/[smeserver]/cdrom.image/sme8/README.txt
ViewVC logotype

Diff of /cdrom.image/sme8/README.txt

Parent Directory Parent Directory | Revision Log Revision Log | View Revision Graph Revision Graph | View Patch Patch

Revision 1.9 by wellsi, Sun Sep 25 17:53:32 2011 UTC Revision 1.21 by wellsi, Sun Oct 6 15:40:54 2013 UTC
# Line 1  Line 1 
1  SME Server 8.0 Beta 7 Release Notes  SME Server 8.1Beta2 Release Notes
2  ===================================  ============================
3    
4  DATE TBD  10 October 2013
5    
6  The SME Server development team is pleased to announce the release of  The SME Server development team is pleased to announce the release of
7  SME Server 8.0beta7 which is based on CentOS 5.6 and will be the next  SME Server 8.1 Beta 2 which is based on CentOS 5.9
 major release of SME Server. This is the final planned Beta for SME 8.  
8    
9  Bug reports and reports of potential bugs should be raised in the bug  Bug reports and reports of potential bugs should be raised in the bug
10  tracker (and only there, please);  tracker (and only there, please);
11    
12      http://bugs.contribs.org/      http://bugs.contribs.org/
13    
 ***************************  
 Testers Please Note the following...  
   
 1. SME Server users should not upgrade production servers to this  
    release but those who can are encouraged to load the beta to a  
    dedicated test machine and take part in the testing phase.  
   
 2. CentOS 5 has dropped support for i586 and therefore SME Server 8  
    will not work on i586 hardware. [See bugzilla:2845]. i586 hardware  
    means processors before and including Intel Pentium, Pentium MMX;  
    AMD K5, K6, K6-II, K6-III and Via C3. i686 architecture processors  
    are Intel Pentium Pro, Pentium II, Pentium III; AMD Athlon,  
    Athlon XP and later.  
   
 3. Upgrading from previous releases should only be done on clean  
    machines without contribs or other modifications.  
   
 4. Testers are now encouraged to test upgrade paths and to start testing  
    contribs. They are not certain to work so only try on test servers.  
    Please raise all issues found in the bug tracker.  
   
 5. Some notes on on SME 8 including help on upgrades can be found at  
    http://wiki.contribs.org/SME_Server_8  
   
 6. Please note it may take up to 48 hours for mirrors to finish syncing,  
    during this time you may experience problems.  
    You can download SME8.0 Beta 7 from  
    http://mirror.contribs.org/smeserver/releases/testing/8/iso/i386/  
    or for other methods see http://wiki.contribs.org/SME_Server_8  
   
