Linux下的samba服务配置详解

简介: Linux下的samba服务配置详解

一、Samba介绍

1.SMB(Server Messages Block,信息服务块)是一种在局域网上共享文件和打印机的一种通信协议,它为局域网内的不同计算机之间提供文件及打印机等资源的共享服务。
2.Samba是在Linux和UNIX系统上实现SMB协议的一个免费软件,由服务器及客户端程序构成。
3.其他相关概念:
CIFS:common internet file system,微软基于SMB发布。
NFS:网络文件系统,英文Network File System(NFS),是由SUN公司研制的UNIX表示层协议(presentation layer protocol),能使使用者访问网络上别处的文件就像在使用自己的计算机一样。

二、Samba工具及特性

1.相关包
①amba 提供smb服务
②samba-client 客户端软件
③samba-common 通用软件
④cifs-utils smb客户端工具
⑤samba-winbind 和AD相关

2.相关服务进程
smbd 提供smb(cifs)服务 TCP:139,445
nmbd NetBIOS名称解析 UDP:137,138
3.相关工具及命令
主配置文件:/etc/samba/smb.conf

语法检查: testparm [-v] [/etc/samba/smb.conf]

客户端工具:smbclient,pdnedit -L(列出Samba用户列表,读取passdb.tdb数据库文件)

三、搭建环境介绍

1.使用操作系统为RHEL8.0
2.Samba用户为三个(kitty,buer,alice),都可以浏览共享目录/share/,kitty和buer可以写入文件共享目录。
3.服务端hostname为control,客户端hostname为node1

四、Samba配置步骤

1.服务端操作

①在server端安装软件包

[root@control ~]# yum -y install samba samba-client
Updating Subscription Management repositories.
Unable to read consumer identity
This system is not registered to Red Hat Subscription Management. You can use subscription-manager to register.
Last metadata expiration check: 0:00:36 ago on Sun 02 May 2021 08:10:41 PM CST.
Dependencies resolved.
================================================================================================================================================
 Package                                   Arch                          Version                            Repository                     Size
================================================================================================================================================
Installing:
 samba                                     x86_64                        4.9.1-8.el8                        BaseOS                        708 k
 samba-client                              x86_64                        4.9.1-8.el8                        BaseOS                        636 k
Installing dependencies:
 samba-common-tools                        x86_64                        4.9.1-8.el8                        BaseOS                        461 k
 samba-libs                                x86_64                        4.9.1-8.el8                        BaseOS                        177 k

Transaction Summary
================================================================================================================================================
Install  4 Packages

Total size: 1.9 M
Installed size: 5.6 M
Downloading Packages:
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
  Preparing        :                                                                                                                        1/1 
  Installing       : samba-libs-4.9.1-8.el8.x86_64                                                                                          1/4 
  Running scriptlet: samba-libs-4.9.1-8.el8.x86_64                                                                                          1/4 
  Installing       : samba-common-tools-4.9.1-8.el8.x86_64                                                                                  2/4 
  Installing       : samba-4.9.1-8.el8.x86_64                                                                                               3/4 
  Running scriptlet: samba-4.9.1-8.el8.x86_64                                                                                               3/4 
  Installing       : samba-client-4.9.1-8.el8.x86_64                                                                                        4/4 
  Running scriptlet: samba-client-4.9.1-8.el8.x86_64                                                                                        4/4 
  Verifying        : samba-4.9.1-8.el8.x86_64                                                                                               1/4 
  Verifying        : samba-client-4.9.1-8.el8.x86_64                                                                                        2/4 
  Verifying        : samba-common-tools-4.9.1-8.el8.x86_64                                                                                  3/4 
  Verifying        : samba-libs-4.9.1-8.el8.x86_64                                                                                          4/4 
Installed products updated.

Installed:
  samba-4.9.1-8.el8.x86_64     samba-client-4.9.1-8.el8.x86_64     samba-common-tools-4.9.1-8.el8.x86_64     samba-libs-4.9.1-8.el8.x86_64    

Complete!

