diff options
Diffstat (limited to 'docs/htmldocs')
-rw-r--r-- | docs/htmldocs/lmhosts.5.html | 26 | ||||
-rw-r--r-- | docs/htmldocs/make_smbcodepage.1.html | 20 | ||||
-rw-r--r-- | docs/htmldocs/nmbd.8.html | 56 | ||||
-rw-r--r-- | docs/htmldocs/nmblookup.1.html | 30 | ||||
-rw-r--r-- | docs/htmldocs/samba.7.html | 19 | ||||
-rw-r--r-- | docs/htmldocs/smb.conf.5.html | 262 | ||||
-rw-r--r-- | docs/htmldocs/smbclient.1.html | 40 | ||||
-rw-r--r-- | docs/htmldocs/smbd.8.html | 67 | ||||
-rw-r--r-- | docs/htmldocs/smbpasswd.5.html | 32 | ||||
-rw-r--r-- | docs/htmldocs/smbpasswd.8.html | 36 | ||||
-rw-r--r-- | docs/htmldocs/smbrun.1.html | 4 | ||||
-rw-r--r-- | docs/htmldocs/smbstatus.1.html | 4 | ||||
-rw-r--r-- | docs/htmldocs/smbtar.1.html | 4 | ||||
-rw-r--r-- | docs/htmldocs/swat.8.html | 84 | ||||
-rw-r--r-- | docs/htmldocs/testparm.1.html | 8 | ||||
-rw-r--r-- | docs/htmldocs/testprns.1.html | 8 |
16 files changed, 332 insertions, 368 deletions
diff --git a/docs/htmldocs/lmhosts.5.html b/docs/htmldocs/lmhosts.5.html index f518c18713..d3ffedaff6 100644 --- a/docs/htmldocs/lmhosts.5.html +++ b/docs/htmldocs/lmhosts.5.html @@ -3,7 +3,7 @@ -<html><head><title>lmhosts</title> +<html><head><title>lmhosts (5)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>lmhosts</h1> +<h1>lmhosts (5)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -29,7 +29,7 @@ <h2>DESCRIPTION</h2> <p><br>This file is part of the <strong>Samba</strong> suite. -<p><br>lmhosts is the <strong>Samba</strong> NetBIOS name to IP address mapping file. It +<p><br><strong>lmhosts</strong> is the <strong>Samba</strong> NetBIOS name to IP address mapping file. It is very similar to the <strong>/etc/hosts</strong> file format, except that the hostname component must correspond to the NetBIOS naming format. <p><br><a name="FILEFORMAT"></a> @@ -49,18 +49,12 @@ returned for all names that match the given name, whatever the NetBIOS name type in the lookup. <p><br></ul> <p><br>An example follows : -<p><br><pre> - - -# -# Sample Samba lmhosts file. -# -192.9.200.1 TESTPC -192.9.200.20 NTSERVER#20 -192.9.200.21 SAMBASERVER - -</pre> - +<p><br># <br> +# Sample Samba lmhosts file. <br> +# <br> +192.9.200.1 TESTPC <br> +192.9.200.20 NTSERVER#20 <br> +192.9.200.21 SAMBASERVER <br> <p><br>Contains three IP to NetBIOS name mappings. The first and third will be returned for any queries for the names <code>"TESTPC"</code> and <code>"SAMBASERVER"</code> respectively, whatever the type component of the @@ -84,7 +78,7 @@ as the <a href="smb.conf.html"><strong>smb.conf</strong></a> file. <h2>AUTHOR</h2> <p><br>The original Samba software and related utilities were created by -Andrew Tridgell (samba-bugs@samba.anu.edu.au). Samba is now developed +Andrew Tridgell <a href="mailto:samba-bugs@samba.anu.edu.au"><em>samba-bugs@samba.anu.edu.au</em></a>. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed. <p><br>The original Samba man pages were written by Karl Auer. The man page diff --git a/docs/htmldocs/make_smbcodepage.1.html b/docs/htmldocs/make_smbcodepage.1.html index 34466d6216..10615deb86 100644 --- a/docs/htmldocs/make_smbcodepage.1.html +++ b/docs/htmldocs/make_smbcodepage.1.html @@ -3,7 +3,7 @@ -<html><head><title>make_smbcodepage</title> +<html><head><title>make_smbcodepage (1)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>make_smbcodepage</h1> +<h1>make_smbcodepage (1)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -36,15 +36,15 @@ with the internationalization features of Samba 2.0 <p><br><ul> <p><br><a name="cord"></a> -<li><strong>c|d</strong> This tells make_smbcodepage if it is compiling (c) a text -format code page file to binary, or (d) de-compiling a binary codepage +<li><strong>c|d</strong> This tells <strong>make_smbcodepage</strong> if it is compiling (<strong>c</strong>) a text +format code page file to binary, or (<strong>d</strong>) de-compiling a binary codepage file to text. <p><br><a name="codepage"></a> -<li><strong>codepage</strong> This is the codepage we are processing (a number, eg. 850). +<li><strong>codepage</strong> This is the codepage we are processing (a number, e.g. 850). <p><br><a name="inputfile"></a> -<li><strong>inputfile</strong> This is the input file to process. In the 'c' case this +<li><strong>inputfile</strong> This is the input file to process. In the '<strong>c</strong>' case this will be a text codepage definition file such as the ones found in the -Samba <em>source/codepages</em> directory. In the 'd' case this will be the +Samba <em>source/codepages</em> directory. In the '<strong>d</strong>' case this will be the binary format codepage definition file normally found in the <em>lib/codepages</em> directory in the Samba install directory path. <p><br><a name="outputfile"></a> @@ -57,9 +57,9 @@ binary format codepage definition file normally found in the Samba how to map from upper to lower case for characters greater than ascii 127 in the specified DOS code page. Note that for certain DOS codepages (437 for example) mapping from lower to upper case may be -asynchronous. For example, in code page 437 lower case a acute maps to -a plain upper case A when going from lower to upper case, but maps -from plain upper case A to plain lower case a when lower casing a +non-symmetrical. For example, in code page 437 lower case a acute maps to +a plain upper case A when going from lower to upper case, but +plain upper case A maps to plain lower case a when lower casing a character. <p><br>A binary Samba codepage definition file is a binary representation of the same information, including a value that specifies what codepage diff --git a/docs/htmldocs/nmbd.8.html b/docs/htmldocs/nmbd.8.html index 1408b6fd4e..dc8f5b0de3 100644 --- a/docs/htmldocs/nmbd.8.html +++ b/docs/htmldocs/nmbd.8.html @@ -38,19 +38,19 @@ participates in the browsing protocols which make up the Windows <p><br>SMB/CIFS clients, when they start up, may wish to locate an SMB/CIFS server. That is, they wish to know what IP number a specified host is using. -<p><br>Amongst other services, this program will listen for such requests, +<p><br>Amongst other services, <strong>nmbd</strong> will listen for such requests, and if its own NetBIOS name is specified it will respond with the IP number of the host it is running on. Its "own NetBIOS name" is by default the primary DNS name of the host it is running on, but this -can be overriden with the <strong>-n</strong> option (see <em>OPTIONS</em> below). Thus -nmbd will reply to broadcast queries for its own name(s). Additional -names for nmbd to respond on can be set via parameters in the -<strong>smb.conf (5)</strong> configuration file. -<p><br>nmbd can also be used as a WINS (Windows Internet Name Server) +can be overridden with the <strong>-n</strong> option (see <a href="nmbd.8.html#OPTIONS">OPTIONS</a> below). Thus +<strong>nmbd</strong> will reply to broadcast queries for its own name(s). Additional +names for <strong>nmbd</strong> to respond on can be set via parameters in the +<a href="smb.conf.5.html"><strong>smb.conf(5)</strong></a> configuration file. +<p><br><strong>nmbd</strong> can also be used as a WINS (Windows Internet Name Server) server. What this basically means is that it will act as a WINS database server, creating a database from name registration requests that it receives and replying to queries from clients for these names. -<p><br>In addition, nmbd can act as a WINS proxy, relaying broadcast queries +<p><br>In addition, <strong>nmbd</strong> can act as a WINS proxy, relaying broadcast queries from clients that do not understand how to talk the WINS protocol to a WIN server. <p><br><a name="OPTIONS"></a> @@ -58,9 +58,9 @@ WIN server. <p><br><ul> <p><br><a name="minusD"></a> -<li><strong><strong>-D</strong></strong> If specified, this parameter causes the server to operate +<li><strong><strong>-D</strong></strong> If specified, this parameter causes <strong>nmbd</strong> to operate as a daemon. That is, it detaches itself and runs in the background, -fielding requests on the appropriate port. By default, the server will +fielding requests on the appropriate port. By default, <strong>nmbd</strong> will NOT operate as a daemon. nmbd can also be operated from the inetd meta-daemon, although this is not recommended. <p><br><a name="minusa"></a> @@ -74,15 +74,16 @@ to. <li><strong><strong>-H filename</strong></strong> NetBIOS lmhosts file. <p><br>The lmhosts file is a list of NetBIOS names to IP addresses that is loaded by the nmbd server and used via the name resolution mechanism -<em>name resolve order</em> described in <strong>smbd.conf (5)</strong> to resolve any +<a href="smb.conf.5.html#nameresolveorder"><strong>name resolve order</strong></a> described in +<a href="smb.conf.5.html"><strong>smb.conf (5)</strong></a> to resolve any NetBIOS name queries needed by the server. Note that the contents of -this file are <em>NOT</em> used by nmbd to answer any name queries, adding +this file are <em>NOT</em> used by <strong>nmbd</strong> to answer any name queries. Adding a line to this file affects name NetBIOS resolution from this host <em>ONLY</em>. <p><br>The default path to this file is compiled into Samba as part of the build process. Common defaults are <em>/usr/local/samba/lib/lmhosts</em>, -<em>/usr/samba/lib/lmhosts</em> or <em>/etc/lmhosts</em>. See the <strong>lmhosts -(5)</strong> man page for details on the contents of this file. +<em>/usr/samba/lib/lmhosts</em> or <em>/etc/lmhosts</em>. See the +<a href="lmhosts.5.html"><strong>lmhosts (5)</strong></a> man page for details on the contents of this file. <p><br><a name="minusd"></a> <li><strong><strong>-d debuglevel</strong></strong> debuglevel is an integer from 0 to 10. <p><br>The default value if this parameter is not specified is zero. @@ -105,7 +106,7 @@ be logged. The actual log file name is generated by appending the extension ".nmb" to the specified base name. For example, if the name specified was "log" then the file log.nmb would contain the debugging data. -<p><br>The default log file path is is compiled into Samba as part of the +<p><br>The default log file path is compiled into Samba as part of the build process. Common defaults are <em>/usr/local/samba/var/log.nmb</em>, <em>/usr/samba/var/log.nmb</em> or <em>/var/log/log.nmb</em>. <p><br><a name="minusn"></a> @@ -117,7 +118,7 @@ but will override the setting in the <a href="smb.conf.5.html"><strong>smb.conf< <p><br><a name="minusp"></a> <li><strong><strong>-p UDP port number</strong></strong> UDP port number is a positive integer value. <p><br>This option changes the default UDP port number (normally 137) that -nmbd responds to name queries on. Don't use this option unless you are +<strong>nmbd</strong> responds to name queries on. Don't use this option unless you are an expert, in which case you won't need help! <p><br><a name="minuss"></a> <li><strong><strong>-s configuration file</strong></strong> The default configuration file name is @@ -126,14 +127,14 @@ this may be changed when Samba is autoconfigured. <p><br>The file specified contains the configuration details required by the server. See <a href="smb.conf.5.html"><strong>smb.conf (5)</strong></a> for more information. <p><br><a name="minusi"></a> -<li><strong><strong>-i scope</strong></strong> This specifies a NetBIOS scope that the server will use +<li><strong><strong>-i scope</strong></strong> This specifies a NetBIOS scope that <strong>nmbd</strong> will use to communicate with when generating NetBIOS names. For details on the use of NetBIOS scopes, see rfc1001.txt and rfc1002.txt. NetBIOS scopes are <em>very</em> rarely used, only set this parameter if you are the system administrator in charge of all the NetBIOS systems you communicate with. <p><br><a name="minush"></a> -<li><strong><strong>-h</strong></strong> Prints the help information (usage) for nmbd. +<li><strong><strong>-h</strong></strong> Prints the help information (usage) for <strong>nmbd</strong>. <p><br></ul> <p><br><a name="FILES"></a> <h2>FILES</h2> @@ -142,11 +143,12 @@ communicate with. <p><br>If the server is to be run by the inetd meta-daemon, this file must contain suitable startup information for the meta-daemon. <p><br><strong>/etc/rc</strong> -<p><br>(or whatever initialisation script your system uses). +<p><br>(or whatever initialization script your system uses). <p><br>If running the server as a daemon at startup, this file will need to contain an appropriate startup sequence for the server. <p><br><strong>/usr/local/samba/lib/smb.conf</strong> -<p><br>This is the default location of the <em>smb.conf</em> server configuration +<p><br>This is the default location of the +<a href="smb.conf.5.html"><strong>smb.conf</strong></a> server configuration file. Other common places that systems install this file are <em>/usr/samba/lib/smb.conf</em> and <em>/etc/smb.conf</em>. <p><br>When run as a <strong>WINS</strong> server (see the <a href="smb.conf.5.html#winssupport"><strong>wins support</strong></a> @@ -160,17 +162,17 @@ configured under wherever Samba was configured to install itself. <p><br><a name="SIGNALS"></a> <h2>SIGNALS</h2> -<p><br>To shut down an nmbd process it is recommended that SIGKILL (-9) +<p><br>To shut down an <strong>nmbd</strong> process it is recommended that SIGKILL (-9) <em>NOT</em> be used, except as a last resort, as this may leave the name -database in an inconsistant state. The correct way to terminate -nmbd is to send it a SIGTERM (-15) signal and wait for it to die on +database in an inconsistent state. The correct way to terminate +<strong>nmbd</strong> is to send it a SIGTERM (-15) signal and wait for it to die on its own. -<p><br>nmbd will accept SIGHUP, which will cause it to dump out it's -namelists into the file namelist.debug in the +<p><br><strong>nmbd</strong> will accept SIGHUP, which will cause it to dump out it's +namelists into the file <code>namelist.debug</code> in the <em>/usr/local/samba/var/locks</em> directory (or the <em>var/locks</em> directory configured under wherever Samba was configured to install -itself). This will also cause nmbd to dump out it's server database in -the log.nmb file. In addition, the the debug log level of nmbd may be raised +itself). This will also cause <strong>nmbd</strong> to dump out it's server database in +the log.nmb file. In addition, the debug log level of nmbd may be raised by sending it a SIGUSR1 (<code>kill -USR1 <nmbd-pid></code>) and lowered by sending it a SIGUSR2 (<code>kill -USR2 <nmbd-pid></code>). This is to allow transient problems to be diagnosed, whilst still running at a normally low log @@ -193,7 +195,7 @@ available as a link from the Web page : <h2>AUTHOR</h2> <p><br>The original Samba software and related utilities were created by -Andrew Tridgell (samba-bugs@samba.anu.edu.au). Samba is now developed +Andrew Tridgell <a href="mailto:samba-bugs@samba.anu.edu.au"><em>samba-bugs@samba.anu.edu.au</em></a>. