summaryrefslogtreecommitdiff
path: root/docs/Samba3-HOWTO/TOSHARG-ConfigSmarts.xml
blob: f46cc8e1811be925f5deaa08b2a469c2a3486260 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE chapter PUBLIC "-//Samba-Team//DTD DocBook V4.2-Based Variant V1.0//EN" "http://www.samba.org/samba/DTD/samba-doc">
<chapter id="cfgsmarts">
<chapterinfo>
	&author.jht;
	<pubdate>June 30, 2005</pubdate>
</chapterinfo>
<title>Advanced Configuration Techniques</title>

<para>
<indexterm><primary>configuration techniques</primary></indexterm>
<indexterm><primary>include</primary></indexterm>
Since the release of the first edition of this book there have been repeated requests to better document
configuration techniques that may help a network administrator to get more out of Samba. Some users have asked
for documentation regarding the use of the <smbconfoption name="include">file-name</smbconfoption> parameter.
</para>

<para>
<indexterm><primary>multiple servers</primary></indexterm>
<indexterm><primary>multiple server personalities</primary></indexterm>
Commencing around mid-2004 there has been increasing interest in the ability to host multiple Samba servers on
one machine. There has also been an interest in the hosting of multiple Samba server personalities on one
server.
</para>

<para>
<indexterm><primary>technical reviewers</primary></indexterm>
<indexterm><primary>reviewers</primary></indexterm>
Feedback from technical reviewers made the inclusion of this chapter a necessity. So, here is an 
answer the questions that have to date not been adequately addressed. Additional user input is welcome as
it will help this chapter to mature. What is presented here is just a small beginning.
</para>

<para>
<indexterm><primary>multiple servers</primary></indexterm>
<indexterm><primary>multiple hosting</primary></indexterm>
<indexterm><primary>domain controllers</primary></indexterm>
There are a number of ways in which multiple servers can be hosted on a single Samba server. Multiple server
hosting makes it possible to host multiple domain controllers on one machine. Each such machine is
independent, and each can be stopped or started without affecting another.
</para>

<para>
<indexterm><primary>multiple servers</primary></indexterm>
<indexterm><primary>DMS</primary></indexterm>
<indexterm><primary>anonymous server</primary></indexterm>
Sometimes it is desirable to host multiple servers, each with its own security mode. For example, a single
UNIX/Linux host may be a domain member server (DMS) as well as a generic anonymous print server. In this case,
only domain member machines and domain users can access the DMS, but even guest users can access the generic
print server. Another example of a situation where it may be beneficial to host a generic (anonymous) server
is to host a CDROM server.
</para>

<para>
<indexterm><primary>separate servers</primary></indexterm>
<indexterm><primary></primary></indexterm>
Some environments dictate the need to have separate servers, each with their own resources, each of which are
accessible only by certain users or groups. This is one of the simple, but highly effective, ways that Samba
can replace many physical Windows servers in one Samba installation.
</para>

<sect1>
<title>Implementation</title>

<para>
</para>

<sect2>
<title>Multiple Server Hosting</title>

<para>
<indexterm><primary>multiple server hosting</primary></indexterm>
<indexterm><primary>separate instances</primary></indexterm>
<indexterm><primary>nmbd</primary></indexterm>
<indexterm><primary>smbd</primary></indexterm>
<indexterm><primary>winbindd</primary></indexterm>
<indexterm><primary>recompiling</primary></indexterm>
<indexterm><primary>TDB</primary></indexterm>
The use of multiple server hosting involves running multiple separate instances of Samba, each with it's own
configuration file. This method is complicated by the fact that each instance of &nmbd;, &smbd; and &winbindd;
must have write access to entirely separate TDB files. The ability to keep separate the TDB files used by
&nmbd;, &smbd; and &winbindd; can be enabled either by recompiling Samba for each server hosted so each has its
own default TDB directories, or by configuring these in the &smb.conf; file, in which case each instance of
&nmbd;, &smbd; and &winbindd; must be told to start up with its own &smb.conf; configuration file.
</para>