②创建samba共享目录/share,设置权限,并拷贝文件到共享目录

[root@control ~]# mkdir /share
[root@control ~]# ll /share
total 0
[root@control ~]# ll -ld /share
drwxr-xr-x. 2 root root 6 May  2 20:24 /share
[root@control ~]# chmod 777 /share
[root@control ~]# ll -ld /share
drwxrwxrwx. 2 root root 6 May  2 20:24 /share

[root@control ~]# cp /etc/passwd /share
[root@control ~]# cp /etc/group /share
[root@control ~]# ls /share
group  passwd

③创建samba用户

[root@control ~]# groupadd it
[root@control ~]# useradd -g it kitty
[root@control ~]# useradd alice
[root@control ~]# useradd buer
[root@control ~]# smbpasswd -a kitty
New SMB password:
Retype new SMB password:
Added user kitty.
[root@control ~]# smbpasswd -a alice
New SMB password:
Retype new SMB password:
Added user alice.
[root@control ~]# smbpasswd -a buer
New SMB password:
Retype new SMB password:
Added user buer.
#查看samba用户列表
[root@control ~]# pdbedit -L
kitty:2034:
buer:2036:
alice:2035:

④编辑samba主配置文件
进入配置目录/etc/samba/smb.conf

[share]
      path = /share
      browseable = yes
      write list = @it,buer
      hosts allow = 192.168.200.0/24

测试配置文件语法

[root@control ~]# testparm /etc/samba/smb.conf
Load smb config files from /etc/samba/smb.conf
rlimit_max: increasing rlimit_max (1024) to minimum Windows limit (16384)
Processing section "[homes]"
Processing section "[printers]"
Processing section "[print$]"
Processing section "[share]"
Loaded services file OK.
Server role: ROLE_STANDALONE

Press enter to see a dump of your service definitions

# Global parameters
[global]
    printcap name = cups
    security = USER
    workgroup = SAMBA
    idmap config * : backend = tdb
    cups options = raw


[homes]
    browseable = No
    comment = Home Directories
    inherit acls = Yes
    read only = No
    valid users = %S %D%w%S


[printers]
    browseable = No
    comment = All Printers
    create mask = 0600
    path = /var/tmp
    printable = Yes


[print$]
    comment = Printer Drivers
    create mask = 0664
    directory mask = 0775
    force group = @printadmin
    path = /var/lib/samba/drivers
    write list = @printadmin root


[share]
    hosts allow = 192.168.200.0/24
    path = /share
    write list = @it buer

⑤启动samba服务

[root@control ~]# systemctl start smb
[root@control ~]# systemctl start nmb
[root@control ~]# systemctl enable nmb
Created symlink /etc/systemd/system/multi-user.target.wants/nmb.service → /usr/lib/systemd/system/nmb.service.
[root@control ~]# systemctl enable smb
Created symlink /etc/systemd/system/multi-user.target.wants/smb.service → /usr/lib/systemd/system/smb.service.

⑥防火墙放行

[root@control ~]# firewall-cmd --permanent --add-service=samba
success
[root@control ~]# firewall-cmd --reload 
success

⑦配置selinux安全标签

[root@control ~]# semanage fcontext -a -t samba_share_t '/share(/.*)?'
[root@control ~]# restorecon
restorecon        restorecon_xattr  
[root@control ~]# restorecon -vvFR /share
Relabeled /share from unconfined_u:object_r:default_t:s0 to system_u:object_r:samba_share_t:s0
Relabeled /share/passwd from unconfined_u:object_r:default_t:s0 to system_u:object_r:samba_share_t:s0
Relabeled /share/group from unconfined_u:object_r:default_t:s0 to system_u:object_r:samba_share_t:s0

2.在客户端操作

①客户端安装相关软件包

[root@node1 yum.repos.d]# yum -y install samba-client cifs-utils
Updating Subscription Management repositories.
Unable to read consumer identity
This system is not registered to Red Hat Subscription Management. You can use subscription-manager to register.
Repository AppStream is listed more than once in the configuration
Repository BaseOS is listed more than once in the configuration
AppStream                                                                                                       3.1 MB/s | 3.2 kB     00:00    
BaseOS                                                                                                          2.7 MB/s | 2.7 kB     00:00    
ansiable                                                                                                        0.0  B/s |   0  B     00:00    
Failed to synchronize cache for repo 'ansiable', ignoring this repo.
Dependencies resolved.
================================================================================================================================================
 Package                              Arch                           Version                               Repository                      Size
================================================================================================================================================
Installing:
 cifs-utils                           x86_64                         6.8-2.el8                             BaseOS                          93 k
 samba-client                         x86_64                         4.9.1-8.el8                           BaseOS                         636 k

Transaction Summary
================================================================================================================================================
Install  2 Packages

Total size: 729 k
Installed size: 2.3 M
Downloading Packages:
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
  Preparing        :                                                                                                                        1/1 
  Installing       : samba-client-4.9.1-8.el8.x86_64                                                                                        1/2 
  Running scriptlet: samba-client-4.9.1-8.el8.x86_64                                                                                        1/2 
  Installing       : cifs-utils-6.8-2.el8.x86_64                                                                                            2/2 
  Running scriptlet: cifs-utils-6.8-2.el8.x86_64                                                                                            2/2 
  Verifying        : cifs-utils-6.8-2.el8.x86_64                                                                                            1/2 
  Verifying        : samba-client-4.9.1-8.el8.x86_64                                                                                        2/2 
Installed products updated.