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed. <p><br>The original Samba man pages were written by Karl Auer. The man page diff --git a/docs/htmldocs/nmblookup.1.html b/docs/htmldocs/nmblookup.1.html index 9fbab962a2..217ddd7965 100644 --- a/docs/htmldocs/nmblookup.1.html +++ b/docs/htmldocs/nmblookup.1.html @@ -3,7 +3,7 @@ -<html><head><title>nmblookup</title> +<html><head><title>nmblookup (1)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>nmblookup</h1> +<h1>nmblookup (1)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -31,7 +31,7 @@ <p><br>This program is part of the <strong>Samba</strong> suite. <p><br><strong>nmblookup</strong> is used to query NetBIOS names and map them to IP addresses in a network using NetBIOS over TCP/IP queries. The options -allow the name queries to be directed at a particlar IP broadcast area +allow the name queries to be directed at a particular IP broadcast area or to a particular machine. All queries are done over UDP. <p><br><a name="OPTIONS"></a> <h2>OPTIONS</h2> @@ -49,12 +49,13 @@ NetBIOS processing code on a machine is used instead. See rfc1001, rfc1002 for details. <p><br><a name="minusS"></a> <li><strong><strong>-S</strong></strong> Once the name query has returned an IP address then do a -node status query as well. +node status query as well. A node status query returns the NetBIOS names +registered by a host. <p><br><a name="minusr"></a> <li><strong><strong>-r</strong></strong> Try and bind to UDP port 137 to send and receive UDP datagrams. The reason for this option is a bug in Windows 95 where it ignores the source port of the requesting packet and only replies to -UDP port 137. Unfortunately, on most UNIX systems root privillage is +UDP port 137. Unfortunately, on most UNIX systems root privilage is needed to bind to this port, and in addition, if the <a href="nmbd.8.html"><strong>nmbd</strong></a> daemon is running on this machine it also binds to this port. @@ -89,11 +90,11 @@ level</strong></a> parameter in the <a href="smb.conf.5.html"><strong>smb.conf (5)</strong></a> file. <p><br><a name="minuss"></a> <li><strong><strong>-s smb.conf</strong></strong> This parameter specifies the pathname to the -Samba configuration file, smb.conf. This file controls all aspects of -the Samba setup on the machine and smbclient also needs to read this -file. +Samba configuration file, <a href="smb.conf.5.html"><strong>smb.conf</strong></a>. +This file controls all aspects of +the Samba setup on the machine. <p><br><a name="minusi"></a> -<li><strong><strong>-i scope</strong></strong> This specifies a NetBIOS scope that smbclient will use +<li><strong><strong>-i scope</strong></strong> This specifies a NetBIOS scope that <strong>nmblookup</strong> will use to communicate with when generating NetBIOS names. For details on the use of NetBIOS scopes, see rfc1001.txt and rfc1002.txt. NetBIOS scopes are <em>very</em> rarely used, only set this parameter if you are the @@ -103,14 +104,15 @@ communicate with. <li><strong><strong>name</strong></strong> This is the NetBIOS name being queried. Depending upon the previous options this may be a NetBIOS name or IP address. If a NetBIOS name then the different name types may be specified by -appending <code>#<type></code> to the name. +appending <code>#<type></code> to the name. This name may also be <code>"*"</code>, +which will return all registered names within a broadcast area. <p><br></ul> <p><br><a name="EXAMPLES"></a> <h2>EXAMPLES</h2> -<p><br><strong>nmblookup</strong> can be used to query a WINS server (in the same way .B -nslookup is used to query DNS servers). To query a WINS server, -nmblookup must be called like this: +<p><br><strong>nmblookup</strong> can be used to query a WINS server (in the same way +<strong>nslookup</strong> is used to query DNS servers). To query a WINS server, +<strong>nmblookup</strong> must be called like this: <p><br><code>nmblookup -U server -R 'name'</code> <p><br>For example, running : <p><br><code>nmblookup -U samba.anu.edu.au -R IRIX#1B'</code> @@ -129,7 +131,7 @@ browser (1B name type) for the IRIX workgroup. <h2>AUTHOR</h2> <p><br>The original Samba software and related utilities were created by -Andrew Tridgell (samba-bugs@samba.anu.edu.au). Samba is now developed +Andrew Tridgell <a href="mailto:samba-bugs@samba.anu.edu.au"><em>samba-bugs@samba.anu.edu.au</em></a>. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed. <p><br>The original Samba man pages were written by Karl Auer. The man page diff --git a/docs/htmldocs/samba.7.html b/docs/htmldocs/samba.7.html index 1408b2163d..1f6b8a0ae5 100644 --- a/docs/htmldocs/samba.7.html +++ b/docs/htmldocs/samba.7.html @@ -2,7 +2,7 @@ -<html><head><title>Samba</title> +<html><head><title>Samba (7)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -10,7 +10,7 @@ <hr> -<h1>Samba</h1> +<h1>Samba (7)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -28,7 +28,7 @@ <h2>DESCRIPTION</h2> <p><br>The Samba software suite is a collection of programs that implements -the Server Message Block(commenly abbreviated as SMB) protocol for +the Server Message Block(commonly abbreviated as SMB) protocol for UNIX systems. This protocol is sometimes also referred to as the Common Internet File System (CIFS), LanManager or NetBIOS protocol. <p><br><a name="COMPONENTS"></a> @@ -38,7 +38,8 @@ Common Internet File System (CIFS), LanManager or NetBIOS protocol. described in a separate manual page. It is strongly recommended that you read the documentation that comes with Samba and the manual pages of those components that you use. If the manual pages aren't clear -enough then please send a patch to <a href="mailto:samba-bugs@samba.anu.edu.au"><em>samba-bugs@samba.anu.edu.au</em></a>. +enough then please send a patch or bug report +to <a href="mailto:samba-bugs@samba.anu.edu.au"><em>samba-bugs@samba.anu.edu.au</em></a>. <p><br><ul> <p><br><li><strong><a href="smbd.8.html"><strong>smbd</strong></a></strong> <br> <br> The <a href="smbd.8.html"><strong>smbd</strong> (8)</a> daemon provides the file and print services to SMB @@ -62,8 +63,8 @@ Windows NT). (1)</strong></a> utility allows you to test the printers defined in your printcap file. <p><br><li><strong><a href="smbstatus.1.html"><strong>smbstatus</strong></a></strong> <br> <br> The <a href="smbstatus.1.html"><strong>smbstatus</strong> -(1)</a> utility allows you to tell who is currently -using the <a href="smbd.8.html"><strong>smbd (8)</strong></a> server. +(1)</a> utility allows you list current connections to the +<a href="smbd.8.html"><strong>smbd (8)</strong></a> server. <p><br><li><strong><a href="nmblookup.1.html"><strong>nmblookup</strong></a></strong> <br> <br> the <a href="nmblookup.1.html"><strong>nmblookup (1)</strong></a> utility allows NetBIOS name queries to be made from the UNIX machine. @@ -81,7 +82,7 @@ passwords on Samba and Windows NT(tm) servers. <p><br>The Samba software suite is licensed under the GNU Public License (GPL). A copy of that license should have come with the package in the file COPYING. You are encouraged to distribute copies of the Samba -suite, but please keep obey the terms of this license. +suite, but please obey the terms of this license. <p><br>The latest version of the Samba suite can be obtained via anonymous ftp from samba.anu.edu.au in the directory pub/samba/. It is also available on several mirror sites worldwide. @@ -107,7 +108,7 @@ for details on how to do this. <p><br>If you have patches to submit or bugs to report then you may mail them directly to <a href="mailto:samba-bugs@samba.anu.edu.au"><em>samba-bugs@samba.anu.edu.au</em></a>. Note, however, that due to the enormous popularity of this package the Samba Team may take some -time to repond to mail. We prefer patches in <em>diff -u</em> format. +time to respond to mail. We prefer patches in <em>diff -u</em> format. <p><br><a name="CREDITS"></a> <h2>CREDITS</h2> @@ -119,7 +120,7 @@ for the pre-CVS changes and at for the contributors to Samba post-CVS. CVS is the Open Source source code control system used by the Samba Team to develop Samba. The project would have been unmanageable without it. -<p><br>In addition, several commercial organisations now help fund the Samba +<p><br>In addition, several commercial organizations now help fund the Samba Team with money and equipment. For details see the Samba Web pages at <a href="http://samba.anu.edu.au/samba/samba-thanks.html">http://samba.anu.edu.au/samba/samba-thanks.html</a>. <p><br><a name="AUTHOR"></a> diff --git a/docs/htmldocs/smb.conf.5.html b/docs/htmldocs/smb.conf.5.html index b1ff9dd3f2..a0c1eb82b3 100644 --- a/docs/htmldocs/smb.conf.5.html +++ b/docs/htmldocs/smb.conf.5.html @@ -3,7 +3,7 @@ -<html><head><title>smb.conf</title> +<html><head><title>smb.conf (5)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>smb.conf</h1> +<h1>smb.conf (5)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -81,7 +81,7 @@ them. The client provides the username. As older clients only provide passwords and not usernames, you may specify a list of usernames to check against the password using the <a href="smb.conf.5.html#user"><strong>"user="</strong></a> option in the share definition. For modern clients such as Windows 95/98 and -Windows NT, this should not be neccessary. +Windows NT, this should not be necessary. <p><br>Note that the access rights granted by the server are masked by the access rights granted to the specified or guest UNIX user by the host system. The server does not grant more access than the host system @@ -94,7 +94,7 @@ the share name "foo": [foo] path = /home/bar - writable = true + writeable = true </pre> @@ -159,7 +159,7 @@ following is a typical and suitable [homes] section: <p><br><pre> [homes] - writable = yes + writeable = yes </pre> @@ -197,14 +197,14 @@ given, the username is set to the located printer name. <p><br></ul> <p><br>Note that the [printers] service MUST be printable - if you specify otherwise, the server will refuse to load the configuration file. -<p><br>Typically the path specified would be that of a world-writable spool +<p><br>Typically the path specified would be that of a world-writeable spool directory with the sticky bit set on it. A typical [printers] entry would look like this: <p><br><pre> [printers] path = /usr/spool/public - writable = no + writeable = no guest ok = yes printable = yes @@ -221,7 +221,7 @@ this: <p><br>Each alias should be an acceptable printer name for your printing subsystem. In the <a href="smb.conf.5.html#global"><strong>[global]</strong></a> section, specify the new -file as your printcap. The server will then only recognise names +file as your printcap. The server will then only recognize names found in your pseudo-printcap, which of course can contain whatever aliases you like. The same technique could be used simply to limit access to a subset of your local printers. @@ -233,15 +233,15 @@ of a printcap record. Records are separated by newlines, components defined on the system you may be able to use <a href="smb.conf.5.html#printcapname"><strong>"printcap name = lpstat"</strong></a> to automatically obtain a list of printers. See the <a href="smb.conf.5.html#printcapname"><strong>"printcap name"</strong></a> option for -more detils. +more details. <p><br></ul> <p><br><a name="PARAMETERS"></a> <h2>PARAMETERS</h2> <p><br>Parameters define the specific attributes of sections. <p><br>Some parameters are specific to the <a href="smb.conf.5.html#global"><strong>[global]</strong></a> section -(eg., <a href="smb.conf.5.html#security"><strong>security</strong></a>). Some parameters are usable in -all sections (eg., <a href="smb.conf.5.html#createmode"><strong>create mode</strong></a>). All others are +(e.g., <a href="smb.conf.5.html#security"><strong>security</strong></a>). Some parameters are usable in +all sections (e.g., <a href="smb.conf.5.html#createmode"><strong>create mode</strong></a>). All others are permissible only in normal sections. For the purposes of the following descriptions the <a href="smb.conf.5.html#homes"><strong>[homes]</strong></a> and <a href="smb.conf.5.html#printers"><strong>[printers]</strong></a> sections will be considered normal. @@ -250,7 +250,7 @@ specific to the <a href="smb.conf.5.html#global"><strong>[global]</strong></a> s indicates that a parameter can be specified in a service specific section. Note that all <code>'S'</code> parameters can also be specified in the <a href="smb.conf.5.html#global"><strong>[global]</strong></a> section - in which case they will define -the default behaviour for all services. +the default behavior for all services. <p><br>Parameters are arranged here in alphabetical order - this may not create best bedfellows, but at least you can find them! Where there are synonyms, the preferred synonym is described, others refer to the @@ -308,8 +308,8 @@ negotiation. It can be one of CORE, COREPLUS, LANMAN1, LANMAN2 or NT1. <li > <strong>%d</strong> = The process id of the current server process. <p><br><a name="percenta"></a> <li > <strong>%a</strong> = the architecture of the remote -machine. Only some are recognised, and those may not be 100% -reliable. It currently recognises Samba, WfWg, WinNT and +machine. Only some are recognized, and those may not be 100% +reliable. It currently recognizes Samba, WfWg, WinNT and Win95. Anything else will be known as "UNKNOWN". If it gets it wrong then sending a level 3 log to <a href="mailto:samba-bugs@samba.anu.edu.au"><em>samba-bugs@samba.anu.edu.au</em></a> should allow it to be fixed. @@ -717,7 +717,7 @@ regardless if the owner of the file is the currently logged on user or not. <p><br>This specifies what type of server <a href="nmbd.8.html"><strong>nmbd</strong></a> will announce itself as, to a network neighborhood browse list. By default this is set to Windows NT. The valid options are : "NT", "Win95" or -"WfW" meaining Windows NT, Windows 95 and Windows for Workgroups +"WfW" meaning Windows NT, Windows 95 and Windows for Workgroups respectively. Do not change this parameter unless you have a specific need to stop Samba appearing as an NT server as this may prevent Samba servers from participating as browser servers correctly. @@ -784,7 +784,7 @@ the interface list given in the <a href="smb.conf.5.html#interfaces"><strong>'in parameter. This restricts the networks that <a href="smbd.8.html"><strong>smbd</strong></a> will serve to packets coming in those interfaces. Note that you should not use this parameter for machines that are serving PPP or -other intermittant or non-broadcast network interfaces as it will not +other intermittent or non-broadcast network interfaces as it will not cope with non-permanent interfaces. <p><br>In addition, to change a users SMB password, the <a href="smbpasswd.8.html"><strong>smbpasswd</strong></a> by default connects to the @@ -820,13 +820,8 @@ request immediately if the lock range cannot be obtained. <p><br><strong>Example:</strong> <code> blocking locks = False</code> <p><br><a name="browsable"></a> -<li><strong><strong>broweable (S)</strong></strong> -<p><br>This controls whether this share is seen in the list of available -shares in a net view and in the browse list. -<p><br><strong>Default:</strong> -<code> browsable = Yes</code> -<p><br><strong>Example:</strong> -<code> browsable = No</code> +<li><strong><strong>browseable (S)</strong></strong> +<p><br>Synonym for <a href="smb.conf.5.html#browseable"><strong>browseable</strong></a>. <p><br><a name="browselist"></a> <li><strong><strong>browse list(G)</strong></strong> <p><br>This controls whether <a href="smbd.8.html"><strong>smbd</strong></a> will serve a browse @@ -836,7 +831,12 @@ should never need to change this. <code> browse list = Yes</code> <p><br><a name="browseable"></a> <li><strong><strong>browseable</strong></strong> -<p><br>Synonym for <a href="smb.conf.5.html#browsable"><strong>browsable</strong></a>. +<p><br>This controls whether this share is seen in the list of available +shares in a net view and in the browse list. +<p><br><strong>Default:</strong> +<code> browseable = Yes</code> +<p><br><strong>Example:</strong> +<code> browseable = No</code> <p><br><a name="casesensitive"></a> <li><strong><strong>case sensitive (G)</strong></strong> <p><br>See the discussion in the section <a href="smb.conf.5.html#NAMEMANGLING"><strong>NAME MANGLING</strong></a>. @@ -907,7 +907,7 @@ described more fully in the manual page <a href="make_smbcodepage.1.html"><stron (1)</strong></a>, tell <a href="smbd.8.html"><strong>smbd</strong></a> how to map lower to upper case characters to provide the case insensitivity of filenames that Windows clients expect. -<p><br>Samba currenly ships with the following code page files : +<p><br>Samba currently ships with the following code page files : <p><br><ul> <p><br><li > <strong>Code Page 437 - MS-DOS Latin US</strong> <p><br><li > <strong>Code Page 737 - Windows '95 Greek</strong> @@ -960,10 +960,10 @@ codes. Shift-JIS to JUNET code with different shift-in, shift out codes. <p><br><li > <strong>EUC</strong> Convert an incoming Shift-JIS character to EUC code. <p><br><li > <strong>HEX</strong> Convert an incoming Shift-JIS character to a 3 byte hex -representation, ie. <code>:AB</code>. +representation, i.e. <code>:AB</code>. <p><br><li > <strong>CAP</strong> Convert an incoming Shift-JIS character to the 3 byte hex -representation used by the Columbia Appletalk Program (CAP), -ie. <code>:AB</code>. This is used for compatibility between Samba and CAP. +representation used by the Columbia AppleTalk Program (CAP), +i.e. <code>:AB</code>. This is used for compatibility between Samba and CAP. <p><br></ul> <p><br><a name="comment"></a> <li><strong><strong>comment (S)</strong></strong> @@ -1005,7 +1005,7 @@ in the configuration file than the service doing the copying. <p><br><a name="createmask"></a> <li><strong><strong>create mask (S)</strong></strong> <p><br>A synonym for this parameter is <a href="smb.conf.5.html#createmode"><strong>'create mode'</strong></a>. -<p><br>When a file is created, the neccessary permissions are calculated +<p><br>When a file is created, the necessary permissions are calculated according to the mapping from DOS modes to UNIX permissions, and the resulting UNIX mode is then bit-wise 'AND'ed with this parameter. This parameter may be thought of as a bit-wise MASK for the UNIX modes @@ -1123,7 +1123,7 @@ you want. delete any files and directories within the vetoed directory. This can be useful for integration with file serving systems such as <strong>NetAtalk</strong>, which create meta-files within directories you might normally veto -DOS/Windows users from seeing (eg. <code>.AppleDouble</code>) +DOS/Windows users from seeing (e.g. <code>.AppleDouble</code>) <p><br>Setting <code>'delete veto files = True'</code> allows these directories to be transparently deleted when the parent directory is deleted (so long as the user has permissions to do so). @@ -1161,7 +1161,7 @@ second should be the number of available blocks. An optional third return value can give the block size in bytes. The default blocksize is 1024 bytes. <p><br>Note: Your script should <em>NOT</em> be setuid or setgid and should be -owned by (and writable only by) root! +owned by (and writeable only by) root! <p><br><strong>Default:</strong> <code> By default internal routines for determining the disk capacity and remaining space will be used.</code> @@ -1192,7 +1192,7 @@ path names on some systems. <li><strong><strong>directory mask (S)</strong></strong> <p><br>This parameter is the octal modes which are used when converting DOS modes to UNIX modes when creating UNIX directories. -<p><br>When a directory is created, the neccessary permissions are calculated +<p><br>When a directory is created, the necessary permissions are calculated according to the mapping from DOS modes to UNIX permissions, and the resulting UNIX mode is then bit-wise 'AND'ed with this parameter. This parameter may be thought of as a bit-wise MASK for the UNIX modes @@ -1203,7 +1203,7 @@ write bits from the UNIX mode, allowing only the user who owns the directory to modify it. <p><br>Following this Samba will bit-wise 'OR' the UNIX mode created from this parameter with the value of the "force directory mode" -parameter. This parameter is set to 000 by default (ie. no extra mode +parameter. This parameter is set to 000 by default (i.e. no extra mode bits are added). <p><br>See the <a href="smb.conf.5.html#forcedirectorymode"><strong>"force directory mode"</strong></a> parameter to cause particular mode bits to always be set on created directories. @@ -1236,7 +1236,7 @@ DNS name lookup requests, as doing a name lookup is a blocking action. <p><br>This is an <strong>EXPERIMENTAL</strong> parameter that is part of the unfinished Samba NT Domain Controller Code. It may be removed in a later release. To work with the latest code builds that may have more support for -Samba NT Domain Controller functionality please subscibe to the +Samba NT Domain Controller functionality please subscribe to the mailing list <strong>Samba-ntdom</strong> available by sending email to <a href="mailto:listproc@samba.anu.edu.au"><em>listproc@samba.anu.edu.au</em></a> <p><br><a name="domainadminusers"></a> @@ -1244,7 +1244,7 @@ mailing list <strong>Samba-ntdom</strong> available by sending email to <p><br>This is an <strong>EXPERIMENTAL</strong> parameter that is part of the unfinished Samba NT Domain Controller Code. It may be removed in a later release. To work with the latest code builds that may have more support for -Samba NT Domain Controller functionality please subscibe to the +Samba NT Domain Controller functionality please subscribe to the mailing list <strong>Samba-ntdom</strong> available by sending email to <a href="mailto:listproc@samba.anu.edu.au"><em>listproc@samba.anu.edu.au</em></a> <p><br><a name="domaincontroller"></a> @@ -1257,7 +1257,7 @@ files. It is left behind for compatibility reasons. <p><br>This is an <strong>EXPERIMENTAL</strong> parameter that is part of the unfinished Samba NT Domain Controller Code. It may be removed in a later release. To work with the latest code builds that may have more support for -Samba NT Domain Controller functionality please subscibe to the +Samba NT Domain Controller functionality please subscribe to the mailing list <strong>Samba-ntdom</strong> available by sending email to <a href="mailto:listproc@samba.anu.edu.au"><em>listproc@samba.anu.edu.au</em></a> <p><br><a name="domainguestgroup"></a> @@ -1265,7 +1265,7 @@ mailing list <strong>Samba-ntdom</strong> available by sending email to <p><br>This is an <strong>EXPERIMENTAL</strong> parameter that is part of the unfinished Samba NT Domain Controller Code. It may be removed in a later release. To work with the latest code builds that may have more support for -Samba NT Domain Controller functionality please subscibe to the +Samba NT Domain Controller functionality please subscribe to the mailing list <strong>Samba-ntdom</strong> available by sending email to <a href="mailto:listproc@samba.anu.edu.au"><em>listproc@samba.anu.edu.au</em></a> <p><br><a name="domainguestusers"></a> @@ -1273,7 +1273,7 @@ mailing list <strong>Samba-ntdom</strong> available by sending email to <p><br>This is an <strong>EXPERIMENTAL</strong> parameter that is part of the unfinished Samba NT Domain Controller Code. It may be removed in a later release. To work with the latest code builds that may have more support for -Samba NT Domain Controller functionality please subscibe to the +Samba NT Domain Controller functionality please subscribe to the mailing list <strong>Samba-ntdom</strong> available by sending email to <a href="mailto:listproc@samba.anu.edu.au"><em>listproc@samba.anu.edu.au</em></a> <p><br><a name="domainlogons"></a> @@ -1284,7 +1284,7 @@ details on setting up this feature see the file DOMAINS.txt in the Samba documentation directory <code>docs/</code> shipped with the source code. <p><br>Note that Win95/98 Domain logons are <em>NOT</em> the same as Windows NT Domain logons. NT Domain logons require a Primary Domain Controller -(PDC) for the Domain. It is inteded that in a future release Samba +(PDC) for the Domain. It is intended that in a future release Samba will be able to provide this functionality for Windows NT clients also. <p><br><strong>Default:</strong> @@ -1292,7 +1292,7 @@ also. <p><br><a name="domainmaster"></a> <li><strong><strong>domain master (G)</strong></strong> <p><br>Tell <a href="nmbd.8.html"><strong>nmbd</strong></a> to enable WAN-wide browse list -collation.Setting this option causes <a href="nmbd.8.html"><strong>nmbd</strong></a> to +collation. Setting this option causes <a href="nmbd.8.html"><strong>nmbd</strong></a> to claim a special domain specific NetBIOS name that identifies it as a domain master browser for its given <a href="smb.conf.5.html#workgroup"><strong>workgroup</strong></a>. Local master browsers in the same @@ -1305,7 +1305,7 @@ list, instead of just the list for their broadcast-isolated subnet. <p><br>Note that Windows NT Primary Domain Controllers expect to be able to claim this <a href="smb.conf.5.html#workgroup"><strong>workgroup</strong></a> specific special NetBIOS name that identifies them as domain master browsers for that -<a href="smb.conf.5.html#workgroup"><strong>workgroup</strong></a> by default (ie. there is no way to +<a href="smb.conf.5.html#workgroup"><strong>workgroup</strong></a> by default (i.e. there is no way to prevent a Windows NT PDC from attempting to do this). This means that if this parameter is set and <a href="nmbd.8.html"><strong>nmbd</strong></a> claims the special name for a <a href="smb.conf.5.html#workgroup"><strong>workgroup</strong></a> before a Windows NT @@ -1315,7 +1315,7 @@ and may fail. <code> domain master = no</code> <p><br><a name="dontdescend"></a> <li><strong><strong>dont descend (S)</strong></strong> -<p><br>There are certain directories on some systems (eg., the <code>/proc</code> tree +<p><br>There are certain directories on some systems (e.g., the <code>/proc</code> tree under Linux) that are either not of interest to clients or are infinitely deep (recursive). This parameter allows you to specify a comma-delimited list of directories that the server should always show @@ -1329,7 +1329,7 @@ just <code>"/proc"</code>. Experimentation is the best policy :-) <code> dont descend = /proc,/dev</code> <p><br><a name="dosfiletimeresolution"></a> <li><strong><strong>dos filetime resolution (S)</strong></strong> -<p><br>Under the DOS and Windows FAT filesystem, the finest granulatity on +<p><br>Under the DOS and Windows FAT filesystem, the finest granularity on time resolution is two seconds. Setting this parameter for a share causes Samba to round the reported time down to the nearest two second boundary when a query call that requires one second resolution is made @@ -1355,7 +1355,7 @@ the timestamp on it. Under POSIX semantics, only the owner of the file or root may change the timestamp. By default, Samba runs with POSIX semantics and refuses to change the timestamp on a file if the user smbd is acting on behalf of is not the file owner. Setting this option -to True allows DOS semantics and smbd will change the file timstamp as +to True allows DOS semantics and smbd will change the file timestamp as DOS requires. <p><br><strong>Default:</strong> <code> dos filetimes = False</code> @@ -1435,16 +1435,16 @@ same time you can get data corruption. Use this option carefully! particular share. Setting this parameter to <em>"No"</em> prevents any file or directory that is a symbolic link from being followed (the user will get an error). This option is very useful to stop users from -adding a symbolic link to <code>/etc/pasword</code> in their home directory for +adding a symbolic link to <code>/etc/passwd</code> in their home directory for instance. However it will slow filename lookups down slightly. -<p><br>This option is enabled (ie. <a href="smbd.8.html"><strong>smbd</strong></a> will follow +<p><br>This option is enabled (i.e. <a href="smbd.8.html"><strong>smbd</strong></a> will follow symbolic links) by default. <p><br><a name="forcecreatemode"></a> <li><strong><strong>force create mode (S)</strong></strong> <p><br>This parameter specifies a set of UNIX mode bit permissions that will <em>*always*</em> be set on a file created by Samba. This is done by bitwise 'OR'ing these bits onto the mode bits of a file that is being -created. The default for this parameter is (in octel) 000. The modes +created. The default for this parameter is (in octal) 000. The modes in this parameter are bitwise 'OR'ed onto the file mode after the mask set in the <a href="smb.conf.5.html#createmask"><strong>"create mask"</strong></a> parameter is applied. <p><br>See also the parameter <a href="smb.conf.5.html#createmask"><strong>"create mask"</strong></a> for details @@ -1461,7 +1461,7 @@ the 'user'. <p><br>This parameter specifies a set of UNIX mode bit permissions that will <em>*always*</em> be set on a directory created by Samba. This is done by bitwise 'OR'ing these bits onto the mode bits of a directory that is -being created. The default for this parameter is (in octel) 0000 which +being created. The default for this parameter is (in octal) 0000 which will not add any extra permission bits to a created directory. This operation is done after the mode mask in the parameter <a href="smb.conf.5.html#directorymask"><strong>"directory mask"</strong></a> is applied. @@ -1516,7 +1516,7 @@ Windows NT but this can be changed to other strings such as "Samba" or <code> fstype = Samba</code> <p><br><a name="getwdcache"></a> <li><strong><strong>getwd cache (G)</strong></strong> -<p><br>This is a tuning option. When this is enabled a cacheing algorithm +<p><br>This is a tuning option. When this is enabled a caching algorithm will be used to reduce the time taken for getwd() calls. This can have a significant impact on performance, especially when the <a href="smb.conf.5.html#widelinks"><strong>widelinks</strong></a> parameter is set to False. @@ -1584,8 +1584,8 @@ directories that match. <p><br>Each entry in the list must be separated by a <code>'/'</code>, which allows spaces to be included in the entry. <code>'*'</code> and <code>'?'