 ***************************  
   
14  About SME Server  About SME Server
15  ================  ================
16    
# Line 64  Thanks and a plea for help Line 31  Thanks and a plea for help
31  ==========================  ==========================
32    
33  The development team would like to thank all of those who have involved  The development team would like to thank all of those who have involved
34  themselves with this beta release. At this stage in development the role  themselves with this release.
35  of testers is vital; the final release date and the stability and  
36  quality of the new version depend on full and thorough testing by all  Notes
37  levels of users, right from beginners who may be confused by, and draw  =====
38  the developers attention to, insufficiently transparent system design,  
39  up to seasoned and skilled users who can probe the system deeply. Bug  1. CentOS 5 has dropped support for i586 and therefore SME Server 8.1
40  triage and verification testing needs lots of community involvement;     will not work on i586 hardware. [See bugzilla:2845]. i586 hardware
41  please try to spare some time to this vital aspect of our community's     means processors before and including Intel Pentium, Pentium MMX;
42  future.     AMD K5, K6, K6-II, K6-III and Via C3. i686 architecture processors
43       are Intel Pentium Pro, Pentium II, Pentium III; AMD Athlon,
44  This release, which is based on a major update of the Centos Core,     Athlon XP and later.
45  contains many new features. Please run Software Installer in Server  
46  Manager regularly during testing to be sure your system reflects the  2. Some notes on SME 8.1 including help on upgrades can be found at
47  latest stage of development.     http://wiki.contribs.org/SME_Server_8
48    
49    3. Please note it may take up to 48 hours for mirrors to finish syncing,
50       during this time you may experience problems.
51       You can download SME8.1 from
52       http://mirror.contribs.org/smeserver/releases/testing/8/iso/i386/
53       or for other methods see http://wiki.contribs.org/SME_Server_8
54    
55    
56    Changes from Beta 1
57    ===================
58    
59    nodmraid is now the default install option as many issues have been seen with dmraid.
60    Installer warning updated to clarify all attached disks will be reformatted.
61    SME Server changes to initscripts included.
62    
 Major changes in beta 7  
 =======================  
 * Require authentication for all emails, including local.  
 * Use ext4 instead of ext3 for filesystems (except for /boot). UNDER DISCUSSION  
 * LDAP authentication can be enabled, but is not on by default in this version,  
   once enabled it cannot be disabled, so experiment with care.  
63    
64  Changes in this release  Changes in this release
65  =======================  =======================
66    
67  This section of this README file lists all package changes carried out  Packages altered by Centos, Redhat, and Fedora-associated developers are
68  by SME-associated developers since SME Server 8.0 Beta 6.  not included.
69    
 The package changelogs often included earlier changes and changes  
 carried out by non-SME-associated developers; these were removed to  
 shorten the list. Packages recently altered by Centos, Redhat, and  
 Fedora-associated developers are not included.  
70    
71  Backups  Backups
72  -------  -------
73  - Improve how Backup to Workstation handles full remote disks.  - Workstation Backup allows the day of the week to be specified on which a full backup occurs. This now works correctly for all days of the week.
74  - Localise the choices for 'Select the type of share for backup destination' in  - To increase reliability of backups to a Microsoft Vista drive, a one second delay was added to the backup. This issue is not seen on the newer Microsoft OS.
75    the Configure Workstation Backup panel  - Allow user setting of compression level for Desktop and Console Backups.
76  - Improve the wording of the 'Backup or restore' server-manager panel.    For example: config setprop backupconsole CompressionLevel -6
77    Replace term "USB disk" with "removable disk" as this is not restricted    The default is -6, where -1 is fastest and -9 is optimal compression.
78    to only USB disks.  - In the console, under item 8, refer to removable media instead of USB device.
79  - Improve wording of workstation backup email regarding the set number.    - After a restore from the console the post-upgrade event was not being performed.
80  - Do not modify the workstation backup location 'SmbShare' during software update  - Add an option to use Wake on LAN before starting Workstation Backup.
81  - Include disk usage in Workstation Backup email.  - Workstation Backup, report cifs mount errors.
82  - A new database property, OpenFilesLimit, allows customisation of  - Workstation Backup, be compatible with destinations that include spaces.
83    open_files_limit option in my.cnf. This can allow backups to succeed if a MySQL  - Workstation Backup, remove temporary directory on success .
84    database has a very large number of tables.  - Workstation Backup, add a choice to delete old backup before or after backup.
85    
86  File Server  File Server
87  -----------  -----------
88  - Change separator character in general Samba configuration file.  - Add support for Windows 8 domain joining & user login with a new registry file.
