Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
samba_share [2025/05/14 11:06] – [3. Configure Samba (smb.conf)] kkaragozsamba_share [2025/05/14 15:36] (current) – [7.1. Windows] kkaragoz
Line 14: Line 14:
 ===== 2. Create the Folder to Share ===== ===== 2. Create the Folder to Share =====
  
-Decide on a location for your shared folder. A common place for service data is the //<code>/srv</code>// directory.+Decide on a location for your shared folder. A common place for service data is the ''%%/srv%%'' directory.
  
-Create the folder (e.g., //<code>myshare</code>//):+Create the folder (e.g., ''%%myshare%%''):
 <code bash> <code bash>
 sudo mkdir -p /srv/myshare sudo mkdir -p /srv/myshare
 </code> </code>
  
-Set appropriate permissions. For a share where multiple users might read and write, you can create a dedicated group (e.g., //<code>sambashare</code>//) and assign ownership and permissions.+Set appropriate permissions. For a share where multiple users might read and write, you can create a dedicated group (e.g., ''%%sambashare%%'') and assign ownership and permissions.
  
 //Optional: Create a group for Samba users// //Optional: Create a group for Samba users//
Line 34: Line 34:
 </code> </code>
  
-**Note:** //Using //<code>chmod -R 777</code>// would make the folder world-writable, which is less secure and generally not recommended for sensitive data. It's better to manage access through Samba users and specific file permissions.//+**Note:** //Using ''%%chmod -R 777%%'' would make the folder world-writable, which is less secure and generally not recommended for sensitive data. It's better to manage access through Samba users and specific file permissions.//
  
 ===== 3. Configure Samba (smb.conf) ===== ===== 3. Configure Samba (smb.conf) =====
  
-The main Samba configuration file is located at <code>/etc/samba/smb.conf</code>.+The main Samba configuration file is located at ''%%/etc/samba/smb.conf%%''.
  
 ==== 3.1. Backup the Original Configuration File ==== ==== 3.1. Backup the Original Configuration File ====
Line 49: Line 49:
 ==== 3.2. Edit the Configuration File ==== ==== 3.2. Edit the Configuration File ====
  
-Open //<code>smb.conf</code>// using a text editor like //<code>nano</code>// or //<code>vim</code>//:+Open ''%%smb.conf%%'' using a text editor like ''%%nano%%'' or ''%%vim%%'':
 <code bash> <code bash>
 sudo nano /etc/samba/smb.conf sudo nano /etc/samba/smb.conf
Line 74: Line 74:
 </file> </file>
  
-  * //<code>[PublicShare]</code>//: The name that will appear when clients browse the network. +  * ''%%[PublicShare]%%'': The name that will appear when clients browse the network. 
-  * //<code>comment</code>//: A descriptive comment for the share. +  * ''%%comment%%'': A descriptive comment for the share. 
-  * //<code>path</code>//: The absolute path to the folder on your Debian server. +  * ''%%path%%'': The absolute path to the folder on your Debian server. 
-  * //<code>browseable = yes</code>//: Makes the share visible in network browsers. +  * ''%%browseable = yes%%'': Makes the share visible in network browsers. 
-  * //<code>writable = yes</code>// / //<code>read only = no</code>//: Allows users to write to the share. +  * ''%%writable = yes%%'' / ''%%read only = no%%'': Allows users to write to the share. 
-  * //<code>guest ok = yes</code>//: Allows access without requiring a username and password. +  * ''%%guest ok = yes%%'': Allows access without requiring a username and password. 
-  * //<code>create mask</code>// / //<code>directory mask</code>//: Default permissions for newly created files and directories within the share. +  * ''%%create mask%%'' / ''%%directory mask%%'': Default permissions for newly created files and directories within the share. 
-  * //<code>force user</code>// / //<code>force group</code>//: Files and directories will be created with the ownership of this specified user and group (//<code>nobody</code>// and //<code>nogroup</code>// are often used for guest access).+  * ''%%force user%%'' / ''%%force group%%'': Files and directories will be created with the ownership of this specified user and group (''%%nobody%%'' and ''%%nogroup%%'' are often used for guest access).
  
 ==== 3.4. Example 2: Secure Share with User Authentication (Recommended) ==== ==== 3.4. Example 2: Secure Share with User Authentication (Recommended) ====
Line 87: Line 87:
 This is the recommended approach for most situations, as it provides better security. This is the recommended approach for most situations, as it provides better security.
  
-First, ensure the Linux user(s) who will access the share exist on the Debian server. If not, create them using //<code>adduser</code>//:+First, ensure the Linux user(s) who will access the share exist on the Debian server. If not, create them using ''%%adduser%%'':
 <code bash> <code bash>
 sudo adduser shareuser_example sudo adduser shareuser_example
 </code> </code>
-(Replace //<code>shareuser_example</code>// with your desired username.)+(Replace ''%%shareuser_example%%'' with your desired username.)
  
