+CHANGES SINCE 4.0.0rc1
+======================
+
+o Michael Adam <obnox@samba.org>
+ * BUG 9173: Make the SMB2 compound request create/delete_on_close/
+ close work as Windows.
+
+
+o Jeremy Allison <jra@samba.org>
+ * BUG 9161: Re-add the vfs_Chdir() cache.
+ * BUG 9189: SMB2 Create doesn't return correct MAX ACCESS access mask in
+ blob.
+ * BUG 9213: Bad ASN.1 NegTokenInit packet can cause invalid free.
+
+
+o Christian Ambach <ambi@samba.org>
+ * BUG 9162: Fix the build of the GPFS VFS module.
+ * BUG 9197: Only do 'printing_subsystem_update' when printing is enabled.
+
+
+o Alexander Bokovoy <ab@samba.org>
+ * BUG 9157: Cleanup idmap_ldap build dependencies.
+
+
+o Ira Cooper <ira@samba.org>
+ * BUG 9162: Fix build on Illumos/Solaris using '--with-acl'.
+ * BUG 9173: Compound requests should continue processing.
+
+
+o Björn Jacke <bj@sernet.de>
+ * BUG 9162: Fix the build of the ACL VFS modules.
+ * BUG 9172: Fix reporting of gfs2 quotas.
+
+
+o Volker Lendecke <vl@samba.org>
+ * BUG 9217: CreateFile with FILE_DIRECTORY_FILE can create directories
+ on read-only shares.
+
+
+o Stefan Metzmacher <metze@samba.org>
+ * BUG 9173: Make the SMB2 compound request create/delete_on_close/
+ close work as Windows.
+ * BUG 9184: Fix receiving of UDP packets from 0 bytes.
+ * BUG 9191: Release the share mode lock before calling exit_server().
+ * BUG 9193: Fix usage of invalid memory in smb2_signing_check_pdu().
+ * BUG 9194: Disallow '--prefix=/usr' and '--prefix=/usr/local' without
+ '--enable-fhs'.
+ * BUG 9198: Fix RHEL-CTDB packaging.
+
+
+o Matthieu Patou <mat@matws.net>
+ * BUG 9199: Fix usage of "panic action".
+
+
+o Andreas Schneider <asn@samba.org>
+ * BUG 8632: Fix builtin forms order to match Windows again.
+ * BUG 9159: Fix generating idmap manpages.
+ * BUG 9218: Don't segfault if user specified ports out for range.
+
+
+KNOWN ISSUES
+============
+
+- 'samba-tool domain classicupgrade' will fail when setting ACLs on
+ the GPO folders with NT_STATUS_INVALID_ONWER in the default
+ configuration. This happens if, as is typical a 'domain admins'
+ group (-512) is mapped in the passdb backend being upgraded. This
+ is because the group mapping to a GID only prevents Samba from
+ allocating a uid for that group. The uid is needed so the 'domain
+ admins' group can own the GPO file objects.
+
+ To work around this issue, remove the 'domain admins' group before
+ upgrade, as it will be re-created automatically. You will
+ of course need to fill in the group membership again. A future release
+ will make this automatic, or find some other workaround.
+
+- This release makes the s3fs file server the default, as this is the
+ file server combination we will use for the Samba 4.0 release.
+
+- For similar reasons, sites with ACLs stored by the ntvfs file server
+ may wish to continue to use that file server implementation, as a
+ posix ACL will similarly not be set in this case.
+
+- Replication of DNS data from one AD server to another may not work.
+ The DNS data used by the internal DNS server and bind9_dlz is stored
+ in an application partition in our directory. The replication of
+ this partition is not yet reliable.
+
+- Replication may fail on FreeBSD due to getaddrinfo() rejecting names
+ containing _. A workaround will be in a future release.
+
+- samba_upgradeprovision should not be run when upgrading to this release
+ from a recent release. No important database format changes have
+ been made since alpha16.
+
+- Installation on systems without a system iconv (and developer
+ headers at compile time) is known to cause errors when dealing with
+ non-ASCII characters.
+
+- Domain member support in the 'samba' binary is in its infancy, and
+ is not comparable to the support found in winbindd. As such, do not
+ use the 'samba' binary (provided for the AD server) on a member
+ server.
+
+- There is no NetBIOS browsing support (network neighbourhood)
+ available for the AD domain controller. (Support in nmbd and smbd
+ for classic domains and member/standalone servers is unchanged).
+
+- Clock Synchronisation is critical. Many 'wrong password' errors are
+ actually due to Kerberos objecting to a clock skew between client
+ and server. (The NTP work in the previous alphas are partly to assist
+ with this problem).
+
+- The DRS replication code may fail. Please contact the team if you
+ experience issues with DRS replication, as we have fixed many issues
+ here in response to feedback from our production users.
+
+
+RUNNING Samba 4.0 as an AD DC
+=============================
+
+A short guide to setting up Samba 4 as an AD DC can be found on the wiki:
+
+ http://wiki.samba.org/index.php/Samba4/HOWTO
+
+#######################################