89  - Changes in Samba's "Recycle VFS exclude" syntax (for ibays).    /server-resources/regedit/win8samba.reg
90  - Create samba account during event for machine.  - New optional samba property smb{WideLinks}, valid values are 'no' or 'yes'. The current samba default is 'no'.  
91  - Keep uid/gid for computer accounts in synch for Unix/Samba/LDAP.    see http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#WIDELINKS
92  - Fixed syntax error in create-machine-account.    For example to enable samba Wide Links
93  - Fix samba-group-mapping for users without group membership.    # config setprop smb WideLinks yes
94  - Fix cpu critical patch missing '  - Add windows network performance enhancements registry file that can help Windows slow logons.
95  - LDAP admin password needs to be loaded in secrets.tdb    /server-resources/regedit/windows_samba_performance.reg
96    - Two new optional samba properties smb{ServerMaxProtocol} & smb{ClientMaxProtocol}.
97      For example: # config setprop smb ServerMaxProtocol NT1
98    - Remove the samba_audit specific logrotate configuration which was causing an email to be sent to the admin every night.
99    - Enable smb auditing per ibay, it is disabled by default.
100      Auditing is enabled via
101      # db accounts setprop ibayname Audit enabled
102      # signal-event ibay-modify ibayname
103    - Prevent emailing about the normal, weekly, checks of RAID arrays
104    - Update ServerName (Samba netbios name) when SystemName is updated
105    - Workaround a deficiency in the proftpd package where it does not handle long lines correctly in its configuration file. This caused FTP to fail when large numbers of local networks were configured.
106    - Ensure Deny from all is on its own line in 15LimitLOGIN
107    
108    
109    LDAP (Optional in SME 8.1, and considered experimental)
110    ----
111    - Fix init-account script when LDAP auth is enabled.
112    - Fix group creation/modification when LDAP auth is enabled.
113    - The ldap.init script which starts just after the ldap service waits for slapd to be to available. The logic to check if slapd is ready was corrected.
114    - Add missing dependency on openldap-servers.
115    - The ldap log files can take significant space on servers with a lot of users. This update will ensure old BDB log files are removed.
116    
117    
118  Localisation  Localisation
119  ------------  ------------
120  - Latest localisation updates applied.  - Latest translations included.
121    
122    
123  Mail Server  Mail Server
124  -----------  -----------
125  - Require SMTP authentication by default when sending to an external address.  - Fetchmail multidrop mode follows TCPPort setting.
126  - Fix TLS security defaults, TLS Ciphers for qpsmtpd can be configured.  - Avoid use of unitialised variables in smtp migrate fragments.
127  - Change enabled to transparent for mail proxy.  - Allow smtp_auth_proxy to use port 587 with STARTTLS.
128  - Enable authentication for smtp traffic and migrate if necessary.  - Due to SMTP servers not handling SMTP Auth well enable the use of a blacklist to remove the troublesome methods.
129  - Fix pseudonym modification for "local network only" accounts.      For example to remove CRAM-MD5:
130  - Add smtp auth into web interface, not just when enabled.    # db configuration setprop smtp-auth-proxy Blacklist CRAM-MD5
131  - Fix require_resolvable_fromhost doesn't work    # sv t /service/smtp-auth-proxy
132  - Fix qpsmtpd plugin fatal errors when incoming mail message has no headers.    More than one method can be removed:
133  - Serialize configure_peers to prevent errors.    # db configuration setprop smtp-auth-proxy Blacklist "CRAM-MD5 DIGEST-MD5"
134  - Change authentication from passwd/shadow files to the pam database.    # sv t /service/smtp-auth-proxy
135  - New feature: Allow for individual configuration for the number of qmail  - imap-relocate-maildirs action was removed.It was no longer necessary and was sometimes very slow.
136    logfiles.  - The soft memory limits for pop3 and pop3s were increased. Two new optional database properties pop3{MemLimit} and pop3s{MemLimit}
137      For example to increase the memory limit
138      # config setprop pop3s MemLimit 50000000
139      # expand-template /var/service/pop3s/env/MEMLIMIT
140      # config setprop pop3 MemLimit 50000000
141      # expand-template /var/service/pop3/env/MEMLIMIT
142    - New optional qmail property qmail{ConcurrencyLocal} and default for /var/qmail/control/concurrencylocal changed to 20.
143      For example to decrease the local concurrecny limit
144      # config setprop qmail ConcurrencyLocal 6
145    - Modify domain style pseudonym pointing to user with dot in name.
146    - Accept messages with no body and no trailing \n after headers.
147    - Prevent email delivery failure with required updates for perl-Net-DNS and qpsmtpd.
148    - New optional spamassassin property spamassassin{MaxMessageSize} to allow for spamassassin qpsmtpd's plugin size limit to be changed.
149      For example to also scan larger files
150      # config setprop spamassassin MaxMessageSize 1500000
151    - Make CipherSuite secure by default and tls ciphers defaults to disallow SSLv2.
152    - Fix how qpsmtpd tags spam email.
153    - Add template to extend the functionality of SSL verified certificate to IMAP and SSMTP transactions
154    - Update ClamAV to release 0.97.8.
155    - Load TextCat plugin if ok_languages is enabled.
156    
157    
158  Server manager  Server manager
159  --------------  --------------