</code> can be used to specify multiple files or directories as in DOS wildcards. -<p><br>Each entry must be a unix path, not a DOS path and must not include the -unix directory separator <code>'/'</code>. +<p><br>Each entry must be a Unix path, not a DOS path and must not include the +Unix directory separator <code>'/'</code>. <p><br>Note that the case sensitivity option is applicable in hiding files. <p><br>Setting this parameter will affect the performance of Samba, as it will be forced to check all files and directories for a match as they @@ -1719,7 +1719,7 @@ parameter allows the use of them to be turned on or off. <p><br>Kernel oplocks support allows Samba <a href="smb.conf.5.html#oplocks"><strong>oplocks</strong></a> to be broken whenever a local UNIX process or NFS operation accesses a file that <a href="smbd.8.html"><strong>smbd</strong></a> has oplocked. This allows complete -data consistancy between SMB/CIFS, NFS and local file access (and is a +data consistency between SMB/CIFS, NFS and local file access (and is a <em>very</em> cool feature :-). <p><br>This parameter defaults to <em>"On"</em> on systems that have the support, and <em>"off"</em> on systems that don't. You should never need to touch @@ -1832,7 +1832,7 @@ will be loaded for browsing by default. See the <a href="smb.conf.5.html#printers"><strong>"printers"</strong></a> section for more details. <p><br><strong>Default:</strong> <code> load printers = yes</code> -<p><br>bg(Example:) +<p><br><strong>Example:</strong> <code> load printers = no</code> <p><br><a name="localmaster"></a> <li><strong><strong>local master (G)</strong></strong> @@ -1926,14 +1926,14 @@ preferences and directories to be loaded onto the Windows 95/98 client. The share must be writeable when the logs in for the first time, in order that the Windows 95/98 client can create the user.dat and other directories. -<p><br>Thereafter, the directories and any of contents can, if required, be -made read-only. It is not adviseable that the USER.DAT file be made +<p><br>Thereafter, the directories and any of the contents can, if required, be +made read-only. It is not advisable that the USER.DAT file be made read-only - rename it to USER.MAN to achieve the desired effect (a <em>MAN</em>datory profile). <p><br>Windows clients can sometimes maintain a connection to the [homes] share, even though there is no user logged in. Therefore, it is vital that the logon path does not include a reference to the homes share -(i.e setting this parameter to <code>\\%N\HOMES\profile_path</code> will cause +(i.e. setting this parameter to <code>\\%N\HOMES\profile_path</code> will cause problems). <p><br>This option takes the standard substitutions, allowing you to have separate logon scripts for each user or machine. @@ -1956,7 +1956,7 @@ file that will be downloaded is: <p><br><code>/usr/local/samba/netlogon/STARTUP.BAT</code> <p><br>The contents of the batch file is entirely your choice. A suggested command would be to add <code>NET TIME \\SERVER /SET /YES</code>, to force every -machine to synchronise clocks with the same time server. Another use +machine to synchronize clocks with the same time server. Another use would be to add <code>NET USE U: \\SERVER\UTILS</code> for commonly used utilities, or <code>NET USE Q: \\SERVER\ISO9001_QA</code> for example. <p><br>Note that it is particularly important not to allow write access to @@ -2010,7 +2010,7 @@ the <strong>lpq</strong> command in use. previous identical <strong>lpq</strong> command will be used if the cached data is less than 10 seconds old. A large value may be advisable if your <strong>lpq</strong> command is very slow. -<p><br>A value of 0 will disable cacheing completely. +<p><br>A value of 0 will disable caching completely. <p><br>See also the <a href="smb.conf.5.html#printing"><strong>"printing"</strong></a> parameter. <p><br><strong>Default:</strong> <code> lpq cache time = 10</code> @@ -2135,8 +2135,8 @@ end. <p><br>See the section on <a href="smb.conf.5.html#NAMEMANGLING"><strong>"NAME MANGLING"</strong></a>. <p><br><a name="mangledmap"></a> <li><strong><strong>mangled map (S)</strong></strong> -<p><br>This is for those who want to directly map UNIX file names which are -not representable on Windows/DOS. The mangling of names is not always +<p><br>This is for those who want to directly map UNIX file names which can +not be represented on Windows/DOS. The mangling of names is not always what is needed. In particular you may have documents with file extensions that differ between DOS and UNIX. For example, under UNIX it is common to use <code>".html"</code> for HTML files, whereas under @@ -2144,7 +2144,7 @@ Windows/DOS <code>".htm"</code> is more commonly used. <p><br>So to map <code>"html"</code> to <code>"htm"</code> you would use: <p><br><code> mangled map = (*.html *.htm)</code> <p><br>One very useful case is to remove the annoying <code>";1"</code> off the ends -of filenames on some CDROMS (only visible under some UNIXes). To do +of filenames on some CDROMS (only visible under some UNIXs). To do this use a map of (*;1 *). <p><br><strong>default:</strong> <code> no mangled map</code> @@ -2233,7 +2233,7 @@ becoming executable under UNIX. This can be quite annoying for shared source code, documents, etc... <p><br>Note that this requires the <a href="smb.conf.5.html#createmask"><strong>"create mask"</strong></a> parameter to be set such that owner execute bit is not masked out -(ie. it must include 100). See the parameter <a href="smb.conf.5.html#createmask"><strong>"create +(i.e. it must include 100). See the parameter <a href="smb.conf.5.html#createmask"><strong>"create mask"</strong></a> for details. <p><br><strong>Default:</strong> <code> map archive = yes</code> @@ -2244,7 +2244,7 @@ mask"</strong></a> for details. <p><br>This controls whether DOS style hidden files should be mapped to the UNIX world execute bit. <p><br>Note that this requires the <a href="smb.conf.5.html#createmask"><strong>"create mask"</strong></a> to be -set such that the world execute bit is not masked out (ie. it must +set such that the world execute bit is not masked out (i.e. it must include 001). See the parameter <a href="smb.conf.5.html#createmask"><strong>"create mask"</strong></a> for details. <p><br><strong>Default:</strong> @@ -2256,7 +2256,7 @@ for details. <p><br>This controls whether DOS style system files should be mapped to the UNIX group execute bit. <p><br>Note that this requires the <a href="smb.conf.5.html#createmask"><strong>"create mask"</strong></a> to be -set such that the group execute bit is not masked out (ie. it must +set such that the group execute bit is not masked out (i.e. it must include 010). See the parameter <a href="smb.conf.5.html#createmask"><strong>"create mask"</strong></a> for details. <p><br><strong>Default:</strong> @@ -2266,7 +2266,7 @@ for details. <p><br><a name="maptoguest"></a> <li><strong><strong>map to guest (G)</strong></strong> <p><br>This parameter is only useful in <a href="smb.conf.5.html#security"><strong>security</strong></a> modes -other than <a href="smb.conf.5.html#securityequalshare"><strong>"security=share"</strong></a> - ie. user, +other than <a href="smb.conf.5.html#securityequalshare"><strong>"security=share"</strong></a> - i.e. user, server, and domain. <p><br>This parameter can take three different values, which tell <a href="smbd.8.html"><strong>smbd</strong></a> what to do with user login requests that @@ -2282,7 +2282,7 @@ account"</strong></a>. <p><br><li > <strong>"Bad Password"</strong> - Means user logins with an invalid password are treated as a guest login and mapped into the <a href="smb.conf.5.html#guestaccount"><strong>"guest account"</strong></a>. Note that this can -cause problems as it means that any user mistyping their +cause problems as it means that any user incorrectly typing their password will be silently logged on a <strong>"guest"</strong> - and will not know the reason they cannot access files they think they should - there will have been no message given to them @@ -2358,7 +2358,7 @@ never need to set this parameter. <p><br>This parameter limits the maximum number of open files that one <a href="smbd.8.html"><strong>smbd</strong></a> file serving process may have open for a client at any one time. The default for this parameter is set -very high (10,000) as Samba uses only one bit per un-opened file. +very high (10,000) as Samba uses only one bit per unopened file. <p><br>The limit of the number of open files is usually set by the UNIX per-process file descriptor limit rather than this parameter so you should never need to touch this parameter. @@ -2542,7 +2542,7 @@ system and the Samba server with this option must also be a <code> nis homedir = true</code> <p><br><a name="ntpipesupport"></a> <li><strong><strong>nt pipe support (G)</strong></strong> -<p><br>This boolean parameter controlls whether <a href="smbd.8.html"><strong>smbd</strong></a> +<p><br>This boolean parameter controls whether <a href="smbd.8.html"><strong>smbd</strong></a> will allow Windows NT clients to connect to the NT SMB specific <code>IPC$</code> pipes. This is a developer debugging option and can be left alone. @@ -2550,7 +2550,7 @@ alone. <code> nt pipe support = yes</code> <p><br><a name="ntsmbsupport"></a> <li><strong><strong>nt smb support (G)</strong></strong> -<p><br>This boolean parameter controlls whether <a href="smbd.8.html"><strong>smbd</strong></a> +<p><br>This boolean parameter controls whether <a href="smbd.8.html"><strong>smbd</strong></a> will negotiate NT specific SMB support with Windows NT clients. Although this is a developer debugging option and should be left alone, benchmarking has discovered that Windows NT clients give @@ -2607,14 +2607,14 @@ of the user. <li><strong><strong>oplocks (S)</strong></strong> <p><br>This boolean option tells smbd whether to issue oplocks (opportunistic locks) to file open requests on this share. The oplock code can -dramatically (approx 30% or more) improve the speed of access to files -on Samba servers. It allows the clients to agressively cache files +dramatically (approx. 30% or more) improve the speed of access to files +on Samba servers. It allows the clients to aggressively cache files locally and you may want to disable this option for unreliable network environments (it is turned on by default in Windows NT Servers). For more information see the file Speed.txt in the Samba docs/ directory. <p><br>Oplocks may be selectively turned off on certain files on a per share basis. -See the 'veto oplock files' parameter. On some systems oplocks are recognised -by the underlying operating system. This allows data synchronisation between +See the 'veto oplock files' parameter. On some systems oplocks are recognized +by the underlying operating system. This allows data synchronization between all access to oplocked files, whether it be via Samba or NFS or a local UNIX process. See the <a href="smb.conf.5.html#kerneloplocks"><strong>kernel oplocks</strong></a> parameter for details. @@ -2645,7 +2645,7 @@ old <strong>smb.conf</strong> files. <p><br>This is a Samba developer option that allows a system command to be called when either <a href="smbd.8.html"><strong>smbd</strong></a> or <a href="nmbd.8.html"><strong>nmbd</strong></a> crashes. This is usually used to draw -attention to the fact that a problem occured. +attention to the fact that a problem occurred. <p><br><strong>Default:</strong> <code> panic action = <empty string></code> <p><br><a name="passwdchat"></a> @@ -2710,7 +2710,7 @@ program"</strong></a>. <li><strong><strong>passwd program (G)</strong></strong> <p><br>The name of a program that can be used to set UNIX user passwords. Any occurrences of <a href="smb.conf.5.html#percentu"><strong>%u</strong></a> will be replaced with the -user name. The user name is checked for existance before calling the +user name. The user name is checked for existence before calling the password changing program. <p><br>Also note that many passwd programs insist in <em>"reasonable"</em> passwords, such as a minimum length, or the inclusion of mixed case @@ -2719,7 +2719,7 @@ Windows for Workgroups) uppercase the password before sending it. <p><br><em>Note</em> that if the <a href="smb.conf.5.html#unixpasswordsync"><strong>"unix password sync"</strong></a> parameter is set to <code>"True"</code> then this program is called <em>*AS ROOT*</em> before the SMB password in the -<a href="smbpasswd.5.html"><strong>smbpassswd</strong></a> file is changed. If this UNIX +<a href="smbpasswd.5.html"><strong>smbpasswd</strong></a> file is changed. If this UNIX password change fails, then <a href="smbd.8.html"><strong>smbd</strong></a> will fail to change the SMB password also (this is by design). <p><br>If the <a href="smb.conf.5.html#unixpasswordsync"><strong>"unix password sync"</strong></a> parameter is @@ -2789,8 +2789,8 @@ better restrict them with hosts allow! <p><br>If the <a href="smb.conf.5.html#security"><strong>"security"</strong></a> parameter is set to <strong>"domain"</strong>, then the list of machines in this option must be a list of Primary or Backup Domain controllers for the -<a href="smb.conf.5.html#workgroup"><strong>Domain</strong></a>, as the Samba server is cryptographically -in that domain, and will use crpytographically authenticated RPC calls +<a href="smb.conf.5.html#workgroup"><strong>Domain</strong></a>, as the Samba server is cryptographicly +in that domain, and will use cryptographicly authenticated RPC calls to authenticate the user logging on. The advantage of using <a href="smb.conf.5.html#securityequaldomain"><strong>"security=domain"</strong></a> is that if you list several hosts in the <strong>"password server"</strong> option then @@ -2827,7 +2827,7 @@ is to be given access. In the case of printable services, this is where print data will spool prior to being submitted to the host for printing. <p><br>For a printable service offering guest access, the service should be -readonly and the path should be world-writable and have the sticky bit +readonly and the path should be world-writeable and have the sticky bit set. This is not mandatory of course, but you probably won't get the results you expect if you do otherwise. <p><br>Any occurrences of <a href="smb.conf.5.html#percentu"><strong>%u</strong></a> in the path will be replaced @@ -2948,11 +2948,11 @@ have its own print command specified. <p><br>If there is neither a specified print command for a printable service nor a global print command, spool files will be created but not processed and (most importantly) not removed. -<p><br>Note that printing may fail on some UNIXes from the <code>"nobody"</code> +<p><br>Note that printing may fail on some UNIXs from the <code>"nobody"</code> account. If this happens then create an alternative guest account that can print and set the <a href="smb.conf.5.html#guestaccount"><strong>"guest account"</strong></a> in the <a href="smb.conf.5.html#global"><strong>"[global]"</strong></a> section. -<p><br>You can form quite complex print commands by realising that they are +<p><br>You can form quite complex print commands by realizing that they are just passed to a shell. For example the following will log a print job, print the file, then remove it. Note that <code>';'</code> is the usual separator for command in shell scripts. @@ -3144,7 +3144,7 @@ command as the PATH may not be available to the server. <li><strong><strong>queueresume command (S)</strong></strong> <p><br>This parameter specifies the command to be executed on the server host in order to resume the printerqueue. It is the command to undo the -behaviour that is caused by the previous parameter +behavior that is caused by the previous parameter (<a href="smb.conf.5.html#queuepausecommand"><strong>"queuepause command</strong></a>). <p><br>This command should be a program or script which takes a printer name as its only parameter and resumes the printerqueue, such that queued @@ -3182,8 +3182,8 @@ the <a href="smb.conf.5.html#invalidusers"><strong>"invalid users"</strong></a> <p><br><a name="readonly"></a> <li><strong><strong>read only (S)</strong></strong> <p><br>Note that this is an inverted synonym for -<a href="smb.conf.5.html#writable"><strong>"writable"</strong></a> and <a href="smb.conf.5.html#writeok"><strong>"write ok"</strong></a>. -<p><br>See also <a href="smb.conf.5.html#writable"><strong>"writable"</strong></a> and <a href="smb.conf.5.html#writeok"><strong>"write +<a href="smb.conf.5.html#writeable"><strong>"writeable"</strong></a> and <a href="smb.conf.5.html#writeok"><strong>"write ok"</strong></a>. +<p><br>See also <a href="smb.conf.5.html#writeable"><strong>"writeable"</strong></a> and <a href="smb.conf.5.html#writeok"><strong>"write