Just saw the message below on the Samba mailing list.
Since it impacts Samba/Active Directory and it’s possible and even likely at least one person who’s reading this is running an older version of Windows Server in a VM on their TrueNAS server, I wanted to share it here.
It does sound like it could hit TrueNAS servers acting as “Samba installations acting as member servers in Windows AD domains.”
I"m not really sure if it has implications for TrueNAS directly. It sounds like it’s restricted to environments where Windows Server is the Active Directory domain controller. But I’ve never used AD, so I’m not sure.
From: Ralph Boehme <slow@samba.org>
Subject: [Samba] Important Change in Upcoming Microsoft Update
Date: July 6, 2025 at 6:40:01 AM CDT
To: “samba@lists.samba.org” <samba@lists.samba.org>, samba-technical <samba-technical@lists.samba.org>, samba-announce@lists.samba.orgHi all!
On 8th of July, Microsoft will release an important security update for Active Directory Domain Controllers for Windows Server versions prior to 2025.
This update includes a change to the Microsoft RPC Netlogon protocol, which improves security by tightening access checks for a set of RPC requests. Samba running as domain members in these environments will be impacted by this change if a specific configuration is used, see below for which configuration is affected.
Windows Server version 2025 is already equipped with these specific security hardenings, and Microsoft is now planning to deploy them to all supported Windows Server versions down to Windows Server 2008.
Who is affected?
Samba installations acting as member servers in Windows AD domains will be affected if they are configured to use the ‘ad’ idmapping backend. Samba servers not using this configuration will not be affected by the change – at least to our current knowledge and understanding of the change – and no further action is required.
Current versions of Samba with the affected configuration will no longer function correctly once the Microsoft update has been applied. Users will not be able to connect to the SMB service provided by Samba for any domain configured to use the ‘ad’ idmapping backend.
What the Samba Team is doing and what you should do
Members of the Samba team have been collaborating with Microsoft and changes to Samba are currently being developed and tested to ensure full compatibility between Samba and Microsoft products. The Samba team is aiming to provide updated Samba releases on Monday evening (UTC+2).
What you should do:
If you’re running Samba in a Windows AD environment, check your configuration. Keep an eye out for new Samba package updates early next week (starting 7 July).
References
https://bugzilla.samba.org/show_bug.cgi?id=15876
On behalf of the Samba team
-slow