
Samba 4.21 introduces LDAP TLS/SASL channel binding support, the LDB LDAP-like local database is now provided as an optional public library as part of the Samba package rather than as a standalone option, a new DNS hostname configuration option is introduced, Samba AD will now rotate expired passwords on SmartCard-required accounts, per-user and group "veto files" and "hide files", a new CephFS VFS module, support for Group Managed Service Accounts (gMSAs), support for key features of AD Domain/Forest Functional Level 2012R2, and work on more deterministic/reproducible builds.
Those interested in more details on the many changes to find with Samba 4.21 can see the release notes . Those building Samba from source can grab the new v4.21 builds on Samba.org .