標籤:samba配置
實驗一
要求:
將目錄/usr/src 共用給所有人
共用名稱設為tools
允許所有人訪問、無需密碼驗證
存取權限為唯讀
系統:RHEL6.4
1.安裝軟體包
[[email protected] ~]# rpm -q samba-client samba samba-common
package smaba-client is not installed
......
[[email protected] ~]# vim /etc/repos.d/rhel.repo
[rhel6.4]
name=Red Hat Enterprise Linux 6.4
baseurl=file:///misc/cd
enabled=1
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
[[email protected] ~]# yum -y install samba samba-client samba-common
....
2.修改設定檔
[[email protected] ~]# vim /etc/samba/smb.conf
....
74 workgroup=WORKGROUP
75 server string =Win File Ser
....
89 log file = /var/log/samba/%m.log
....
91 max log size = 50
...
101 security = share //不需要提供使用者名稱和密碼
289 [tools]
290 comment =Tools Public //共用描述資訊
291 path = /usr/src //共用路徑
292 public = yes //允許guest訪問
293 read only = yes //唯讀
3.啟動服務
[[email protected] ~]# testparm //檢測配置是否有錯誤
[[email protected] ~]# service smb restart
[[email protected] ~]# chkconfig smb on
4.用戶端測試:
Windows:UNC路徑\\192.168.10.10
Linux:
[[email protected] ~]# yum -y install samba-client
[[email protected] ~]# smbclient -L 192.168.10.10 //查詢Samba共用
[[email protected] ~]# smbclient //192.168.10.10/toos //串連Samba共用
[[email protected] ~]# mkdir -p /data/smb //將Samba掛載到本地
[[email protected] ~]# mount //192/168/10.10/tools /data/smb/
[[email protected] ~]# ls /data/smb
實驗二(接實驗一)
Samba使用者驗證
修改原有的[tools] 匿名共用設定
不再允許所有人訪問
只允許test1讀取,test2寫入
拒絕其他使用者或匿名訪問
1.建立相應帳戶與samba密碼
[[email protected] ~]#useradd test1
[[email protected] ~]#useradd test2
[[email protected] ~]#echo "123456" | passwd --stdin test1
[[email protected] ~]#echo "123456" | passwd --stdin test2
[[email protected] ~]pdbedit -a test1 //建立Samba使用者
[[email protected] ~]pdbedit -a test2
2.修改設定檔
[[email protected] ~]# vim /etc/samba/smb.conf
101 security=user //授權使用者才能訪問
.....
289 [tools]
comment =tools public
path=/usr/src
public=no //不允許匿名訪問
valid users =test1,test2 //設定允許訪問該共用的使用者
write list=test2 //設定允許寫入該共用的使用者
read only =yes //預設許可權為唯讀
directory mask =0755 //上傳目錄的預設許可權
create mask =0644 //上傳檔案的預設許可權
[[email protected] ~]setfacl -m u:test2:rwx /usr/src //給test2添加本地檔案夾寫入許可權
3.啟動服務
[[email protected] ~]service smb restart
4.用戶端測試
[[email protected] ~]#smbclient -U test1 //192.168.10.10/tools
[[email protected] ~]#mkdir /mnt/smbfs
[[email protected] ~]#mount -o username=test1 //192.168.10.10/tools /mnt/smbfs
[[email protected] ~]#smblient -U test1 //192.168.10.10/tools
smb:\>put install.log //測試test1是否能上傳
[[email protected] ~]#smblient -U hunter //192.168.10.10/tools
smb:\>put install.log //測試test2石佛能上傳
實驗三 Samba帳號別名
把普通使用者test1設定別名為jack
設定只允許192.168.10.0/24網段訪問
1.修改設定檔
[[email protected] ~] # vim /etc/samba/smbusers
nick=jack
[[email protected] ~] #vim /etc/samba/smb.conf
.....
76 username map =/etc/samba/smbusers //定義使用者名稱對應檔案
.....
101 security=user
.....
289 [tools]
291 comment =tools public
292path=/usr/src
293public=no
294valid users =test1,test2
295write list=test2
296read only =yes
297directory mask =0755
298create mask =0644
299host allow = 192.168.10.0/255.255.255.0 //也可以寫為192.168.10.
[[email protected] ~] #vim /etc/samba/smbusers
test1=jack //添加test1別名
2.重啟服務
[[email protected] ~]service smb restart
3.用戶端測試
.....