Samba 4.25.0rc1 Launches with SMB3 Persistent Handles, AES Encryption, and Cluster Functional Levels
Samba 4.25.0rc1 has arrived as the first release candidate for the next major version of the Samba file server, bringing a significant suite of new features for clustering and security. The headline addition is experimental SMB3 Persistent Handles, which enable transparent failover for high-availability workloads, alongside a mandatory shift to AES-only domain encryption to address CVE-2026-20833. Clustering receives a new functional level mechanism to facilitate controlled rolling upgrades, while global rate limiting and improved CTDB path management further enhance infrastructure reliability. Keep in mind that the persistent handles feature enforces SMB-exclusive access and disables local POSIX client support on affected shares, so administrators should test these changes carefully before deploying to production.
Samba 4.25.0rc1 Launches with SMB3 Persistent Handles, AES Encryption, and Cluster Functional Levels
Samba 4.25.0rc1 has been released as the first release candidate for the next major version of the Samba file server, introducing new features such as experimental SMB3 Persistent Handles, AES-only domain encryption, and a new clustering functional level mechanism. The persistent handles allow for transparent failover in high-availability workloads, but they enforce SMB-exclusive access and disable local POSIX client support, necessitating careful testing before production deployment. Additionally, the shift to AES-only encryption addresses a known vulnerability, while the new functional level mechanism facilitates controlled rolling upgrades for clusters. Overall, while this release offers significant improvements for high-availability users, the RC status requires thorough testing, especially for environments that utilize mixed share configurations