Installed:
  cifs-utils-6.8-2.el8.x86_64                                          samba-client-4.9.1-8.el8.x86_64                                         

Complete!

②使用smbclient工具测试kitty和alice用户是否可以查看共享文件夹

[root@node1 yum.repos.d]# smbclient -L //192.168.200.150 -U kitty%redhat

    Sharename       Type      Comment
    ---------       ----      -------
    print$          Disk      Printer Drivers
    share           Disk      
    IPC$            IPC       IPC Service (Samba 4.9.1)
    kitty           Disk      Home Directories
Reconnecting with SMB1 for workgroup listing.

    Server               Comment
    ---------            -------

    Workgroup            Master
    ---------            -------
    SAMBA                CONTROL
[root@node1 yum.repos.d]# smbclient -L //192.168.200.150 -U alice%redhat

    Sharename       Type      Comment
    ---------       ----      -------
    print$          Disk      Printer Drivers
    share           Disk      
    IPC$            IPC       IPC Service (Samba 4.9.1)
    alice           Disk      Home Directories
Reconnecting with SMB1 for workgroup listing.

    Server               Comment
    ---------            -------

    Workgroup            Master
    ---------            -------
    SAMBA                CONTROL

③创建samba认证用户文件smbur,使用alice作为认证用户

[root@node1 yum.repos.d]# echo "username=alice" >> /etc/samba/smbur.txt
[root@node1 yum.repos.d]# echo "password=redhat" >> /etc/samba/smbur.txt

④编辑/etc/fstab文件,使挂载共享目录永久生效

[root@node1 yum.repos.d]# cat /etc/fstab 

#
# /etc/fstab
# Created by anaconda on Fri Mar 19 22:21:55 2021
#
# Accessible filesystems, by reference, are maintained under '/dev/disk/'.
# See man pages fstab(5), findfs(8), mount(8) and/or blkid(8) for more info.
#
# After editing this file, run 'systemctl daemon-reload' to update systemd
# units generated from this file.
#
UUID=b7190d80-906f-4b9d-9ab4-5a503ecaea2c /                       xfs     defaults        0 0
UUID=525a30a7-d484-4ed5-9f38-f827f54e29ff /boot                   xfs     defaults        0 0
UUID=e6cf8733-5eec-4942-9429-c3e9087b6ff0 swap                    swap    defaults        0 0


//192.168.200.150/share /media cifs defaults,credentials=/etc/samba/smbur.txt,multiuser,sec=ntlmssp 0 0
[root@node1 yum.repos.d]# df -h
Filesystem               Size  Used Avail Use% Mounted on
devtmpfs                 970M     0  970M   0% /dev
tmpfs                    984M     0  984M   0% /dev/shm
tmpfs                    984M  9.1M  974M   1% /run
tmpfs                    984M     0  984M   0% /sys/fs/cgroup
/dev/nvme0n1p3            18G  4.0G   14G  23% /
/dev/nvme0n1p1           495M  140M  356M  29% /boot
tmpfs                    197M  4.0K  197M   1% /run/user/0
/dev/sr0                 6.7G  6.7G     0 100% /mnt/cdrom
//192.168.200.150/share   13G  8.5G  4.1G  68% /media

五、测试用户的权限情况

1.检查在/media目录下以alice用户挂载权限

[root@node1 yum.repos.d]# cd /media/
[root@node1 media]# touch file1
touch: cannot touch 'file1': Permission denied
[root@node1 media]# ls
group  passwd