<para>
<indexterm><primary>independent</primary></indexterm>
<indexterm><primary>listen own socket</primary></indexterm>
<indexterm><primary>socket</primary></indexterm>
<indexterm><primary>SID</primary></indexterm>
Each instance should operate on its own IP address (that independent IP address can be an IP Alias).
Each instance of &nmbd;, &smbd; and &winbindd; should listen only on its own IP socket. This can be secured
using the <smbconfoption name="socket address"/> parameter. Each instance of the Samba server will have its
own SID also, this means that the servers are discrete and independent of each other.
</para>

<para>
<indexterm><primary>multiple server hosting</primary></indexterm>
<indexterm><primary>private dir</primary></indexterm>
<indexterm><primary>pid directory</primary></indexterm>
<indexterm><primary>lock directory</primary></indexterm>
<indexterm><primary>interfaces</primary></indexterm>
<indexterm><primary>bind interfaces only</primary></indexterm>
<indexterm><primary>netbios name</primary></indexterm>
<indexterm><primary>workgroup</primary></indexterm>
<indexterm><primary>socket address</primary></indexterm>
The user of multiple server hosting is non-trivial, and requires careful configuration of each aspect of
process management and start up. The &smb.conf; parameters that must be carefully configured includes:
<smbconfoption name="private dir"/>, <smbconfoption name="pid directory"/>,<smbconfoption name="lock
directory"/>, <smbconfoption name="interfaces"/>, <smbconfoption name="bind interfaces only"/>, <smbconfoption
name="netbios name"/>, <smbconfoption name="workgroup"/>, <smbconfoption name="socket address"/>.
</para>

<para>
<indexterm><primary>multiple servers</primary></indexterm>
<indexterm><primary>contribute</primary></indexterm>
<indexterm><primary>comprehensive documentation</primary></indexterm>
Those who elect to create multiple Samba servers should have the ability to read and follow
the Samba source code, and to modify it as needed. This mode of deployment is considered beyond the scope of
this book. However, if someone will contribute more comprehensive documentation we will gladly review it, and
if it is suitable extend this section of this chapter. Until such documentation becomes available the hosting
of multiple samba servers on a single host is considered not supported for Samba-3 by the Samba Team.
</para>

</sect2>

<sect2>
<title>Multiple Virtual Server Personalities</title>

<para>
<indexterm><primary>multiple virtual servers</primary></indexterm>
<indexterm><primary>netbios alias</primary></indexterm>
<indexterm><primary>meta-services</primary></indexterm>
Samba has the ability to host multiple virtual servers, each of which have their own personality.  This is
achieved by configuring an &smb.conf; file that is common to all personalities hosted.  Each server
personality is hosted using its own <smbconfoption name="netbios alias"/> name, and each has its own distinct
<smbconfoption name="[global]"/> section. Each server may have its own stanzas for services and meta-services.
</para>

<para>
<indexterm><primary>workgroup</primary></indexterm>
<indexterm><primary>security</primary></indexterm>
<indexterm><primary>netbios aliases</primary></indexterm>
When hosting multiple virtual servers, each with their own personality, each can be in a different workgroup.
Only the primary server can be a domain member or a domain controller. The personality is defined by the
combination of the <smbconfoption name="security"/> mode it is operating in, the <smbconfoption name="netbios
aliases"/> it has, and the <smbconfoption name="workgroup"/> that is defined for it.
</para>

