























Microsoft is changing the security defaults for Active Directory to eliminate some security vulnerabilities in its protocols. Unfortunately, these new security defaults may disrupt existing FreeNAS/TrueNAS deployments once Windows systems are updated. The Windows updates may appear sometime in March 2020; no official date has been announced as of yet.
FreeNAS and TrueNAS users that utilize Active Directory should update to version 11.3 (or 11.2-U8) to avoid potential disruption of their networks when updating to the latest versions of Windows software after March 1, 2020. Version 11.3 has been released and version 11.2-U8 will be available in early March.
Full details are available in this iXsystems Technical Note about LDAP channel binding and LDAP signing.
Users not using Active Directory are unaffected by these Microsoft updates and therefore can update their FreeNAS and TrueNAS systems at their leisure.
SMB Sharing on FreeNAS and TrueNAS
FreeNAS and TrueNAS are used to provide SMB shares in over 80% of deployments. Windows, Mac, and now Linux clients use SMB to share files. In many cases, SMB3 is preferred to NFSv3 and includes some file integrity advantages because the client behavior is well defined. SMB clients gain the advantages of the highly robust OpenZFS file system and all the replication and administration tools that FreeNAS and TrueNAS provide.
SMB3 is usually deployed in organizations with Active Directory to manage user authentication and permissions. All Windows Servers and FreeNAS/TrueNAS units can be configured to use the same security control.
FreeNAS and TrueNAS Release 11.3
The good news is that version 11.3 includes many improvements to SMB and Active Directory support beyond the compatibility with the new Microsoft security patches:
Please contact us if we can help you with your next SMB server deployments.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。