Chapter 6. Users, Security, and Domains
This chapter discusses how to configure users with the Samba server. This topic may seem straightforward at first, but you’ll soon discover that there are several ancillary problems that can crop up. One issue that Samba administrators have difficulty with is user authentication—password and security problems are by far the most common support questions on the Samba mailing lists. Learning why various authentication mechanisms work on certain architectures (and don’t on others) can save you a tremendous amount of time testing and debugging Samba users in the future.
Users and Groups
Before we start, we need to warn you up front that if you are connecting to Samba with a Windows 98 or NT 4.0 Workstation SP3, you need to configure your server for encrypted passwords before you can make a connection; otherwise, the clients will refuse to connect to the Samba server. This is because each of those Windows clients sends encrypted passwords, and Samba needs to be configured to expect and decrypt them. We’ll show you how to set up Samba for this task later in the chapter, assuming you haven’t already tackled this problem in Chapter 2.
Let’s start with a single user. The easiest way to set up a client user is to create a Unix account (and home directory) for that individual on the server, and notify Samba of the user’s existence. You can do the latter by creating a disk share that maps to the user’s home directory in the Samba configuration file, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access