 Next, add this Linux user to Samba's password database. You will be prompted to set a Samba-specific password for this user (it can be different from their Linux system login password). Next, add this Linux user to Samba's password database. You will be prompted to set a Samba-specific password for this user (it can be different from their Linux system login password).
Line 98: Line 98:
 </code> </code>
  
-Now, add the following share definition to your //<code>/etc/samba/smb.conf</code>// file:+Now, add the following share definition to your ''%%/etc/samba/smb.conf%%'' file:
 <file ini> <file ini>
 [SecureShare] [SecureShare]
Line 112: Line 112:
 </file> </file>
  
-  * //<code>valid users</code>//: Specifies which users (e.g., //<code>shareuser_example</code>//) or groups (prefixed with //<code>@</code>//, e.g., //<code>@sambashare</code>//) are allowed to access this share. +  * ''%%valid users%%'': Specifies which users (e.g., ''%%shareuser_example%%'') or groups (prefixed with ''%%@%%'', e.g., ''%%@sambashare%%'') are allowed to access this share. 
-  * Ensure that the Linux file permissions on the shared directory (//<code>/srv/myshare</code>//) allow the specified //<code>valid users</code>// or group members to read and write. For example:+  * Ensure that the Linux file permissions on the shared directory (''%%/srv/myshare%%'') allow the specified ''%%valid users%%'' or group members to read and write. For example:
     <code bash>     <code bash>
-    sudo chown shareuser_example:sambashare /srv/myshare // Or relevant user/group +    sudo chown shareuser_example:sambashare /srv/myshare # Or relevant user/group 
-    sudo chmod -R 770 /srv/myshare // Give read/write/execute to user and group+    sudo chmod -R 770 /srv/myshare # Give read/write/execute to user and group
     </code>     </code>
  
 ===== 4. Check Samba Configuration ===== ===== 4. Check Samba Configuration =====
  
-After saving your changes to //<code>smb.conf</code>//, use the //<code>testparm</code>// utility to check for syntax errors:+After saving your changes to ''%%smb.conf%%'', use the ''%%testparm%%'' utility to check for syntax errors:
 <code bash> <code bash>
 testparm testparm
Line 129: Line 129:
 ===== 5. Restart Samba Services ===== ===== 5. Restart Samba Services =====
  
-To apply the new configuration, restart the Samba daemons (//<code>smbd</code>// and //<code>nmbd</code>//):+To apply the new configuration, restart the Samba daemons (''%%smbd%%'' and ''%%nmbd%%''):
 <code bash> <code bash>
 sudo systemctl restart smbd sudo systemctl restart smbd
Line 143: Line 143:
 ===== 6. Configure Firewall (if ufw is enabled) ===== ===== 6. Configure Firewall (if ufw is enabled) =====
  
-If you are using //<code>ufw</code>// (Uncomplicated Firewall) on your Debian server, you need to allow Samba traffic:+If you are using ''%%ufw%%'' (Uncomplicated Firewall) on your Debian server, you need to allow Samba traffic:
 <code bash> <code bash>
 sudo ufw allow Samba sudo ufw allow Samba
Line 152: Line 152:
 sudo ufw allow proto udp from any to any port 137,138 sudo ufw allow proto udp from any to any port 137,138
 </code> </code>
-Then, reload //<code>ufw</code>//:+Then, reload ''%%ufw%%'':
 <code bash> <code bash>
 sudo ufw reload sudo ufw reload
Line 159: Line 159:
 ===== 7. Connect from Client Computers ===== ===== 7. Connect from Client Computers =====
  
-You can now connect to your Samba share from various client operating systems. Replace //<code>your_server_ip</code>// with the actual IP address of your Debian server (e.g., //<code>192.168.1.100</code>//) and //<code>ShareName</code>// with the name you defined in //<code>smb.conf</code>// (e.g., //<code>PublicShare</code>// or //<code>SecureShare</code>//).+You can now connect to your Samba share from various client operating systems. Replace ''%%your_server_ip%%'' with the actual IP address of your Debian server (e.g., ''%%192.168.1.100%%'') and ''%%ShareName%%'' with the name you defined in ''%%smb.conf%%'' (e.g., ''%%PublicShare%%'' or ''%%SecureShare%%'').
  
 ==== 7.1. Windows ==== ==== 7.1. Windows ====
   - Open File Explorer.   - Open File Explorer.
-  - In the address bar, type: //<code>\\\\your_server_ip</code>// or //<code>\\\\your_server_hostname</code>//+  - In the address bar, type: ''%%\\your_server_ip\SecureShare%%'' or ''%%\\your_server_hostname%%''
   - You should see your defined share(s). Double-click to open.   - You should see your defined share(s). Double-click to open.
-  - If connecting to a secure share, you will be prompted for the username and password you set with //<code>smbpasswd</code>//.+  - If connecting to a secure share, you will be prompted for the username and password you set with ''%%smbpasswd%%''.
   - To make access easier, you can right-click the share and select "Map network drive..." to assign it a drive letter.   - To make access easier, you can right-click the share and select "Map network drive..." to assign it a drive letter.
  
