Blame
|
1 | # SAMBA |
||||||
| 2 | ||||||||
| 3 | ## Preparation |
|||||||
| 4 | ||||||||
| 5 | 1. Create group for backups |
|||||||
| 6 | ```bash |
|||||||
| 7 | sudo groupadd backupusers |
|||||||
| 8 | ``` |
|||||||
| 9 | - create new group `backupusers` |
|||||||
| 10 | ||||||||
| 11 | ||||||||
| 12 | 2. Create user for samba |
|||||||
| 13 | ```bash |
|||||||
| 14 | sudo adduser --disabled-login --no-create-home --gecos "" smbbackup |
|||||||
| 15 | sudo usermod -aG backupusers smbbackup |
|||||||
| 16 | ||||||||
| 17 | ``` |
|||||||
| 18 | - --disabled-login - no system login |
|||||||
| 19 | - --no-create-home - no user home directory |
|||||||
| 20 | - --gecos "" - no interactive questions for name and so on |
|||||||
| 21 | - with `usermod`: add user `$USER` to group `backupusers` |
|||||||
| 22 | ||||||||
| 23 | 3. Prepare directory to use with samba |
|||||||
| 24 | ```bash |
|||||||
| 25 | sudo chown root:smbbackup /srv/ssd/backups |
|||||||
| 26 | sudo chmod 2770 /srv/ssd/backups |
|||||||
| 27 | ``` |
|||||||
| 28 | ||||||||
| 29 | 4. Install samba |
|||||||
| 30 | ```bash |
|||||||
| 31 | sudo apt install samba samba-common-bin smbclient cifs-utils |
|||||||
| 32 | systemctl status smbd --no-pager |
|||||||
| 33 | ``` |
|||||||
| 34 | - last one for checking status of smbd (active?) |
|||||||
| 35 | ||||||||
| 36 | 5. Registrate user for samba |
|||||||
| 37 | ```bash |
|||||||
| 38 | sudo smbpasswd -a smbbackup |
|||||||
| 39 | sudo smbpasswd -e smbbackup |
|||||||
| 40 | ``` |
|||||||
| 41 | - first one registrates smbbackup with a chosen password as user in samba |
|||||||
| 42 | - second one enables user smbbackup |
|||||||
| 43 | ||||||||
| 44 | 6. Change samba configuration |
|||||||
| 45 | ```bash |
|||||||
| 46 | sudo cp /etc/samba/smb.conf "/etc/samba/smb.conf.backup-$(date +%F-%H%M%S)" |
|||||||
| 47 | sudo nano /etc/samba/smb.conf |
|||||||
| 48 | ``` |
|||||||
| 49 | add at the end |
|||||||
| 50 | ``` |
|||||||
| 51 | [Backups] |
|||||||
| 52 | comment = Backups auf der externen SSD |
|||||||
| 53 | path = /srv/ssd/Backups |
|||||||
| 54 | ||||||||
| 55 | browseable = yes |
|||||||
| 56 | read only = no |
|||||||
| 57 | guest ok = no |
|||||||
| 58 | ||||||||
| 59 | valid users = smbbackup |
|||||||
| 60 | force group = backupusers |
|||||||
| 61 | ||||||||
| 62 | create mask = 0660 |
|||||||
| 63 | force create mode = 0660 |
|||||||
| 64 | directory mask = 2770 |
|||||||
| 65 | force directory mode = 2770 |
|||||||
| 66 | ``` |
|||||||
| 67 | ||||||||
| 68 | 7. Restart samba |
|||||||
| 69 | ```bash |
|||||||
| 70 | sudo testparm -s |
|||||||
| 71 | sudo systemctl restart smbd |
|||||||
| 72 | ``` |
|||||||
| 73 | - check configuration and then restart |
|||||||
| 74 | ||||||||
| 75 | 8. Checks |
|||||||
| 76 | ```bash= |
|||||||
| 77 | sudo systemctl status smbd --no-pager |
|||||||
| 78 | smbclient -L localhost -U smbbackup |
|||||||
| 79 | smbclient //localhost/Backups -U smbbackup |
|||||||
| 80 | ``` |
|||||||
| 81 | 1: check service active and enabled |
|||||||
| 82 | 2: check Shares of samba |
|||||||
| 83 | 3: connect to shell of samba and test `mkdir test` |
|||||||
| 84 | ||||||||
| 85 | 9. Prepare connection to network |
|||||||
| 86 | ```bash= |
|||||||
| 87 | sudo ufw app list |
|||||||
| 88 | sudo ufw app info Samba |
|||||||
| 89 | sudo ufw allow in on <eth0> from <192.168.2.0/24> to any app Samba |
|||||||
| 90 | sudo ufw status |
|||||||
| 91 | ``` |
|||||||
| 92 | 1: all apps ufw knows |
|||||||
| 93 | 2: ufw info about Samba app (ports) |
|||||||
| 94 | 3: open ports for LAN in network to Samba |
|||||||
| 95 | 4: show changed ufw rules |
|||||||
