Samba 4.25.0rc2 Lands With Experimental SMB3 Persistent Handles, Cluster Overhaul, and AES-Only Kerberos

Published by

Samba 4.25.0rc2 has been released with experimental SMB3 Persistent Handles aimed at providing transparent failover and continuous availability for clustered Linux file servers, albeit with limitations that restrict its use to SMB-exclusive access. The update also strengthens Kerberos encryption by making AES-only the default for higher functional domains and introduces new cluster functional levels for easier upgrades. Additionally, it includes various bug fixes related to DNS handling, audit logging, and improved coordination of rate limits across clusters. As this release is still a candidate for testing rather than a production build, users are advised to verify the download and track any blocking bugs before the final version is released



Samba 4.25.0rc2 Lands With Experimental SMB3 Persistent Handles, Cluster Overhaul, and AES-Only Kerberos

Samba 4.25.0rc2 introducing experimental SMB3 Persistent Handles designed to enable transparent failover and continuous availability for clustered Linux file servers. Enabling the feature forces SMB-exclusive share access and disables POSIX interop, so it remains strictly reserved for workloads like clustered databases where application-level reopen times are unacceptable. The release also hardens the Kerberos KDC to AES-only encryption by default for domains at functional level 2008 or higher to close CVE-2026-20833, while bundling new cluster functional levels for controlled rolling upgrades and a raft of DNS and audit logging fixes. It remains a testing candidate rather than a production build, so you will want to verify the tarballs with GnuPG and track blocking bugs on the Samba wiki before the final 4.25 ships.

Samba 4.25.0rc2 Lands With Experimental SMB3 Persistent Handles, Cluster Overhaul, and AES-Only Kerberos @ Linux Compatible