatedb.conf file. This update ensures the correct /etc/updatedb.conf file.
187  - Fix template-expansion for dhclient.conf.  - Updated SME root server template as D-root changed its IPv4 address on the 3rd of January.
188  - Improve validation (error) message for remote access setup.  - The console would crash when no value is entered as static gateway in servergateway(-private) mode. Improved error-checking in isValidIP() prevents this.
189  - Change text in hostname and addresses panel for remote host (add  - Use file locking to make sure that only one copy of the masq script is running at any particular time.
190    FQDN).  - Add python-hashlib so we can read newer repodata signatures.
191  - Fix hostname editing for comments with double speechmarks  - Point mirrorlist to mirrorlist.contribs.org
192  - Trap croak inside Net::IPv4Addr::ipv4_in_network to allow a FQDN to be  - Increase memory limit for ntpd .
   inserted in hostnames and addresses panel in lieu of an IP address.  
 - Add validator back for ip or cname entry.  
 - Correctly strip numbers from sql scripts  
 - Enable speedier time synchronisation for suspended VMs, this can be  
   configured by a new db key for ntpd, SupportLargeDrift.  
 - Obsolete KeepAlive and replace by ClientAliveInterval and  
   ClientAliveCountMax to prevent SSH sessions from being timed out by  
   network inactivity.  
 - New feature: Default Cipher to blowfish for ssh configuration.  
 - Add directive "PersistentPasswd off" to proftpd configuration.  
 - Quota panel should allow non-integers but only accept uppercase units.  
 - Obsolete magic_quotes_gpc settings.  
 - Set default timezone for php version 5.3.3.  
193    
194  General features  General features
195  ================  ================
196    
197  - Based on CentOS 5.7 and all available updates  - Based on CentOS 5.9 and all available updates
198    
199    $Id: README.txt,v 1.20 2013/09/27 14:47:02 wellsi Exp $
200    
 $Id: README.txt,v 1.9 2011/09/25 17:53:32 wellsi Exp $  
201    
202    


Legend:
Removed lines/characters  
Changed lines/characters
  Added lines/characters

admin@koozali.org
ViewVC Help
Powered by ViewVC 1.2.1 RSS 2.0 feed