ok"</strong></a>. <p><br><a name="readprediction"></a> <li><strong><strong>read prediction (G)</strong></strong> @@ -3256,7 +3256,7 @@ browse masters if your network config is that stable. <p><br><a name="remotebrowsesync"></a> <li><strong><strong>remote browse sync (G)</strong></strong> <p><br>This option allows you to setup <a href="nmbd.8.html"><strong>nmbd</strong></a> to -periodically request synchronisation of browse lists with the master +periodically request synchronization of browse lists with the master browser of a samba server that is on a remote segment. This option will allow you to gain browse lists for multiple workgroups across routed networks. This is done in a manner that does not work with any @@ -3268,7 +3268,7 @@ send IP packets to. <p><br>For example: <p><br><code> remote browse sync = 192.168.2.255 192.168.4.255</code> <p><br>the above line would cause <a href="nmbd.8.html"><strong>nmbd</strong></a> to request the -master browser on the specified subnets or addresses to synchronise +master browser on the specified subnets or addresses to synchronize their browse lists with the local server. <p><br>The IP addresses you choose would normally be the broadcast addresses of the remote networks, but can also be the IP addresses of known @@ -3304,7 +3304,7 @@ automatic access as the same username. <p><br>Synonym for <a href="smb.conf.5.html#rootdirectory"><strong>"root directory"</strong></a>. <p><br><a name="rootdirectory"></a> <li><strong><strong>root directory (G)</strong></strong> -<p><br>The server will <code>"chroot()"</code> (ie. Change it's root directory) to +<p><br>The server will <code>"chroot()"</code> (i.e. Change it's root directory) to this directory on startup. This is not strictly necessary for secure operation. Even without it the server will deny access to files not in one of the service entries. It may also check for, and deny access to, @@ -3335,7 +3335,7 @@ filesystems (such as cdroms) after a connection is closed. <li><strong><strong>root preexec (S)</strong></strong> <p><br>This is the same as the <a href="smb.conf.5.html#preexec"><strong>"preexec"</strong></a> parameter except that the command is run as root. This is useful for mounting -filesystems (such as cdroms) before a connection is finalised. +filesystems (such as cdroms) before a connection is finalized. <p><br>See also <a href="smb.conf.5.html#preexec"><strong>"preexec"</strong></a>. <p><br><a name="security"></a> <li><strong><strong>security (G)</strong></strong> @@ -3356,7 +3356,7 @@ PREVIOUS VERSIONS OF SAMBA *******</em>. <p><br>In previous versions of Samba the default was <a href="smb.conf.5.html#securityequalshare"><strong>"security=share"</strong></a> mainly because that was the only option at one stage. -<p><br>There is a bug in WfWg that has relevence to this setting. When in +<p><br>There is a bug in WfWg that has relevance to this setting. When in user or server level security a WfWg client will totally ignore the password you type in the "connect drive" dialog box. This makes it very difficult (if not impossible) to connect to a Samba service as @@ -3371,7 +3371,7 @@ shares). This is commonly used for a shared printer server. It is more difficult to setup guest shares with <a href="smb.conf.5.html#securityequaluser"><strong>security=user</strong></a>, see the <a href="smb.conf.5.html#maptoguest"><strong>"map to guest"</strong></a>parameter for details. -<p><br>It is possible to use <a href="smbd.8.html"><strong>smbd</strong></a> in a <em>"hybred +<p><br>It is possible to use <a href="smbd.8.html"><strong>smbd</strong></a> in a <em>"hybrid mode"</em> where it is offers both user and share level security under different <a href="smb.conf.5.html#netbiosaliases"><strong>NetBIOS aliases</strong></a>. See the <a href="smb.conf.5.html#netbiosaliases"><strong>NetBIOS aliases</strong></a> and the @@ -3436,7 +3436,7 @@ be used in this security mode. Parameters such as are then applied and may change the UNIX user to use on this connection, but only after the user has been successfully authenticated. -<p><br><em>Note</em> that the the name of the resource being requested is +<p><br><em>Note</em> that the name of the resource being requested is <em>*not*</em> sent to the server until after the server has successfully authenticated the client. This is why guest shares don't work in user level security without allowing the server to automatically map unknown @@ -3458,7 +3458,7 @@ directory ENCRYPTION.txt for details on how to set this up. the same as <a href="smb.conf.5.html#securityequaluser"><strong>"security=user"</strong></a>. It only affects how the server deals with the authentication, it does not in any way affect what the client sees. -<p><br><em>Note</em> that the the name of the resource being requested is +<p><br><em>Note</em> that the name of the resource being requested is <em>*not*</em> sent to the server until after the server has successfully authenticated the client. This is why guest shares don't work in server level security without allowing the server to automatically map unknown @@ -3485,7 +3485,7 @@ UNIX account to map file access to. the same as <a href="smb.conf.5.html#securityequaluser"><strong>"security=user"</strong></a>. It only affects how the server deals with the authentication, it does not in any way affect what the client sees. -<p><br><em>Note</em> that the the name of the resource being requested is +<p><br><em>Note</em> that the name of the resource being requested is <em>*not*</em> sent to the server until after the server has successfully authenticated the client. This is why guest shares don't work in domain level security without allowing the server to automatically map unknown @@ -3497,7 +3497,7 @@ doing this. set usernames. The communication with a Domain Controller must be done in UNICODE and Samba currently does not widen multi-byte user names to UNICODE correctly, thus a multi-byte -username will not be recognised correctly at the Domain Controller. +username will not be recognized correctly at the Domain Controller. This issue will be addressed in a future release. <p><br>See also the section <a href="smb.conf.5.html#NOTEABOUTUSERNAMEPASSWORDVALIDATION"><strong>"NOTE ABOUT USERNAME/PASSWORD VALIDATION"</strong></a>. @@ -3533,7 +3533,7 @@ client. See the Pathworks documentation for details. <code> set directory = yes</code> <p><br><a name="sharemodes"></a> <li><strong><strong>share modes (S)</strong></strong> -<p><br>This enables or disables the honouring of the <code>"share modes"</code> during a +<p><br>This enables or disables the honoring of the <code>"share modes"</code> during a file open. These modes are used by clients to gain exclusive read or write access to a file. <p><br>These open modes are not directly supported by UNIX, so they are @@ -3611,9 +3611,9 @@ experiment and choose them yourself. We strongly suggest you read the appropriate documentation for your operating system first (perhaps <strong>"man setsockopt"</strong> will help). <p><br>You may find that on some systems Samba will say "Unknown socket -option" when you supply an option. This means you either mis-typed it -or you need to add an include file to includes.h for your OS. If the -latter is the case please send the patch to +option" when you supply an option. This means you either incorrectly +typed it or you need to add an include file to includes.h for your OS. +If the latter is the case please send the patch to <a href="mailto:samba-bugs@samba.anu.edu.au"><em>samba-bugs@samba.anu.edu.au</em></a>. <p><br>Any of the supported socket options may be combined in any way you like, as long as your OS allows it. @@ -3673,7 +3673,7 @@ option <code>"--with-ssl"</code> was given at configure time. <p><br><em>Note</em> that for export control reasons this code is <em>**NOT**</em> enabled by default in any current binary version of Samba. <p><br>This variable defines where to look up the Certification -Autorities. The given directory should contain one file for each CA +Authorities. The given directory should contain one file for each CA that samba will trust. The file name must be the hash value over the "Distinguished Name" of the CA. How this directory is set up is explained later in this document. All files within the directory that @@ -3692,7 +3692,7 @@ enabled by default in any current binary version of Samba. certificates of the trusted CAs are collected in one big file and this variable points to the file. You will probably only use one of the two ways to define your CAs. The first choice is preferable if you have -many CAs or want to be flexible, the second is perferable if you only +many CAs or want to be flexible, the second is preferable if you only have one CA and want to keep things simple (you won't need to create the hashed file names). You don't need this variable if you don't verify client certificates. @@ -3868,7 +3868,7 @@ change this parameter. <p><br><strong>Default:</strong> status = yes <p><br><a name="strictlocking"></a> -dir(<strong>strict locking (S)</strong>) +<li><strong><strong>strict locking (S)</strong></strong> <p><br>This is a boolean that controls the handling of file locking in the server. When this is set to <code>"yes"</code> the server will check every read and write access for file locks, and deny access if locks exist. This can @@ -3888,7 +3888,7 @@ preferable. seem to confuse flushing buffer contents to disk with doing a sync to disk. Under UNIX, a sync call forces the process to be suspended until the kernel has ensured that all outstanding data in kernel disk -buffers has been safely stored onto stable storate. This is very slow +buffers has been safely stored onto stable storage. This is very slow and should only be done rarely. Setting this parameter to "no" (the default) means that smbd ignores the Windows applications requests for a sync call. There is only a possibility of losing data if the @@ -3923,16 +3923,16 @@ set to <code>"yes"</code> in order for this parameter to have any affect. <p><br>See also the <a href="smb.conf.5.html#strictsync"><strong>"strict sync"</strong></a> parameter. <p><br><strong>Default:</strong> <code> sync always = no</code> -<p><br><strong>xample:</strong> +<p><br><strong>Example:</strong> <code> sync always = yes</code> <p><br><a name="syslog"></a> <li><strong><strong>syslog (G)</strong></strong> <p><br>This parameter maps how Samba debug messages are logged onto the system syslog logging levels. Samba debug level zero maps onto syslog LOG_ERR, debug level one maps onto LOG_WARNING, debug level two maps -to LOG_NOTICE, debug level three maps onto LOG_INFO. The paramter +to LOG_NOTICE, debug level three maps onto LOG_INFO. The parameter sets the threshold for doing the mapping, all Samba debug messages -above this threashold are mapped to syslog LOG_DEBUG messages. +above this threshold are mapped to syslog LOG_DEBUG messages. <p><br><strong>Default:</strong> <code> syslog = 1</code> <p><br><a name="syslogonly"></a> @@ -3969,7 +3969,7 @@ parameter allows the timestamping to be turned off. <code> timestamp logs = False</code> <p><br><a name="unixpasswordsync"></a> <li><strong><strong>unix password sync (G)</strong></strong> -<p><br>This boolean parameter controlls whether Samba attempts to synchronise +<p><br>This boolean parameter controls whether Samba attempts to synchronize the UNIX password with the SMB password when the encrypted SMB password in the smbpasswd file is changed. If this is set to true the program specified in the <a href="smb.conf.5.html#passwdprogram"><strong>"passwd program"</strong></a> @@ -4095,7 +4095,7 @@ as many DOS clients send an all-uppercase username. By default Samba tries all lowercase, followed by the username with the first letter capitalized, and fails if the username is not found on the UNIX machine. -<p><br>If this parameter is set to non-zero the behaviour changes. This +<p><br>If this parameter is set to non-zero the behavior changes. This parameter is a number that specifies the number of uppercase combinations to try whilst trying to determine the UNIX user name. The higher the number the more combinations will be tried, but the slower @@ -4107,7 +4107,7 @@ strange usernames on your UNIX machine, such as <code>"AstrangeUser"</code>. <code> username level = 5</code> <p><br><a name="usernamemap"></a> <li><strong><strong>username map (G)</strong></strong> -<p><br>This option allows you to to specify a file containing a mapping of +<p><br>This option allows you to specify a file containing a mapping of usernames from the clients to the server. This can be used for several purposes. The most common is to map usernames that users use on DOS or Windows machines to those that the UNIX box uses. The other is to map @@ -4206,13 +4206,13 @@ overwritten. <pre> Samba defaults to using a reasonable set of valid characters - for english systems + for English systems </pre> <p><br><strong>Example</strong> <code> valid chars = 0345:0305 0366:0326 0344:0304</code> -<p><br>The above example allows filenames to have the swedish characters in +<p><br>The above example allows filenames to have the Swedish characters in them. <p><br>NOTE: It is actually quite difficult to correctly produce a <strong>"valid chars"</strong> line for a particular system. To automate the process @@ -4354,32 +4354,16 @@ network. <p><br><a name="workgroup"></a> <li><strong><strong>workgroup (G)</strong></strong> <p><br>This controls what workgroup your server will appear to be in when -queried by clients. Note that this parameter also controlls the Domain +queried by clients. Note that this parameter also controls the Domain name used with the <a href="smb.conf.5.html#securityequaldomain"><strong>"security=domain"</strong></a> setting. <p><br><strong>Default:</strong> <code> set at compile time to WORKGROUP</code> -<p><br>.B Example: +<p><br><strong>Example:</strong> workgroup = MYGROUP <p><br><a name="writable"></a> <li><strong><strong>writable (S)</strong></strong> -<p><br>An inverted synonym is <a href="smb.conf.5.html#readonly"><strong>"read only"</strong></a>. -<p><br>If this parameter is <code>"no"</code>, then users of a service may not create -or modify files in the service's directory. -<p><br>Note that a printable service <a href="smb.conf.5.html#printable"><strong>("printable = yes")</strong></a> -will <em>*ALWAYS*</em> allow writing to the directory (user privileges -permitting), but only via spooling operations. -<p><br><strong>Default:</strong> -<code> writable = no</code> -<p><br><strong>Examples:</strong> -<pre> - - read only = no - writable = yes - write ok = yes - -</pre> - +<p><br>Synonym for <a href="smb.conf.5.html#writeable"><strong>"writeable"</strong></a> for people who can't spell :-). <p><br><a name="writelist"></a> <li><strong><strong>write list (S)</strong></strong> <p><br>This is a list of users that are given read-write access to a @@ -4396,7 +4380,7 @@ they will be given write access. <code> write list = admin, root, @staff</code> <p><br><a name="writeok"></a> <li><strong><strong>write ok (S)</strong></strong> -<p><br>Synonym for <a href="smb.conf.5.html#writable"><strong>writable</strong></a>. +<p><br>Synonym for <a href="smb.conf.5.html#writeable"><strong>writeable</strong></a>. <p><br><a name="writeraw"></a> <li><strong><strong>write raw (G)</strong></strong> <p><br>This parameter controls whether or not the server will support raw @@ -4406,7 +4390,23 @@ need to change this parameter. <code> write