<para>
<indexterm><primary>NetBIOS name</primary></indexterm>
<indexterm><primary>NetBIOS-less SMB</primary></indexterm>
<indexterm><primary>smb ports</primary></indexterm>
<indexterm><primary>TCP port 139</primary></indexterm>
<indexterm><primary>TCP port 445</primary></indexterm>
<indexterm><primary>%L</primary></indexterm>
This configuration style can be used either with NetBIOS names, or using NetBIOS-less SMB over TCP services.
If run using NetBIOS mode (the most common method) it is important that the parameter <smbconfoption name="smb
ports">139</smbconfoption> should be specified in the primary &smb.conf; file. Failure to do this will result
in Samba operating over TCP port 445 and problematic operation at best, and at worst only being able to obtain
the functionality that is specified in the primary &smb.conf; file. The use of NetBIOS over TCP/IP using only
TCP port 139 means that the use of the <literal>%L</literal> macro is fully enabled. If the <smbconfoption
name="smb ports">139</smbconfoption> is not specified (the default is <parameter>445 139</parameter>, or if
the value of this parameter is set at <parameter>139 445</parameter> then the <literal>%L</literal> macro
is not serviceable.
</para>

<para>
<indexterm><primary>host multiple servers</primary></indexterm>
<indexterm><primary>multiple personality</primary></indexterm>
<indexterm><primary>NetBIOS-less</primary></indexterm>
<indexterm><primary>%i macro</primary></indexterm>
It is possible to host multiple servers, each with their own personality, using port 445 (the NetBIOS-less SMB
port), in which case the <literal>%i</literal> macro can be used to provide separate server identities (by
IP Address). Each can have its own <smbconfoption name="security"/> mode. It will be necessary to use the
<smbconfoption name="interfaces"/>, <smbconfoption name="bind interfaces only"/> and IP aliases in addition to
the <smbconfoption name="netbios name"/> parameters to create the virtual servers. This method is considerably
more complex than that using NetBIOS names only using TCP port 139.
</para>

<para>
<indexterm><primary>anonymous file server</primary></indexterm>
Consider an example environment that consists of a standalone, user-mode security Samba server and a read-only
Windows 95 file server that has to be replaced. Instead of replacing the Windows 95 machine with a new PC, it
is possible to add this server as a read-only anonymous file server that is hosted on the Samba server. Here
are some parameters:
</para>

<para>
The Samba server is called <literal>ELASTIC</literal>, its workgroup name is <literal>ROBINSNEST</literal>.
The CDROM server is called <literal>CDSERVER</literal> and its workgroup is <literal>ARTSDEPT</literal>. A
possible implementation is shown here:
</para>

<para>
<indexterm><primary>/etc/samba</primary></indexterm>
<indexterm><primary>nmbd</primary></indexterm>
<indexterm><primary>smbd</primary></indexterm>
<indexterm><primary>smb.conf</primary></indexterm>
The &smb.conf; file for the master server is shown in <link linkend="elastic">Elastic smb.conf File</link>.
This file is placed in the <filename>/etc/samba</filename> directory. Only the &nmbd; and the &smbd; daemons
are needed. When started the server will appear in Windows Network Neighborhood as the machine
<literal>ELASTIC</literal> under the workgroup <literal>ROBINSNEST</literal>. It is helpful if the Windows
clients that must access this server are also in the workgroup <literal>ROBINSNEST</literal> as this will make
browsing much more reliable.
</para>

<example id="elastic">
<title>Elastic smb.conf File</title>
<smbconfblock>
<smbconfcomment>Global parameters</smbconfcomment>
<smbconfsection name="[global]"/>
<smbconfoption name="workgroup">ROBINSNEST</smbconfoption>
<smbconfoption name="netbios name">ELASTIC</smbconfoption>
<smbconfoption name="netbios aliases">CDSERVER</smbconfoption>
<smbconfoption name="smb ports">139</smbconfoption>
<smbconfoption name="printcap name">cups</smbconfoption>
<smbconfoption name="disable spoolss">Yes</smbconfoption>
<smbconfoption name="show add printer wizard">No</smbconfoption>
<smbconfoption name="printing">cups</smbconfoption>
<smbconfoption name="include">/etc/samba/smb-%L.conf</smbconfoption>

<smbconfsection name="[homes]"/>
<smbconfoption name="comment">Home Directories</smbconfoption>
<smbconfoption name="valid users">%S</smbconfoption>
<smbconfoption name="read only">No</smbconfoption>
<smbconfoption name="browseable">No</smbconfoption>

