Difference between revisions of "Samba"

From UVOO Tech Wiki
Jump to navigation Jump to search
 
(7 intermediate revisions by the same user not shown)
Line 1: Line 1:
 
# Setting Up
 
# Setting Up
 +
 +
### Redhat 7
 +
- [[ Samba File Server CentOS 7 ]]
 +
- https://access.redhat.com/solutions/3802321 and https://access.redhat.com/articles/4355391 - Don't use sssd
 +
- https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/system_administrators_guide/ch-file_and_print_servers#the_samba_services
  
 
## This seems to work
 
## This seems to work
Line 31: Line 36:
 
alternatives --display cifs-idmap-plugin
 
alternatives --display cifs-idmap-plugin
 
alternatives --set cifs-idmap-plugin /usr/lib64/cifs-utils/cifs_idmap_sss.so  # was  alternatives --set cifs-idmap-plugin /usr/lib/cifs-utils/idmapwb.so
 
alternatives --set cifs-idmap-plugin /usr/lib64/cifs-utils/cifs_idmap_sss.so  # was  alternatives --set cifs-idmap-plugin /usr/lib/cifs-utils/idmapwb.so
 +
alternatives --set cifs-idmap-plugin /usr/lib64/cifs-utils/idmapwb.so
 +
systemctl is-active winbind.service
 +
systemctl is-active sssd.service
 
```
 
```
  

Latest revision as of 20:52, 10 May 2020

Setting Up

Redhat 7

This seems to work

Other

Client

gvfs-mount smb://stay@nas/stay

mount sucks as must be root use above or gui tools

sudo mount -t cifs -o username=myuser //nas/myuser /mnt/smbmount

https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/windows_integration_guide/smb-sssd

New-SmbMapping -UserName jtest -password 123123 -LocalPath 'M:' -RemotePath '\10.250.24.12\jtest'

alternatives --display cifs-idmap-plugin
alternatives --set cifs-idmap-plugin /usr/lib64/cifs-utils/cifs_idmap_sss.so  # was  alternatives --set cifs-idmap-plugin /usr/lib/cifs-utils/idmapwb.so
alternatives --set cifs-idmap-plugin /usr/lib64/cifs-utils/idmapwb.so
systemctl is-active winbind.service
systemctl is-active sssd.service

smbpasswd -a jebusk

New-SmbMapping -LocalPath 'O:' -RemotePath '\10.250.24.12\jtest3'

/var/lib/samba/private/passdb.tdb

Ubuntu 18.04

vim /etc/pam.d/common-session # at bottom of file

session optional pam_mkhomedir.so skel=/etc/skel umask=077

Access

```realm permit statements handle ACLs with sssd but with windbind let's use pam to restrict auth connections.
/etc/pam.d/sshd
account required pam_access.so
to enforce
/etc/security/access.conf
+ : usertoallow : ALL
ALL : ALL https://ubuntuforums.org/showthread.php?t=1385235
<br />Checks

getent passwd myuser id user@domain.com ```

http://koo.fi/blog/2015/06/16/ubuntu-14-04-active-directory-authentication/