raw = yes</code> <p><br><a name="writeable"></a> <li><strong><strong>writeable</strong></strong> -<p><br>Synonym for <a href="smb.conf.5.html#writable"><strong>"writable"</strong></a> for people who can't spell :-). +<p><br>An inverted synonym is <a href="smb.conf.5.html#readonly"><strong>"read only"</strong></a>. +<p><br>If this parameter is <code>"no"</code>, then users of a service may not create +or modify files in the service's directory. +<p><br>Note that a printable service <a href="smb.conf.5.html#printable"><strong>("printable = yes")</strong></a> +will <em>*ALWAYS*</em> allow writing to the directory (user privileges +permitting), but only via spooling operations. +<p><br><strong>Default:</strong> +<code> writeable = no</code> +<p><br><strong>Examples:</strong> +<pre> + + read only = no + writeable = yes + write ok = yes + +</pre> + <p><br><a name="WARNINGS"></a> <h2>WARNINGS</h2> diff --git a/docs/htmldocs/smbclient.1.html b/docs/htmldocs/smbclient.1.html index 8e480a2bea..533066c500 100644 --- a/docs/htmldocs/smbclient.1.html +++ b/docs/htmldocs/smbclient.1.html @@ -3,7 +3,7 @@ -<html><head><title>smbclient</title> +<html><head><title>smbclient (1)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>smbclient</h1> +<h1>smbclient (1)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -105,7 +105,7 @@ methods as it depends on the target host being on a locally connected subnet. To specify a particular broadcast address the <a href="smbclient.1.html#minusB"><strong>-B</strong></a> option may be used. <p><br></ul> -<p><br>If this parameter is not set then the name resolver order defined +<p><br>If this parameter is not set then the name resolve order defined in the <a href="smb.conf.5.html"><strong>smb.conf</strong></a> file parameter <a href="smb.conf.5.html#nameresolveorder">(<strong>name resolve order</strong>)</a> will be used. @@ -219,7 +219,7 @@ that it must be a valid NetBIOS name. the environment variable <code>USER</code> or <code>LOGNAME</code> in that order. If no username is supplied and neither environment variable exists the username "GUEST" will be used. -<p><br>If the <code>USER</code> environment variable containts a '%' character, +<p><br>If the <code>USER</code> environment variable contains a '%' character, everything after that will be treated as a password. This allows you to set the environment variable to be <code>USER=username%password</code> so that a password is not passed on the command line (where it may be @@ -269,7 +269,7 @@ tested and may have some problems. Samba source code for the complete list. <p><br><a name="minusm"></a> <li><strong><strong>-m max protocol level</strong></strong> With the new code in Samba2.0, -<strong>smbclient</strong> allways attempts to connect at the maximum +<strong>smbclient</strong> always attempts to connect at the maximum protocols level the server supports. This parameter is preserved for backwards compatibility, but any string following the <strong>-m</strong> will be ignored. @@ -291,11 +291,11 @@ share. The secondary tar flags that can be given to this option are : share. Unless the <a href="smbclient.1.html#minusD"><strong>-D</strong></a> option is given, the tar files will be restored from the top level of the share. Must be followed by the name of the tar file, device or <code>"-"</code> for standard input. Mutually exclusive - with the <strong>c</strong> flag. Restored files have theuir creation times (mtime) + with the <strong>c</strong> flag. Restored files have their creation times (mtime) set to the date saved in the tar file. Directories currently do not get their creation dates restored properly. <p><br><li><strong><strong>I</strong></strong> Include files and directories. Is the default - behaviour when filenames are specified above. Causes tar files to + behavior when filenames are specified above. Causes tar files to be included in an extract or create (and therefore everything else to be excluded). See example below. Filename globbing does not work for included files for extractions (yet). @@ -364,12 +364,12 @@ commands are case-insensitive. Parameters to commands may or may not be case sensitive, depending on the command. <p><br>You can specify file names which have spaces in them by quoting the name with double quotes, for example "a long file name". -<p><br>Parameters shown in square brackets (eg., "[parameter]") are +<p><br>Parameters shown in square brackets (e.g., "[parameter]") are optional. If not given, the command will use suitable -defaults. Parameters shown in angle brackets (eg., "<parameter>") are +defaults. Parameters shown in angle brackets (e.g., "<parameter>") are required. <p><br>Note that all commands operating on the server are actually performed -by issuing a request to the server. Thus the behaviour may vary from +by issuing a request to the server. Thus the behavior may vary from server to server, depending on how the server was implemented. <p><br>The commands available are given here in alphabetical order. <p><br><ul> @@ -459,7 +459,7 @@ from the local machine through a printable service on the server. mode to suit either binary data (such as graphical information) or text. Subsequent print commands will use the currently set print mode. -<p><br><a name="prompt"></a> dir(<strong>prompt</strong>) Toggle prompting for filenames during +<p><br><a name="prompt"></a> <li><strong><strong>prompt</strong></strong> Toggle prompting for filenames during operation of the <a href="smbclient.1.html#mget"><strong>mget</strong></a> and <a href="smbclient.1.html#mput"><strong>mput</strong></a> commands. <p><br>When toggled ON, the user will be prompted to confirm the transfer of @@ -470,12 +470,12 @@ file called "local file name" from the machine running the client to the server. If specified, name the remote copy "remote file name". Note that all transfers in smbclient are binary. See also the <a href="smbclient.1.html#lowercase"><strong>lowercase</strong></a> command. -<p><br><a name="queue"></a> dir(<strong>queue</strong>) Displays the print queue, showing the job +<p><br><a name="queue"></a> <li><strong><strong>queue</strong></strong> Displays the print queue, showing the job id, name, size and current status. <p><br><a name="quit"></a> <li><strong><strong>quit</strong></strong> See the <a href="smbclient.1.html#exit"><strong>exit</strong></a> command. -<p><br><a name="rd"></a> dir(<strong>rd <directory name></strong>) See the <a href="smbclient.1.html#rmdir"><strong>rmdir</strong></a> +<p><br><a name="rd"></a> <li><strong><strong>rd <directory name></strong></strong> See the <a href="smbclient.1.html#rmdir"><strong>rmdir</strong></a> command. -<p><br><a name="recurse"></a> dir(<strong>recurse</strong>) Toggle directory recursion for the +<p><br><a name="recurse"></a> <li><strong><strong>recurse</strong></strong> Toggle directory recursion for the commands <a href="smbclient.1.html#mget"><strong>mget</strong></a> and <a href="smbclient.1.html#mput"><strong>mput</strong></a>. <p><br>When toggled ON, these commands will process all directories in the source directory (i.e., the directory they are copying .IR from ) and @@ -488,12 +488,12 @@ directory on the source machine that match the mask specified to the <a href="smbclient.1.html#mget"><strong>mget</strong></a> or <a href="smbclient.1.html#mput"><strong>mput</strong></a> commands will be copied, and any mask specified using the <a href="smbclient.1.html#mask"><strong>mask</strong></a> command will be ignored. -<p><br><a name="rm"></a> dir(<strong>rm <mask></strong>) Remove all files matching mask from +<p><br><a name="rm"></a> <li><strong><strong>rm <mask></strong></strong> Remove all files matching mask from the current working directory on the server. <p><br><a name="rmdir"></a> <li><strong><strong>rmdir <directory name></strong></strong> Remove the specified directory (user access privileges permitting) from the server. <p><br><a name="tar"></a> <li><strong><strong>tar <c|x>[IXbgNa]</strong></strong> Performs a tar operation - see -the <a href="smbclient.1.html#minusT"><strong>-T</strong></a> command line option above. Behaviour may be +the <a href="smbclient.1.html#minusT"><strong>-T</strong></a> command line option above. Behavior may be affected by the <a href="smbclient.1.html#tarmode"><strong>tarmode</strong></a> command (see below). Using g (incremental) and N (newer) will affect tarmode settings. Note that using the "-" option with tar x may not work - use the command line @@ -501,8 +501,8 @@ option instead. <p><br><a name="blocksize"></a> <li><strong><strong>blocksize <blocksize></strong></strong> Blocksize. Must be followed by a valid (greater than zero) blocksize. Causes tar file to be written out in blocksize*TBLOCK (usually 512 byte) blocks. -<p><br><a name="tarmode"></a> dir(<strong>tarmode <full|inc|reset|noreset></strong>) Changes tar's -behaviour with regard to archive bits. In full mode, tar will back up +<p><br><a name="tarmode"></a> <li><strong><strong>tarmode <full|inc|reset|noreset></strong></strong> Changes tar's +behavior with regard to archive bits. In full mode, tar will back up everything regardless of the archive bit setting (this is the default mode). In incremental mode, tar will only back up files with the archive bit set. In reset mode, tar will reset the archive bit on all @@ -516,7 +516,7 @@ of the DOS attrib command to set file permissions. For example: <h2>NOTES</h2> <p><br>Some servers are fussy about the case of supplied usernames, -passwords, share names (aka service names) and machine names. If you +passwords, share names (AKA service names) and machine names. If you fail to connect try giving all parameters in uppercase. <p><br>It is often necessary to use the <a href="smbclient.1.html#minusn"><strong>-n</strong></a> option when connecting to some types of servers. For example OS/2 LanManager insists on a valid @@ -544,7 +544,7 @@ readable by all, writeable only by root. The client program itself should be executable by all. The client should <em>NOT</em> be setuid or setgid! <p><br>The client log files should be put in a directory readable and -writable only by the user. +writeable only by the user. <p><br>To test the client, you will need to know the name of a running SMB/CIFS server. It is possible to run <a href="smbd.8.html"><strong>smbd (8)</strong></a> an ordinary user - running that server as a daemon on a diff --git a/docs/htmldocs/smbd.8.html b/docs/htmldocs/smbd.8.html index cd00af3b27..a6e0f32e12 100644 --- a/docs/htmldocs/smbd.8.html +++ b/docs/htmldocs/smbd.8.html @@ -3,7 +3,7 @@ -<html><head><title>smbd</title> +<html><head><title>smbd (8)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>smbd</h1> +<h1>smbd (8)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -29,7 +29,8 @@ <h2>DESCRIPTION</h2> <p><br>This program is part of the <strong>Samba</strong> suite. -<p><br><strong>smbd</strong> is the server daemon that provides filesharing services to +<p><br><strong>smbd</strong> is the server daemon that provides filesharing and printing +services to Windows clients. The server provides filespace and printer services to clients using the SMB (or CIFS) protocol. This is compatible with the LanManager protocol, and can service LanManager clients. These @@ -37,16 +38,18 @@ include MSCLIENT 3.0 for DOS, Windows for Workgroups, Windows 95, Windows NT, OS/2, DAVE for Macintosh, and smbfs for Linux. <p><br>An extensive description of the services that the server can provide is given in the man page for the configuration file controlling the -attributes of those services (see <strong>smb.conf (5)</strong>). This man page +attributes of those services (see +<a href="smb.conf.5.html"><strong>smb.conf (5)</strong></a>. This man page will not describe the services, but will concentrate on the administrative aspects of running the server. <p><br>Please note that there are significant security implications to -running this server, and the <strong>smb.conf (5)</strong> manpage should be +running this server, and the +<a href="smb.conf.5.html"><strong>smb.conf (5)</strong></a> manpage should be regarded as mandatory reading before proceeding with installation. <p><br>A session is created whenever a client requests one. Each client gets a copy of the server for each session. This copy then services all connections made by the client during that session. When all -connections from its client are are closed, the copy of the server for +connections from its client are closed, the copy of the server for that client terminates. <p><br>The configuration file, and any files that it includes, are automatically reloaded every minute, if they change. You can force a @@ -116,13 +119,13 @@ rfc1002.txt section 4.3.5. <p><br>This parameter is not normally specified except in the above situation. <p><br><a name="minuss"></a> -<li><strong><strong>-s configuration file</strong></strong> The default configuration file name is -determined at compile time. -<p><br>The file specified contains the configuration details required by the +<li><strong><strong>-s configuration file</strong></strong> +The file specified contains the configuration details required by the server. The information in this file includes server-specific information such as what printcap file to use, as well as descriptions of all the services that the server is to provide. See <strong>smb.conf (5)</strong> for more information. +The default configuration file name is determined at compile time. <p><br><a name="minusi"></a> <li><strong><strong>-i scope</strong></strong> This specifies a NetBIOS scope that the server will use to communicate with when generating NetBIOS names. For details on the @@ -142,23 +145,23 @@ out. Used for debugging by the developers only. <p><br><strong>/etc/inetd.conf</strong> <p><br>If the server is to be run by the inetd meta-daemon, this file must contain suitable startup information for the meta-daemon. See the -section <em>INSTALLATION</em> below. +section <a href="smbd.8.html#INSTALLATION">INSTALLATION</a> below. <p><br><strong>/etc/rc</strong> -<p><br>(or whatever initialisation script your system uses). +<p><br>(or whatever initialization script your system uses). <p><br>If running the server as a daemon at startup, this file will need to contain an appropriate startup sequence for the server. See the -section <em>INSTALLATION</em> below. +section <a href="smbd.8.html#INSTALLATION">INSTALLATION</a> below. <p><br><strong>/etc/services</strong> <p><br>If running the server via the meta-daemon inetd, this file must -contain a mapping of service name (eg., netbios-ssn) to service port -(eg., 139) and protocol type (eg., tcp). See the section -<em>INSTALLATION</em> below. +contain a mapping of service name (e.g., netbios-ssn) to service port +(e.g., 139) and protocol type (e.g., tcp). See the section +<a href="smbd.8.html#INSTALLATION">INSTALLATION</a> below. <p><br><strong>/usr/local/samba/lib/smb.conf</strong> <p><br>This is the default location of the <em>smb.conf</em> server configuration file. Other common places that systems install this file are <em>/usr/samba/lib/smb.conf</em> and <em>/etc/smb.conf</em>. <p><br>This file describes all the services the server is to make available -to clients. See <strong>smb.conf (5)</strong> for more information. +to clients. See <a href="smb.conf.5.html"><strong>smb.conf (5)</strong></a> for more information. <p><br><a name="LIMITATIONS"></a> <h2>LIMITATIONS</h2> @@ -196,10 +199,10 @@ at the time this