Changes:

  • Upgraded base distribution to Debian 13.x/Trixie.
  • Samba DNS forwarder now defaults to the host's existing upstream resolver rather than being hardcoded to Google DNS (8.8.8.8)
  • Removed bundled legacy Windows Point-and-Print v3 print drivers; current Windows blocks them by default (post-PrintNightmare) and CUPS ships disabled by default.
  • domain-controller inithook fixes:
    • Keep the administrator password out of firstboot and samba-tool process arguments, console output, and retained command logs.
    • Wait for the newly provisioned Kerberos service before firstboot exits.
    • Report the actual samba error (not a literal "{samba_run_out}") when provisioning fails non-interactively.
    • Validate nameserver IPs strictly (reject partial forms like "8.8").
    • Honour --join_ns as a join request when falling back to interactive mode (previously it could create a new domain instead).
    • Select a single IPv4 from 'hostname -I' for the samba interfaces option and hosts file.
    • Check nameserver reachability via TCP/53 rather than ICMP ping.
    • Fix empty realm-segment validation and assorted dead-code cleanups.
  • Joining domain tested and confirmed working from Windows 11 Pro - 25H2 (OS Build 26200.8875).
  • Replace TurnKey custom Debian-Installer based 'di-live' with new custom TurnKey installer built from scratch; 'tkl-installer'.
  • Updated release signing keys & apt repo keys - now included as 'turnkey-keys' deb package.
  • Replace legacy '.list' apt remote config files with Deb822 '.sources' files.
  • "Proper" IPv6 support. May still have some gaps and still requires cosmetic work but fully functional.
  • Improved fail2ban config:
    • Increased default findtime (10 minutes) & bumped maxretry (3) to minimize risk of user accidentally locking themself out.
    • Removed redundant v18.x custom patches.
  • Include 'zstd' by default to support smaller initramfs that unpacks faster.
  • Replace 'ifupdown' with 'ifupdown-ng' (and 'ifupdown-ng-compat').
  • Replace 'udhcpc' (IPv4 only) with 'dhcpcd-base' (dual stack ipv4/6). Also include custom TurnKey config (if-pre-up & if-post-down scripts provided by 'tkl-dhcpcd-ifupdown-glue') to ensure DHCP config is in sync with /etc/network/interfaces file.
  • General code cleanup of TurnKey code; build code, build tools and TurnKey custom tools & libraries. Updates include linting, formating and style updates. Still WIP but solid start.
  • Configuration console (confconsole):
    • Bugfixes:
      • Support for firewall config when setting a static IP. Particularly affected OpenVPN (which ships with firewall enabled by default). Closes #2037.
      • Fix Let's Encrypt integration failing back-to-back runs. Closes #2121.
    • Features:
      • "Proper" support for IPv6:
        • Make ifutil.py module code "IPv6 aware", including reliable management of /etc/network/interfaces with "inet6" stanza/s.
        • Show IPv6 info on "usage" page - only shown if IPv6 configured. Special thanks to Marcos: https://github.com/marcos-mendez - https://popsolutions.co/
    • Misc clean up and improvements in code and packaging. See Confconsole release notes for full details.
  • Firstboot Initialization (inithooks):
    • Bugfixes:
      • Ensure everyboot scripts only run once per boot.
      • firstboot.d/15regen-sslcert:
        • Only services which are already running need to be restarted as restart is only to apply updated certs.
      • firstboot.d/01ipconfig:
        • Minor bugfix.
    • Features/improvements and other changes of significance:
      • Reimplement an 'inithooks.service' and refactor integration with getty1.
      • Delay start of inithooks/confconsole at boot time to reduce chance of boot messages overwriting inithooks/confconsole.
        • Developers - please note that hooks with a prefix less than '30' will still run early, so should _always_ be non-interactive.
      • TurnKey 'init-fence' (blocks web access at firstboot):
        • Run by default on all builds pre firstboot initialization (previously only enabled on "headless" builds).
        • New pre-seed variable 'AUTO_RUN' to skip interactive config (re-implements previous "headless" build functionality).
        • Replace legacy init.d script with systemd 'turnkey-init-fence.service' (& script which is called by the service).
        • Add support for 'systemctl reload turnkey-init-fence.service' - which restarts 'simplehttpd.py' (init-fence mini web server) but does not disable the firewall rules.
        • Support for custom init-fence content.
        • Update dynamically generated SSH information for IPv6 address display.
        • Add IPv6 support to mini server.
    • Ensure inithook 'SEC_UPDATES' pre-seed variable test is case insensitive; eliminates risk of unintended behavior when pre-seeding.
    • Misc clean up and improvements in code and packaging. See Inithooks release notes for full details.
  • Web management console (webmin):
    • Upgraded Webmin to latest upstream.
    • Refactored TurnKey Webmin packaging process to support easier updates; with the intention of following upstream releases as closely as possible (provided via TurnKey apt repo).
    • Updated default Webmin config:
      • Listen on IPv6 by default.
      • Preconfigured IPv6 firewall matching IPv4 rules (but not enabled - as per historical IPv4 default).
      • Auto redirect http => https.
      • Default 30 min user logout (can be overridden via login page "remember me" checkbox or webmin "authentication" config).
      • Updated logging paths and fixed log file rotation.
  • Backup (tklbam):
    • Bugfixes:
      • Fix broken help pager (not sure how long that has been broken!?).
      • Fix broken tar command (deprecated functionality removed in Debian Trixie).
    • Features/improvements:
      • Migrate core program and direct dependency python2 runtime from cpython2 (EOL) to Pypy (still supported - packaged by TurnKey).
      • Migrate all other components to python3. Note: remaining python2 TKLBAM code port to python3 is in progress but no ETA yet...
    • Misc clean up and improvements in code and packaging. See TKLBAM release notes for full details.
  • Misc code cleanup and improvements.

Links