2.切换本地admin用户,以kitty和buer这两个samba用户访问测试权限

[root@node1 yum.repos.d]# cd /media/
[root@node1 media]# touch file1
touch: cannot touch 'file1': Permission denied
[root@node1 media]# ls
group  passwd
[root@node1 media]# useradd admin
[root@node1 media]# su - admin
[admin@node1 ~]$ cd /media
[admin@node1 media]$ cifscreds add -u kitty control
Password: 
[admin@node1 media]$ ls
group  passwd
[admin@node1 media]$ touch file1
[admin@node1 media]$ ls
file1  group  passwd
[admin@node1 media]$ cifscreds update  -u buer control
Password: 
[admin@node1 media]$ ls
file1  group  passwd
[admin@node1 media]$ touch file2
[admin@node1 media]$ ls
file1  file2  group  passwd
相关文章
|
Linux 网络安全 Docker
盘古栈云,创建带ssh服务的linux容器
创建带ssh服务的linux容器
551 146
|
Ubuntu Linux 网络安全
Linux服务器之Ubuntu的安装与配置
Ubuntu Desktop是目前最成功、最流行的图形界面的Linux发行版;而Ubuntu Server也在服务器端市场占据了较大的份额。今天为大家详细介绍了Ubuntu Server的安装与配置,希望对你能有所帮助。关于VMware、VirtualBox等虚拟化软件的使用,朱哥还会在后续的文章中为大家详细介绍,敬请关注!
|
安全 Linux 开发工具
【Linux】vim使用与配置教程
Vim是一款功能强大的文本编辑器,广泛应用于Linux环境,是开发者和系统管理员的必备工具。本文介绍了Vim的基本操作与简单配置,涵盖命令模式、插入模式和底行模式的使用方法,以及光标定位、复制粘贴、搜索替换等常用技巧。同时,文章还提供了实用的分屏操作和代码注释方法,并分享了通过`.vimrc`文件进行个性化配置(如显示行号、语法高亮、自动缩进等)的技巧,帮助用户提升文本编辑效率。掌握这些内容,能让Vim更好地服务于日常工作与开发需求。
1263 3
|
12月前
|
存储 Linux 开发工具
Linux环境下使用Buildroot配置软件包
使用Buildroot可以大大简化嵌入式Linux系统的开发和维护工作,但它需要对Linux系统和交叉编译有深入的理解。通过上述步骤,可以有效地配置和定制软件包,为特定的嵌入式应用构建高效、稳定的系统。
1240 11
|
缓存 安全 Linux
六、Linux核心服务与包管理
在没有网络的情况下,使用系统安装光盘是获取RPM包的常用方法。场景二:配置本地文件镜像源 (使用系统安装光盘/ISO)(检查RPM包的GPG签名以保证安全) 或。YUM/DNF包管理工具 (yum/dnf)(此处可以放置您为本主题制作的思维导图)处理依赖问题的危险选项 (应极力避免)(覆盖文件、替换已安装包)。(list) 则是列出文件。(query file) 是。(假设系统安装光盘已挂载到。信息 (verbose)。(upgrade) 选项。(all) 已安装的包。(package) 选项
813 11
|
Linux Shell
在Linux、CentOS7中设置shell脚本开机自启动服务
以上就是在CentOS 7中设置shell脚本开机自启动服务的全部步骤。希望这个指南能帮助你更好地管理你的Linux系统。
2515 25
|
关系型数据库 MySQL Java
安装和配置JDK、Tomcat、MySQL环境,以及如何在Linux下更改后端端口。
遵循这些步骤,你可以顺利完成JDK、Tomcat、MySQL环境的安装和配置,并在Linux下更改后端端口。祝你顺利!
830 11
|
Kubernetes Linux 网络安全
Rocky Linux 8.9配置Kubernetes集群详解,适用于CentOS环境
初始化成功后,记录下显示的 `kubeadm join`命令。
948 0
|
Java Linux 应用服务中间件
在Rocky Linux 9上安装JDK并配置环境变量!
本教程介绍在Rocky Linux 9上安装JDK并配置环境变量的完整步骤。首先更新系统,清理旧版本JDK相关包及残留文件,确保环境干净。接着搜索并安装所需版本的JDK(如OpenJDK 17),验证安装是否成功。然后查找JDK安装路径,配置全局环境变量`JAVA_HOME`和`PATH`,最后验证环境变量设置。按照此流程操作,可顺利完成Java开发环境搭建,支持多版本切换(如JDK 8/11/17)。生产环境请谨慎操作,避免影响现有服务。
2263 21
|
安全 Linux 网络安全
在Linux(CentOS和AWS)上安装更新的git2的方法并配置github-ssh
经过以上这些步骤,你现在就能在GitHub上顺利往返,如同海洋中的航海者自由驰骋。欢迎你加入码农的世界,享受这编程的乐趣吧!
700 10

热门文章

最新文章