was written. It is possible that this hole only exists in Linux, as testing on other systems has thus far shown them to be immune. <p><br>The server log files should be put in a directory readable and -writable only by root, as the log files may contain sensitive +writeable only by root, as the log files may contain sensitive information. <p><br>The configuration file should be placed in a directory readable and -writable only by root, as the configuration file controls security for +writeable only by root, as the configuration file controls security for the services offered by the server. The configuration file can be made readable by all if desired, but this is not necessary for correct operation of the server and is not recommended. A sample configuration @@ -218,8 +221,9 @@ faster. If run from a meta-daemon some memory will be saved and utilities such as the tcpd TCP-wrapper may be used for extra security. For serious use as file server it is recommended that <strong>smbd</strong> be run as a daemon. -<p><br>When you've decided, continue with either <em>RUNNING THE SERVER AS A -DAEMON</em> or <em>RUNNING THE SERVER ON REQUEST</em>. +<p><br>When you've decided, continue with either +<a href="smbd.8.html#RUNNINGTHESERVERASADAEMON">RUNNING THE SERVER AS A DAEMON</a> or +<a href="smbd.8.html#RUNNINGTHESERVERONREQUEST">RUNNING THE SERVER ON REQUEST</a>. <p><br><a name="RUNNINGTHESERVERASADAEMON"></a> <h2>RUNNING THE SERVER AS A DAEMON</h2> @@ -239,17 +243,17 @@ files. Wherever appropriate (for example, in /etc/rc), insert the following line, substituting port number, log file location, configuration file location and debug level as desired: <p><br><code>/usr/local/samba/bin/smbd -D -l /var/adm/smblogs/log -s /usr/local/samba/lib/smb.conf</code> -<p><br>(The above should appear in your initialisation script as a single line. +<p><br>(The above should appear in your initialization script as a single line. Depending on your terminal characteristics, it may not appear that way in this man page. If the above appears as more than one line, please treat any newlines or indentation as a single space or TAB character.) <p><br>If the options used at compile time are appropriate for your system, -all parameters except the desired debug level and <a href="smbd.8.html#minusD"><strong>-D</strong></a> may be -omitted. See the section <em>OPTIONS</em> above. +all parameters except <a href="smbd.8.html#minusD"><strong>-D</strong></a> may be +omitted. See the section <a href="smbd.8.html#OPTIONS">OPTIONS</a> above. <p><br><a name="RUNNINGTHESERVERONREQUEST"></a> <h2>RUNNING THE SERVER ON REQUEST</h2> -<p><br>If your system uses a meta-daemon such as inetd, you can arrange to +<p><br>If your system uses a meta-daemon such as <strong>inetd</strong>, you can arrange to have the smbd server started whenever a process attempts to connect to it. This requires several changes to the startup files on the host machine. If you are experimenting as an ordinary user rather than as @@ -284,10 +288,10 @@ start with, the following two services should be all you need: [homes] - writable = yes + writeable = yes [printers] - writable = no + writeable = no printable = yes path = /tmp public = yes @@ -307,7 +311,8 @@ tables if they receive a HUP signal. <p><br>If your machine's name is "fred" and your name is "mary", you should now be able to connect to the service <code>\\fred\mary</code>. <p><br>To properly test and experiment with the server, we recommend using -the smbclient program (see <strong>smbclient (1)</strong>) and also going through +the smbclient program (see +<a href="smbclient.1.html"><strong>smbclient (1)</strong></a>) and also going through the steps outlined in the file <em>DIAGNOSIS.txt</em> in the <em>docs/</em> directory of your Samba installation. <p><br><a name="VERSION"></a> @@ -323,8 +328,8 @@ overridden on the command line. <p><br>The number and nature of diagnostics available depends on the debug level used by the server. If you have problems, set the debug level to 3 and peruse the log files. -<p><br>Most messages are reasonably self-explanatory. Unfortunately, at time -of creation of this man page there are too many diagnostics available +<p><br>Most messages are reasonably self-explanatory. Unfortunately, at the time +this man page was created, there are too many diagnostics available in the source code to warrant describing each and every diagnostic. At this stage your best bet is still to grep the source code and inspect the conditions that gave rise to the diagnostics you are seeing. @@ -335,7 +340,7 @@ the conditions that gave rise to the diagnostics you are seeing. configuration file within a short period of time. <p><br>To shut down a users smbd process it is recommended that SIGKILL (-9) <em>NOT</em> be used, except as a last resort, as this may leave the shared -memory area in an inconsistant state. The safe way to terminate an +memory area in an inconsistent state. The safe way to terminate an smbd is to send it a SIGTERM (-15) signal and wait for it to die on its own. <p><br>The debug log level of smbd may be raised @@ -363,7 +368,7 @@ specification is available as a link from the Web page : <h2>AUTHOR</h2> <p><br>The original Samba software and related utilities were created by -Andrew Tridgell (samba-bugs@samba.anu.edu.au). Samba is now developed +Andrew Tridgell <a href="mailto:samba-bugs@samba.anu.edu.au"><em>samba-bugs@samba.anu.edu.au</em></a>. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed. <p><br>The original Samba man pages were written by Karl Auer. The man page diff --git a/docs/htmldocs/smbpasswd.5.html b/docs/htmldocs/smbpasswd.5.html index 35649e689b..6c4081fc4d 100644 --- a/docs/htmldocs/smbpasswd.5.html +++ b/docs/htmldocs/smbpasswd.5.html @@ -3,7 +3,7 @@ -<html><head><title>smbpasswd</title> +<html><head><title>smbpasswd (5)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>smbpasswd</h1> +<h1>smbpasswd (5)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -30,7 +30,7 @@ <p><br>This file is part of the <strong>Samba</strong> suite. <p><br>smbpasswd is the <strong>Samba</strong> encrypted password file. It contains -the username, unix user id and the SMB hashed passwords of the +the username, Unix user id and the SMB hashed passwords of the user, as well as account flag information and the time the password was last changed. This file format has been evolving with Samba and has had several different formats in the past. @@ -38,7 +38,7 @@ and has had several different formats in the past. <h2>FILE FORMAT</h2> <p><br>The format of the smbpasswd file used by Samba 2.0 is very similar to -the familiar unix <strong>passwd (5)</strong> file. It is an ASCII file containing +the familiar Unix <strong>passwd (5)</strong> file. It is an ASCII file containing one line for each user. Each field within each line is separated from the next by a colon. Any entry beginning with # is ignored. The smbpasswd file contains the following information for each user: @@ -50,7 +50,9 @@ smbpasswd file contains the following information for each user: <p><br><a name="uid"></a> <li><strong><strong>uid</strong></strong> <br> <br> <p><br>This is the UNIX uid. It must match the uid field for the same - user entry in the standard UNIX passwd file. + user entry in the standard UNIX passwd file. If this does not + match then Samba will refuse to recognize this <strong>smbpasswd</strong> file entry + as being valid for a user. <p><br><a name="LanmanPasswordHash"></a> <li><strong><strong>Lanman Password Hash</strong></strong> <br> <br> <p><br>This is the <em>LANMAN</em> hash of the users password, encoded as 32 hex @@ -58,7 +60,7 @@ smbpasswd file contains the following information for each user: string with the users password as the DES key. This is the same password used by Windows 95/98 machines. Note that this password hash is regarded as weak as it is vulnerable to dictionary attacks and if - two users choose the same password this entry will be identical (ie. + two users choose the same password this entry will be identical (i.e. the password is not <em>"salted"</em> as the UNIX password is). If the user has a null password this field will contain the characters <code>"NO PASSWORD"</code> as the start of the hex string. If the hex string @@ -67,7 +69,7 @@ smbpasswd file contains the following information for each user: server. <p><br><em>WARNING !!</em>. Note that, due to the challenge-response nature of the SMB/CIFS authentication protocol, anyone with a knowledge of this - password hash will be able to impersonate the user of the network. + password hash will be able to impersonate the user on the network. For this reason these hashes are known as <em>"plain text equivalent"</em> and must <em>NOT</em> be made available to anyone but the root user. To protect these passwords the <strong>smbpasswd</strong> file is placed in a @@ -84,11 +86,11 @@ smbpasswd file contains the following information for each user: Password Hash</strong></a> as it preserves the case of the password and uses a much higher quality hashing algorithm. However, it is still the case that if two users choose the same password this - entry will be identical (ie. the password is not <em>"salted"</em> as the + entry will be identical (i.e. the password is not <em>"salted"</em> as the UNIX password is). <p><br><em>WARNING !!</em>. Note that, due to the challenge-response nature of the SMB/CIFS authentication protocol, anyone with a knowledge of this - password hash will be able to impersonate the user of the network. + password hash will be able to impersonate the user on the network. For this reason these hashes are known as <em>"plain text equivalent"</em> and must <em>NOT</em> be made available to anyone but the root user. To protect these passwords the <strong>smbpasswd</strong> file is placed in a @@ -104,8 +106,8 @@ smbpasswd file contains the following information for each user: any of the characters. <p><br><ul> <p><br><a name="capU"></a> - <li > <strong>'U'</strong> This means this is a <em>"User"</em> account, ie. an ordinary - user. Only <strong>User</strong> and <a href="smbpasswd.5.html#capW"><strong>Worskstation Trust</strong></a> accounts are + <li > <strong>'U'</strong> This means this is a <em>"User"</em> account, i.e. an ordinary + user. Only <strong>User</strong> and <a href="smbpasswd.5.html#capW"><strong>Workstation Trust</strong></a> accounts are currently supported in the <strong>smbpasswd</strong> file. <p><br><a name="capN"></a> <li > <strong>'N'</strong> This means the account has <em>no</em> password (the passwords @@ -115,7 +117,7 @@ smbpasswd file contains the following information for each user: <a href="smb.conf.5.html#nullpasswords"><strong>null passwords</strong></a> parameter is set in the <a href="smb.conf.5.html"><strong>smb.conf (5)</strong></a> config file. <p><br><a name="capD"></a> - <li > <strong>'D'</strong> This means the account is diabled and no SMB/CIFS logins + <li > <strong>'D'</strong> This means the account is disabled and no SMB/CIFS logins will be allowed for this user. <p><br><a name="capW"></a> <li > <strong>'W'</strong> This means this account is a <em>"Workstation Trust"</em> account. @@ -177,12 +179,14 @@ algorithm. <h2>AUTHOR</h2> <p><br>The original Samba software and related utilities were created by -Andrew Tridgell (samba-bugs@samba.anu.edu.au). Samba is now developed +Andrew Tridgell <a href="mailto:samba-bugs@samba.anu.edu.au"><em>samba-bugs@samba.anu.edu.au</em></a>. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed. <p><br>The original Samba man pages were written by Karl Auer. The man page sources were converted to YODL format (another excellent piece of Open -Source software) and updated for the Samba2.0 release by Jeremy +Source software, available at +<a href="ftp://ftp.icce.rug.nl/pub/unix/"><strong>ftp://ftp.icce.rug.nl/pub/unix/</strong></a>) +and updated for the Samba2.0 release by Jeremy Allison, <a href="mailto:samba-bugs@samba.anu.edu.au"><em>samba-bugs@samba.anu.edu.au</em></a>. <p><br>See <a href="samba.7.html"><strong>samba (7)</strong></a> to find out how to get a full list of contributors and details on how to submit bug reports, diff --git a/docs/htmldocs/smbpasswd.8.html b/docs/htmldocs/smbpasswd.8.html index 066004be21..6bfd8cdb44 100644 --- a/docs/htmldocs/smbpasswd.8.html +++ b/docs/htmldocs/smbpasswd.8.html @@ -3,7 +3,7 @@ -<html><head><title>smbpasswd</title> +<html><head><title>smbpasswd (8)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>smbpasswd</h1> +<h1>smbpasswd (8)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -35,7 +35,7 @@ user it allows the user to change the password used for their SMB sessions on any machines that store SMB passwords. <p><br>By default (when run with no arguments) it will attempt to change the current users SMB password on the local machine. This is similar to -the way the <strong>passwd (1)</strong> program works. <strong>smbpasswd</strong> differs from +the way the <strong>passwd (1)</strong> program works. <strong>smbpasswd</strong> differs from how the <strong>passwd</strong> program works however in that it is not <em>setuid root</em> but works in a client-server mode and communicates with a locally running <a href="smbd.8.html"><strong>smbd</strong></a>. As a consequence in order for this @@ -49,13 +49,13 @@ correctly. No passwords will be echoed on the screen whilst being typed. If you have a blank smb password (specified by the string "NO PASSWORD" in the <a href="smbpasswd.5.html"><strong>smbpasswd</strong></a> file) then just press the <Enter> key when asked for your old password. -<p><br><strong>smbpasswd</strong> also can be used by a normal user to change their SMB +<p><br><strong>smbpasswd</strong> can also be used by a normal user to change their SMB password on remote machines, such as Windows NT Primary Domain Controllers. See the <a href="smbpasswd.8.html#minusr">(<strong>-r</strong>)</a> and <a href="smbpasswd.8.html#minusU"><strong>-U</strong></a> options below. <p><br>When run by root, <strong>smbpasswd</strong> allows new users to be added and deleted in the <a href="smbpasswd.5.html"><strong>smbpasswd</strong></a> file, as well as -changes to the attributes of the user in this file to be made. When +allows changes to the attributes of the user in this file to be made. When run by root, <strong>smbpasswd</strong> accesses the local <a href="smbpasswd.5.html"><strong>smbpasswd</strong></a> file directly, thus enabling changes to be made even if <a href="smbd.8.html"><strong>smbd</strong></a> is not running. @@ -69,8 +69,8 @@ be added to the local <a href="smbpasswd.5.html"><strong>smbpasswd</strong></a> the new password typed (type <Enter> for the old password). This option is ignored if the username following already exists in the <a href="smbpasswd.5.html"><strong>smbpasswd</strong></a> file and it is treated like a -regular change password command. Note that the user to be added .B -must already exist in the system password file (usually /etc/passwd) +regular change password command. Note that the user to be added +<strong>must</strong> already exist in the system password file (usually /etc/passwd) else the request to add the user will fail. <p><br>This option is only available when running <strong>smbpasswd</strong> as root. @@ -142,6 +142,9 @@ username. specified must be the Primary Domain Controller for the domain (Backup Domain Controllers only have a read-only copy of the user account database and will not allow the password change). +<p><br><em>Note</em> that Windows 95/98 do not have a real password database +so it is not possible to change passwords specifying a Win95/98 +machine as remote machine target. <p><br><a name="minusR"></a> <li><strong><strong>-R name resolve order</strong></strong> This option allows the user of smbclient to determine what name resolution services to use when @@ -155,11 +158,12 @@ resolved as follows : <p><br><a name="host"></a> <li > <strong>host</strong> : Do a standard host name to IP address resolution, using the system /etc/hosts, NIS, or DNS lookups. This method of name -resolution is operating system depended for instance on IRIX or -Solaris this may be controlled by the <em>/etc/nsswitch.conf</em> file). +resolution is operating system dependent. For instance on IRIX or +Solaris, this may be controlled by the <em>/etc/nsswitch.conf</em> file). <p><br><a name="wins"></a> -<li > <strong>wins</strong> : Query a name with the IP address listed in the <a href="smb.conf.5.html#winsserver"><strong>wins -server</strong></a> parameter in the smb.conf file. If +<li > <strong>wins</strong> : Query a name with the IP address listed in the +<a href="smb.conf.5.html#winsserver"><strong>wins server</strong></a> parameter in the +<a href="smb.conf.5.html"><strong>smb.conf file</strong></a>. If no WINS server has been specified this method will be ignored. <p><br><a name="bcast"></a> <li > <strong>bcast</strong> : Do a broadcast on each of the known local interfaces @@ -168,7 +172,7 @@ in the smb.conf file. This is the least reliable of the name resolution methods as it depends on the target host being on a locally connected subnet. <p><br></ul> -<p><br>If this parameter is not set then the name resolver order defined +<p><br>If this parameter is not set then the name resolve order defined in the <a href="smb.conf.5.html"><strong>smb.conf</strong></a> file parameter <a href="smb.conf.5.html#nameresolveorder"><strong>name resolve order</strong></a> will be used. @@ -202,7 +206,7 @@ Controller for the Domain (found in the the machine account password used to create the secure Domain communication. This password is then stored by <strong>smbpasswd</strong> in a file, read only by root, called <code><Domain>.