160  - Enhance IP address syntax checking in remote access panel.  - Do not load mod_ssl for httpd-admin as it is not needed and creates log noise.
161    - If the browser used to access the server-manager used lower case for %escapes a blank screen would be shown. The server manager URL processing is now case-insensitive for %escapes.
162    - Fix more uninitialized warnings in log (httpd/admin_error_log) from HTML.pm.
163    - Remove log noise (httpd/admin-error-log) when accessing the Create Starter Web panel in server-manager
164    
165    
166  Webmail and Groupware  Webmail and Groupware
167  ---------------------  ---------------------
168  - Update to Horde 3.3.11, imp 4.3.9, Ingo 1.2.5 & Turba 2.3.5  
169  - Add option to verify from address in webmail if setting up additional  - If IMAP is disabled in the server manager email panel, IMAP will now listen to the loopback interface to allow webmail to function.
170    identities.  - Webmail no longer uses SSL over loopback interface.
171  - Turba searches on LDAP address book fixed.  
172    
173  Web Server  Web Server
174  ----------  ----------
175  - Disable SSLv2 by default.  - Disable index listing of Apache icons folder.
176  - make user 'apache' an alias for user 'www'.  - PHP's magic_quotes are deprecated so should no longer be used. The php.ini will now have "magic_quotes Off" instead of fully removing it as the default is ON.
177    - Change wording of Software Update button.
178    
179    
180  Other fixes and updates  Other fixes and updates
181  -----------------------  -----------------------
182  - Use ext4 instead of ext3 for filesystems (except for /boot)  - Remove old System Name from the Hosts DB
183  - Properly handle account with accents in first- or lastname with regards to LDAP.  - Fix warning in /var/log/messages by correctly initialising the relevant variable. The warning related to the HW Address of a NIC.
184  - Only allow backup to (removable) storage media that are not read only.  - user-modify-unix script could take many minutes, it has now been optimised to take only seconds
185  - Improve error handling when trying to install without NIC.  - The memory limit for pppoe was increased to 100Mb.
186  - Only remove dangling symlinks in weak-updates directories.  - On upgrading from SME Server 7 to SME Server 8 an email could be sent to the admin everyday due to a modified /etc/updatedb.conf file. This update ensures the correct /etc/updatedb.conf file.
187  - Fix create user gid parameter.  - Updated SME root server template as D-root changed its IPv4 address on the 3rd of January.
188  - Path for gpasswd command fixed in "init-accounts" script.  - The console would crash when no value is entered as static gateway in servergateway(-private) mode. Improved error-checking in isValidIP() prevents this.
189  - Fix template-expansion for dhclient.conf.  - Use file locking to make sure that only one copy of the masq script is running at any particular time.
190  - Improve validation (error) message for remote access setup.  - Add python-hashlib so we can read newer repodata signatures.
191  - Change text in hostname and addresses panel for remote host (add FQDN).  - Point mirrorlist to mirrorlist.contribs.org
192  - Fix hostname editing for comments with double speechmarks  - Increase memory limit for ntpd .
 - Trap croak inside Net::IPv4Addr::ipv4_in_network to allow a FQDN to be inserted  
   in hostnames and addresses panel in lieu of an IP address.  
 - Add validator back for ip or cname entry.  
 - All ibay account commands as system accounts in LDAP.  
 - Create ibay accounts as system accounts in LDAP.  
 - Use cpu commands to manage Ibays accounts if ldap is master.  
 - Make cpu calls critical only with ldap{Auth} is enabled.  
 - Check slapd.conf syntax before trying to dump the database.  
 - Simplify ldap-update call by calling ldif-fix  
 - Change script order: ldap-update should be called after domain-group-maps.  
 - LDAP ou field is taken from Dept not Department.  
 - LDAP chnages: Add rfc2739.schema back in and include in config.  
 - Use ldapmodify to load ldif, add -a if no changetype.  
 - Remove bogus junk attribute from ldif templates.  
 - Change startup order for ldap.  
 - ldap should store locked passwords for expired passwords.  
 - Correctly strip numbers from sql scripts  
 - Enable speedier time synchronisation for suspended VMs, this can be configured  
   by a new db key for ntpd, SupportLargeDrift.  
 - Obsolete KeepAlive and replace by ClientAliveInterval and ClientAliveCountMax  
   to prevent SSH sessions from being timed out by network inactivity.  
 - New feature: Default Cipher to blowfish for ssh configuration.  
 - Add directive "PersistentPasswd off" to proftpd configuration.  
 - Quota panel should allow non-integers but only accept uppercase units.  
 - Enable quotas on ext4 filesystems as well.  
 - Add ldap as an auth type to radius  
 - Radius should use LDAP backend (if LDAP auth is enabled).  
193    
194  General features  General features
195  ================  ================
196    
197  - Based on CentOS 5.6 and all available updates  - Based on CentOS 5.9 and all available updates
198    
199    $Id: README.txt,v 1.20 2013/09/27 14:47:02 wellsi Exp $
200    
201    
 $Id: README.txt,v 1.7 2010/07/15 07:58:07 wellsi Exp $  
202    


Legend:
Removed lines/characters  
Changed lines/characters
  Added lines/characters

admin@koozali.org
ViewVC Help
Powered by ViewVC 1.2.1 RSS 2.0 feed