<smbconfsection name="[office]"/>
<smbconfoption name="comment">Data</smbconfoption>
<smbconfoption name="path">/data</smbconfoption>
<smbconfoption name="read only">No</smbconfoption>

<smbconfsection name="[printers]"/>
<smbconfoption name="comment">All Printers</smbconfoption>
<smbconfoption name="path">/var/spool/samba</smbconfoption>
<smbconfoption name="create mask">0600</smbconfoption>
<smbconfoption name="guest ok">Yes</smbconfoption>
<smbconfoption name="printable">Yes</smbconfoption>
<smbconfoption name="use client driver">Yes</smbconfoption>
<smbconfoption name="browseable">No</smbconfoption>
</smbconfblock>
</example>

<para>
<indexterm><primary>smb-cdserver.conf</primary></indexterm>
The configuration file for the CDROM server is listed in <link linkend="cdserver">CDROM Server
smb-cdserver.conf file</link>. This file is called <filename>smb-cdserver.conf</filename> and it should be
located in the <filename>/etc/samba</filename> directory. Machines that are in the workgroup
<literal>ARTSDEPT</literal> will be able to browse this server freely.
</para>

<example id="cdserver">
<title>CDROM Server smb-cdserver.conf file</title>
<smbconfblock>
<smbconfcomment>Global parameters</smbconfcomment>
<smbconfsection name="[global]"/>
<smbconfoption name="workgroup">ARTSDEPT</smbconfoption>
<smbconfoption name="netbios name">CDSERVER</smbconfoption>
<smbconfoption name="map to guest">Bad User</smbconfoption>
<smbconfoption name="guest ok">Yes</smbconfoption>

<smbconfsection name="[carousel]"/>
<smbconfoption name="comment">CDROM Share</smbconfoption>
<smbconfoption name="path">/export/cddata</smbconfoption>
<smbconfoption name="read only">Yes</smbconfoption>
<smbconfoption name="guest ok">Yes</smbconfoption>
</smbconfblock>
</example>

<para>
<indexterm><primary>different resources</primary></indexterm>
<indexterm><primary>separate workgroups</primary></indexterm>
<indexterm><primary>read-only access</primary></indexterm>
<indexterm><primary>nobody account</primary></indexterm>
The two servers have different resources and are in separate workgroups. The server <literal>ELASTIC</literal>
can only be accessed by uses who have an appropriate account on the host server. All users will be able to
access the CDROM data that is stored in the <filename>/export/cddata</filename> directory. File system
permissions should set so that the <literal>others</literal> user has read-only access to the directory and its
contents. The files can be owned by root (any user other than the nobody account).
</para>

</sect2>

<sect2>
<title>Multiple Virtual Server Hosting</title>

<para>
<indexterm><primary>primary domain controller</primary></indexterm>
<indexterm><primary>extra machine</primary></indexterm>
<indexterm><primary>same domain/workgroup</primary></indexterm>
In this example, the requirement is for a primary domain controller for the domain called
<literal>MIDEARTH</literal>. The PDC will be called <literal>MERLIN</literal>. An extra machine called
<literal>SAURON</literal> is required. Each machine will have only its own shares. Both machines belong to the
same domain/workgroup.
</para>

<para>
<indexterm><primary>master smb.conf</primary></indexterm>
<indexterm><primary>/etc/samba</primary></indexterm>
<indexterm><primary></primary></indexterm>
The master &smb.conf; file is shown in <link linkend="mastersmbc">the Master smb.conf File Global Section</link>.
The two files that specify the share information for each server are shown in <link linkend="merlinsmbc">the
smb-merlin.conf File Share Section</link>, and <link linkend="sauronsmbc">the smb-sauron.conf File Share
Section</link>. All three files are locate in the <filename>/etc/samba</filename> directory.
</para>

