这是使用 Samba 共享和管理权限跟踪文件所有权的有效设置吗?

这是使用 Samba 共享和管理权限跟踪文件所有权的有效设置吗?

只需要有人监视我并告诉我在我开始添加用户后此设置是否可以正常工作而不会出现任何大问题。

当前设置:

  • Ubuntu 14.0.4LTS
  • Samba 4.1.6-Ubuntu
  • 外部驱动器安装在/etc/fstab设置为/媒体/备份01使用“ntfs-3g 权限,windows_names,locale=en_US.utf8”
  • 团体用户将目标 SMB 用户定义为成员并在文件夹中设置组粘性位/媒体/备份01/分享
  • 外部 WINS 服务器,无论其价值 (192.168.0.4)
  • Windows 7 和 Windows 10 客户端(修改注册表项以允许它们加入域)

ls -l /媒体

drwxrwxrwx 1 root root 4096 Aug 13 14:13 Backup01

ls -l /media/Backup01

drwxrwsr-x 1 nobody users 152 Aug 17 09:12 share

测试参数

Load smb config files from /etc/samba/smb.conf
rlimit_max: increasing rlimit_max (1024) to minimum Windows limit (16384)
Processing section "[netlogon]"
Processing section "[share]"
Loaded services file OK.
Server role: ROLE_DOMAIN_PDC
Press enter to see a dump of your service definitions
[global]
    workgroup = DOMAINNAME
    server string = %h PDC server (Samba, Ubuntu)
    map to guest = Bad User
    obey pam restrictions = Yes
    pam password change = Yes
    passwd program = /usr/bin/passwd %u
    passwd chat = *Enter\snew\s*\spassword:* %n\n *Retype\snew\s*\spassword:* %n\n *password\supdated\ssuccessfully* .
    unix password sync = Yes
    syslog = 0
    log file = /var/log/samba/log.%m
    max log size = 1000
    name resolve order = wins, lmhosts, hosts, bcast
    add machine script = /usr/sbin/useradd -N -g machines -c "%u machine account" -d /var/lib/samba -s /bin/false %u
    logon script = logon.cmd
    logon drive = H:
    domain logons = Yes
    preferred master = Yes
    domain master = Yes
    dns proxy = No
    wins server = 192.168.0.4
    panic action = /usr/share/samba/panic-action %d
    idmap config * : backend = tdb
    create mask = 0664
    directory mask = 0775
[netlogon]
    comment = Network Logon Service
    path = /srv/samba/netlogon
    valid users = %S
    read only = No
    create mask = 0700
    directory mask = 0700
    guest ok = Yes
    browseable = No
[share]
    comment = Share
    path = /media/Backup01/share
    read only = No
    force create mode = 0664
    directory mask = 02775
    force directory mode = 02775

看来目前正在工作。

  • 工作站可以通过 SMB root 的权限加入域
  • 用户可以映射分享,凭证为 DOMAINNAME\smbuser
  • 用户可以在根目录中创建测试文件
  • 权限表明用户拥有该文件

相关内容