<Machine>.mac</code> where -<code><Domain></code> is the name of the Domain we are joining and tt<Machine> +<code><Domain></code> is the name of the Domain we are joining and <code><Machine></code> is the primary NetBIOS name of the machine we are running on. <p><br>Once this operation has been performed the <a href="smb.conf.5.html"><strong>smb.conf</strong></a> file may be updated to set the @@ -224,19 +228,19 @@ different systems to change these passwords. <li><strong><strong>-h</strong></strong> This option prints the help string for <strong>smbpasswd</strong>, selecting the correct one for running as root or as an ordinary user. <p><br><a name="minuss"></a> -<li><strong><strong>-s</strong></strong> This option causes <strong>smbpasswd</strong> to be silent (ie. not +<li><strong><strong>-s</strong></strong> This option causes <strong>smbpasswd</strong> to be silent (i.e. not issue prompts) and to read it's old and new passwords from standard input, rather than from <code>/dev/tty</code> (like the <strong>passwd (1)</strong> program does). This option is to aid people writing scripts to drive <strong>smbpasswd</strong> <p><br><a name="username"></a> -dir(<strong>username</strong>) This specifies the username for all of the <em>root +<li><strong><strong>username</strong></strong> This specifies the username for all of the <em>root only</em> options to operate on. Only root can specify this parameter as only root has the permission needed to modify attributes directly in the local <a href="smbpasswd.5.html"><strong>smbpasswd</strong></a> file. <p><br><a name="NOTES"></a> <h2>NOTES</h2> -<p><br>As <strong>smbpasswd</strong> works in client-server mode communicating with a +<p><br>Since <strong>smbpasswd</strong> works in client-server mode communicating with a local <a href="smbd.8.html"><strong>smbd</strong></a> for a non-root user then the <strong>smbd</strong> daemon must be running for this to work. A common problem is to add a restriction to the hosts that may access the <strong>smbd</strong> running on the diff --git a/docs/htmldocs/smbrun.1.html b/docs/htmldocs/smbrun.1.html index b8d1021d56..9db9b7e783 100644 --- a/docs/htmldocs/smbrun.1.html +++ b/docs/htmldocs/smbrun.1.html @@ -3,7 +3,7 @@ -<html><head><title>smbrun</title> +<html><head><title>smbrun (1)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>smbrun</h1> +<h1>smbrun (1)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> diff --git a/docs/htmldocs/smbstatus.1.html b/docs/htmldocs/smbstatus.1.html index 3c46e55fdf..cc48f29d88 100644 --- a/docs/htmldocs/smbstatus.1.html +++ b/docs/htmldocs/smbstatus.1.html @@ -3,7 +3,7 @@ -<html><head><title>smbstatus</title> +<html><head><title>smbstatus (1)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>smbstatus</h1> +<h1>smbstatus (1)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> diff --git a/docs/htmldocs/smbtar.1.html b/docs/htmldocs/smbtar.1.html index 47a2d26b10..610ead88df 100644 --- a/docs/htmldocs/smbtar.1.html +++ b/docs/htmldocs/smbtar.1.html @@ -3,7 +3,7 @@ -<html><head><title>smbtar</title> +<html><head><title>smbtar (1)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>smbtar</h1> +<h1>smbtar (1)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> diff --git a/docs/htmldocs/swat.8.html b/docs/htmldocs/swat.8.html index 4a2eeec3d5..31afec1a89 100644 --- a/docs/htmldocs/swat.8.html +++ b/docs/htmldocs/swat.8.html @@ -3,7 +3,7 @@ -<html><head><title>swat</title> +<html><head><title>swat (8)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>swat</h1> +<h1>swat (8)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -34,8 +34,7 @@ addition, a swat configuration page has help links to all the configurable options in the <a href="smb.conf.5.html"><strong>smb.conf</strong></a> file allowing an administrator to easily look up the effects of any change. -<p><br><strong>swat</strong> can be run as a stand-alone daemon, from <strong>inetd</strong>, -or invoked via CGI from a Web server. +<p><br><strong>swat</strong> is run from <strong>inetd</strong> <p><br><a name="OPTIONS"></a> <h2>OPTIONS</h2> @@ -51,13 +50,10 @@ of all the services that the server is to provide. See <a href="smb.conf.5.html" (5)</a> for more information. <p><br><a name="minusa"></a> <li><strong><strong>-a</strong></strong> -<p><br>This option is only used if <strong>swat</strong> is running as it's own mini-web -server (see the <a href="swat.8.html#INSTALLATION"><strong>INSTALLATION</strong></a> section below). -<p><br>This option removes the need for authentication needed to modify the -<a href="smb.conf.5.html"><strong>smb.conf</strong></a> file. <em>**THIS IS ONLY MEANT FOR -DEMOING SWAT AND MUST NOT BE SET IN NORMAL SYSTEMS**</em> as it would -allow <em>*ANYONE*</em> to modify the <a href="smb.conf.5.html"><strong>smb.conf</strong></a> -file, thus giving them root access. +<p><br>This option disables authentication and puts <strong>swat</strong> in demo mode. In +that mode anyone will be able to modify the +<a href="smb.conf.5.html"><strong>smb.conf</strong></a> file. +<p><br>Do NOT enable this option on a production server. <p><br></ul> <p><br><a name="INSTALLATION"></a> <h2>INSTALLATION</h2> @@ -73,14 +69,11 @@ would put these in: </pre> -<p><br><a name="RUNNINGVIAINETD"></a> -<h2>RUNNING VIA INETD</h2> +<p><br><a name="INETD"></a> +<h2>INETD INSTALLATION</h2> <p><br>You need to edit your <code>/etc/inetd.conf</code> and <code>/etc/services</code> to -enable <strong>SWAT</strong> to be launched via inetd. Note that <strong>swat</strong> can also -be launched via the cgi-bin mechanisms of a web server (such as -apache) and that is described below in the section <a href="swat.8.html#RUNNINGVIACGIBIN"><strong>RUNNING VIA -CGI-BIN</strong></a>. +enable <strong>SWAT</strong> to be launched via inetd. <p><br>In <code>/etc/services</code> you need to add a line like this: <p><br><code>swat 901/tcp</code> <p><br>Note for NIS/YP users - you may need to rebuild the NIS service maps @@ -91,67 +84,26 @@ presents an obscure security hole depending on the implementation details of your <strong>inetd</strong> daemon). <p><br>In <code>/etc/inetd.conf</code> you should add a line like this: <p><br><code>swat stream tcp nowait.400 root /usr/local/samba/bin/swat swat</code> -<p><br>If you just want to see a demo of how swat works and don't want to be -able to actually change any Samba config via swat then you may chose -to change <code>"root"</code> to some other user that does not have permission -to write to <a href="smb.conf.5.html"><strong>smb.conf</strong></a>. <p><br>One you have edited <code>/etc/services</code> and <code>/etc/inetd.conf</code> you need to send a HUP signal to inetd. To do this use <code>"kill -1 PID"</code> where PID is the process ID of the inetd daemon. -<p><br><a name="RUNNINGVIACGIBIN"></a> -<h2>RUNNING VIA CGI-BIN</h2> - -<p><br>To run <strong>swat</strong> via your web servers cgi-bin capability you need to -copy the <strong>swat</strong> binary to your cgi-bin directory. Note that you -should run <strong>swat</strong> either via <a href="swat.8.html#RUNNINGVIAINETD"><strong>inetd</strong></a> or via -cgi-bin but not both. -<p><br>Then you need to create a <code>swat/</code> directory in your web servers root -directory and copy the <code>images/*</code> and <code>help/*</code> files found in the -<code>swat/</code> directory of your Samba source distribution into there so -that they are visible via the URL <code>http://your.web.server/swat/</code> -<p><br>Next you need to make sure you modify your web servers authentication -to require a username/pssword for the URL -<code>http://your.web.server/cgi-bin/swat</code>. <em>**Don't forget this -step!**</em> If you do forget it then you will be allowing anyone to edit -your Samba configuration which would allow them to easily gain root -access on your machine. -<p><br>After testing the authentication you need to change the ownership and -permissions on the <strong>swat</strong> binary. It should be owned by root wth the -setuid bit set. It should be ONLY executable by the user that the web -server runs as. Make sure you do this carefully! -<p><br>for example, the following would be correct if the web server ran as -group <code>"nobody"</code>. -<p><br><code>-rws--x--- 1 root nobody </code> -<p><br>You must also realise that this means that any user who can run -programs as the <code>"nobody"</code> group can run <strong>swat</strong> and modify your -Samba config. Be sure to think about this! <p><br><a name="LAUNCHING"></a> <h2>LAUNCHING</h2> -<p><br>To launch <strong>swat</strong> just run your favourite web browser and point it at -<code>http://localhost:901/</code> or <code>http://localhost/cgi-bin/swat/</code> -depending on how you installed it. -<p><br>Note that you can attach to <strong>swat</strong> from any IP connected machine but +<p><br>To launch <strong>swat</strong> just run your favorite web browser and point it at +<code>http://localhost:901/</code>. +<p><br><strong>Note that you can attach to <strong>swat</strong> from any IP connected machine but connecting from a remote machine leaves your connection open to password sniffing as passwords will be sent in the clear over the -wire. -<p><br>If installed via <strong>inetd</strong> then you should be prompted for a -username/password when you connect. You will need to provide the -username <code>"root"</code> and the correct root password. More sophisticated -authentication options are planned for future versions of <strong>swat</strong>. -<p><br>If installed via cgi-bin then you should receive whatever -authentication request you configured in your web server. +wire.</strong> <p><br><h2>FILES</h2> <p><br><strong>/etc/inetd.conf</strong> -<p><br>If the server is to be run by the inetd meta-daemon, this file must -contain suitable startup information for the meta-daemon. See the -section <a href="swat.8.html#RUNNINGVIAINETD"><strong>RUNNING VIA INETD</strong></a> above. +<p><br>This file must contain suitable startup information for the +meta-daemon. <p><br><strong>/etc/services</strong> -<p><br>If running the server via the meta-daemon inetd, this file must -contain a mapping of service name (eg., swat) to service port -(eg., 901) and protocol type (eg., tcp). See the section -<a href="swat.8.html#RUNNINGVIAINETD"><strong>RUNNING VIA INETD</strong></a> above. +<p><br>This file must contain a mapping of service name (e.g., swat) to +service port (e.g., 901) and protocol type (e.g., tcp). <p><br><strong>/usr/local/samba/lib/smb.conf</strong> <p><br>This is the default location of the <em>smb.conf</em> server configuration file that <strong>swat</strong> edits. Other common places that systems install diff --git a/docs/htmldocs/testparm.1.html b/docs/htmldocs/testparm.1.html index d969131b8f..cd7b08232a 100644 --- a/docs/htmldocs/testparm.1.html +++ b/docs/htmldocs/testparm.1.html @@ -3,7 +3,7 @@ -<html><head><title>testparm</title> +<html><head><title>testparm (1)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>testparm</h1> +<h1>testparm (1)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -53,9 +53,9 @@ then testparm will examine the <a href="smb.conf.5.html#hostsallow"><strong>"hos allow"</strong></a> and <a href="smb.conf.5.html#hostsdeny"><strong>"hosts deny"</strong></a> parameters in the <a href="smb.conf.5.html"><strong>smb.conf</strong></a> file to determine if the hostname -with this IP address would be allowed acces to the +with this IP address would be allowed access to the <a href="smbd.8.html"><strong>smbd</strong></a> server. If this parameter is supplied, the -hostIP parameter must also be supplied. +<a href="testparm.1.html#hostIP">hostIP</a> parameter must also be supplied. <p><br><a name="hostIP"></a> <li><strong><strong>hostIP</strong></strong> This is the IP address of the host specified in the previous parameter. This address must be supplied if the hostname diff --git a/docs/htmldocs/testprns.1.html b/docs/htmldocs/testprns.1.html index ef027385f5..62d71a29f2 100644 --- a/docs/htmldocs/testprns.1.html +++ b/docs/htmldocs/testprns.1.html @@ -3,7 +3,7 @@ -<html><head><title>testparm</title> +<html><head><title>testprns (1)</title> <link rev="made" href="mailto:samba-bugs@samba.anu.edu.au"> </head> @@ -11,7 +11,7 @@ <hr> -<h1>testparm</h1> +<h1>testprns (1)</h1> <h2>Samba</h2> <h2>23 Oct 1998</h2> @@ -20,7 +20,7 @@ <p><br><a name="NAME"></a> <h2>NAME</h2> - testparm - check printer name for validity with smbd + testprns - check printer name for validity with smbd <p><br><a name="SYNOPSIS"></a> <h2>SYNOPSIS</h2> @@ -43,7 +43,7 @@ would be wisest to always specify the printcap file to use. <li><strong><strong>printername</strong></strong> The printer name to validate. <p><br>Printer names are taken from the first field in each record in the printcap file, single printer names and sets of aliases separated by -vertical bars ("|") are recognised. Note that no validation or +vertical bars ("|") are recognized. Note that no validation or checking of the printcap syntax is done beyond that required to extract the printer name. It may be that the print spooling system is more forgiving or less forgiving than <strong>testprns</strong>. However, if |