<example id="mastersmbc">
<title>Master smb.conf File Global Section</title>
<smbconfblock>
<smbconfcomment>Global parameters</smbconfcomment>
<smbconfsection name="[global]"/>
<smbconfoption name="workgroup">MIDEARTH</smbconfoption>
<smbconfoption name="netbios name">MERLIN</smbconfoption>
<smbconfoption name="netbios aliases">SAURON</smbconfoption>
<smbconfoption name="passdb backend">tdbsam</smbconfoption>
<smbconfoption name="smb ports">139</smbconfoption>
<smbconfoption name="syslog">0</smbconfoption>
<smbconfoption name="printcap name">CUPS</smbconfoption>
<smbconfoption name="show add printer wizard">No</smbconfoption>
<smbconfoption name="add user script">/usr/sbin/useradd -m '%u'</smbconfoption>
<smbconfoption name="delete user script">/usr/sbin/userdel -r '%u'</smbconfoption>
<smbconfoption name="add group script">/usr/sbin/groupadd '%g'</smbconfoption>
<smbconfoption name="delete group script">/usr/sbin/groupdel '%g'</smbconfoption>
<smbconfoption name="add user to group script">/usr/sbin/usermod -G '%g' '%u'</smbconfoption>
<smbconfoption name="add machine script">/usr/sbin/useradd -s /bin/false -d /var/lib/nobody '%u'</smbconfoption>
<smbconfoption name="logon script">scripts\login.bat</smbconfoption>
<smbconfoption name="logon path"> </smbconfoption>
<smbconfoption name="logon drive">X:</smbconfoption>
<smbconfoption name="domain logons">Yes</smbconfoption>
<smbconfoption name="preferred master">Yes</smbconfoption>
<smbconfoption name="wins support">Yes</smbconfoption>
<smbconfoption name="printing">CUPS</smbconfoption>
<smbconfoption name="include">/etc/samba/smb-%L.conf</smbconfoption>
</smbconfblock>
</example>

<example id="merlinsmbc">
<title>MERLIN smb-merlin.conf File Share Section</title>
<smbconfblock>
<smbconfcomment>Global parameters</smbconfcomment>
<smbconfsection name="[global]"/>
<smbconfoption name="workgroup">MIDEARTH</smbconfoption>
<smbconfoption name="netbios name">MERLIN</smbconfoption>

<smbconfsection name="[homes]"/>
<smbconfoption name="comment">Home Directories</smbconfoption>
<smbconfoption name="valid users">%S</smbconfoption>
<smbconfoption name="read only">No</smbconfoption>
<smbconfoption name="browseable">No</smbconfoption>

<smbconfsection name="[office]"/>
<smbconfoption name="comment">Data</smbconfoption>
<smbconfoption name="path">/data</smbconfoption>
<smbconfoption name="read only">No</smbconfoption>

<smbconfsection name="[netlogon]"/>
<smbconfoption name="comment">NETLOGON</smbconfoption>
<smbconfoption name="path">/var/lib/samba/netlogon</smbconfoption>
<smbconfoption name="read only">Yes</smbconfoption>
<smbconfoption name="browseable">No</smbconfoption>

<smbconfsection name="[printers]"/>
<smbconfoption name="comment">All Printers</smbconfoption>
<smbconfoption name="path">/var/spool/samba</smbconfoption>
<smbconfoption name="printable">Yes</smbconfoption>
<smbconfoption name="use client driver">Yes</smbconfoption>
<smbconfoption name="browseable">No</smbconfoption>
</smbconfblock>
</example>

<example id="sauronsmbc">
<title>SAURON smb-sauron.conf File Share Section</title>
<smbconfblock>
<smbconfcomment>Global parameters</smbconfcomment>
<smbconfsection name="[global]"/>
<smbconfoption name="workgroup">MIDEARTH</smbconfoption>
<smbconfoption name="netbios name">SAURON</smbconfoption>

<smbconfsection name="[www]"/>
<smbconfoption name="comment">Web Pages</smbconfoption>
<smbconfoption name="path">/srv/www/htdocs</smbconfoption>
<smbconfoption name="read only">No</smbconfoption>
</smbconfblock>
</example>

</sect2>

</sect1>

</chapter>