Line 171: Line 171:
   - Open your file manager (e.g., Nautilus, Dolphin, Thunar).   - Open your file manager (e.g., Nautilus, Dolphin, Thunar).
   - Look for an option like "Connect to Server," "Network," or "Browse Network."   - Look for an option like "Connect to Server," "Network," or "Browse Network."
-  - Enter the server address in the format: //<code>smb://your_server_ip/ShareName</code>//+  - Enter the server address in the format: ''%%smb://your_server_ip/ShareName%%''
   - If prompted, enter the credentials for your secure share.   - If prompted, enter the credentials for your secure share.
  
Line 193: Line 193:
       sudo mount -t cifs //your_server_ip/SecureShare /mnt/myserver_share -o username=shareuser_example,uid=$(id -u),gid=$(id -g)       sudo mount -t cifs //your_server_ip/SecureShare /mnt/myserver_share -o username=shareuser_example,uid=$(id -u),gid=$(id -g)
       </code>       </code>
-      (You will be prompted for the Samba password for //<code>shareuser_example</code>//. The //<code>uid=$(id -u)</code>// and //<code>gid=$(id -g)</code>// options help map file ownership to your local user.) +      (You will be prompted for the Samba password for ''%%shareuser_example%%''. The ''%%uid=$(id -u)%%'' and ''%%gid=$(id -g)%%'' options help map file ownership to your local user.) 
-  - To automatically mount the share at boot, you can add an entry to your //<code>/etc/fstab</code>// file. (This is an advanced topic, refer to //<code>fstab</code>// and //<code>mount.cifs</code>// man pages for details).+  - To automatically mount the share at boot, you can add an entry to your ''%%/etc/fstab%%'' file. (This is an advanced topic, refer to ''%%fstab%%'' and ''%%mount.cifs%%'' man pages for details).
  
 ==== 7.4. macOS ==== ==== 7.4. macOS ====
   - Open Finder.   - Open Finder.
   - From the menu bar, click "Go" -> "Connect to Server..." (or press Command+K).   - From the menu bar, click "Go" -> "Connect to Server..." (or press Command+K).
-  - In the "Server Address" field, type: //<code>smb://your_server_ip/ShareName</code>//+  - In the "Server Address" field, type: ''%%smb://your_server_ip/ShareName%%''
   - Click "Connect."   - Click "Connect."
   - If prompted, enter the username and password for your secure share.   - If prompted, enter the username and password for your secure share.
Line 208: Line 208:
  
   * **NFS (Network File System):** Primarily used in Linux/Unix environments. It can be faster than Samba but setting it up for Windows clients is more involved.   * **NFS (Network File System):** Primarily used in Linux/Unix environments. It can be faster than Samba but setting it up for Windows clients is more involved.
-  * **SFTP (SSH File Transfer Protocol):** If you have an SSH server running on your Debian machine (which is common), SFTP is already available. Clients like FileZilla (Windows, macOS, Linux), WinSCP (Windows), or Cyberduck (macOS, Windows) can be used. For Linux and macOS, //<code>sshfs</code>// can mount an SFTP connection as a local filesystem. This doesn't provide network browsing in the same way as Samba but is very secure.+  * **SFTP (SSH File Transfer Protocol):** If you have an SSH server running on your Debian machine (which is common), SFTP is already available. Clients like FileZilla (Windows, macOS, Linux), WinSCP (Windows), or Cyberduck (macOS, Windows) can be used. For Linux and macOS, ''%%sshfs%%'' can mount an SFTP connection as a local filesystem. This doesn't provide network browsing in the same way as Samba but is very secure.
  
 ===== 9. Recommendation ===== ===== 9. Recommendation =====
  
 For most users needing to share folders between a Linux server and various client operating systems including Windows, **Samba is the recommended solution** due to its wide compatibility and ease of use on client machines. Opt for user authentication (Example 2) for better security. For most users needing to share folders between a Linux server and various client operating systems including Windows, **Samba is the recommended solution** due to its wide compatibility and ease of use on client machines. Opt for user authentication (Example 2) for better security.
 +
 +
 +===== 10. Paperless NGX Connection =====
 +
 +You should add the following line. You can change the path's as you created before.
 +<code yml>
 +volumes:
 +      - /srv/myshare:/usr/src/paperless/consume
 +</code>
 +
 +
 +User of SMB's UID should be equal to the USERMAP_UID and USERMAP_GID values. 
 +<code yml>
 +environment:
 +      USERMAP_UID: '1001' # **VERIFY with 'id -u' on your host and CHANGE if needed**
 +      USERMAP_GID: '1001' # **VERIFY with 'id -g' on your host and CHANGE if needed**
 +</code>
 +
Back to top