Samba guest connections

Hi,
I am trying to comprehend Samba's behaviour on one of my systems and thus I'd
like to ask a couple of quick questions:
The setup I'd like to build is just a small home network for file-sharing using guest connections.
Here it goes,
1) When using the following settings for guest connections,
map to guest = bad user
guest account = nobody
does user 'nobody' have to exist both on Samba AND on the system's accounts?
If yes, is there any other way I can use Samba to serve guest connections without the need to create their respective system accounts? Why is that so?
2) If I change the second option to
guest account = myUnixAccountName
I notice that the system works perfectly well and serves guest connections just fine.
But how is that possible since myUnixAccountName doesn't exist on Samba?
Thanks in advance!

Raynman wrote:
The results you got from (2) should answer the (first) question in (1), and `man smb.conf` also says the guest account has to be an existing UNIX user (no Samba account needed). It's just used for filesystem permissions etc., since guests don't need a password anyway.
Are you happy with that or do you want it the other way around, i.e., a samba account without a unix account for guests (the bit about 'without the need to create system accounts') ? I don't think that's possible/makes sense.
Thanks for the quick response!
You've got me completely covered about guest connections.
However I still would like to know one final thing;
From I understand so far whenever a user wants to connect to a samba server, he/she will have
to eventually assume the identity of a UNIX user for filesystem permissions etc. as you already mentioned above.
Thus I conclude that there are 2 levels of security in filesharing. The first one is what samba allows users to see and
the second and most important is what the underlying unix system allows users to do.
In a scenario where there are 2 users alice and bob, say alice wishes to share her wallpapers in /home/alice/wallpapers.
However that folder's permissions are set to 0700. In smb.conf the wallpapers folder is made available with both reading and writing
permissions for alice and bob. Will bob be able to access and download alice's wallpapers or will he be blocked by the UNIX file permissions?
P.S. I also read here https://help.ubuntu.com/10.04/servergui … urity.html that the libpam-smbpass package syncs UNIX users and passwords with the Samba user database. Does this mean that samba and UNIX passwords can't be different?
Thanks again

Similar Messages

  • Unsecured Guest Connection

    I have set up guest connection.  When guest connects it allowes connection and does not ask for the password that was
    set when I set up the guest connection.
    WHY and how do I change this to make it ask for a password in order for someone to access the guest wireless connection?
    I hve a Linksys E3000 router.

    It might just be a browser issue. Try different internet browsers if you are trying to connect a computer to the Guest Network. Do try to use other computers or devices also that has internet browsers installed or you can install.

  • Does *new* Time Capsule let you limit bandwidth on guest connection?

    I'm curious to know if the new dual-band Time Capsule/AEBS will let you limit bandwidth on the guest connection, or if it will suck up all the available bandwidth without restrictions?

    I would say No to this. Apple wouldn't care much about bandwidth issue but I must admit that could be nice option to play with. But you never know.

  • How do I get guests connected to my wifi?

    How do I get guests connected to my wifi?

    What exactly are you trying to do?
    Do you want to create a seperate guest network or do you want to give guests access to your network without telling them the password (http://docs.info.apple.com/article.html?path=AirPortUtility/5.1/en/ap2118.html) ?
    For a seperate guest network, you need an airport extreme generation 3 or higher or a time capsule generation 2 or higher.
    Post back please, in order to help you!

  • Set up a guest connection

    I want to set up a guest connection to my wi-fi so I don't have to give out my password.

    If your modem and AirPort Express are compatible for this purpose.....
    Open AirPort Utility, select the AirPort Express and click Manual Setup
    You will see a Guest Network tab below the row of icons. Click that tab, assign a name for the guest network, security, and password and  click Update to save the changes.
    The AirPort Express will restart.
    If you do not see a Guest Network tab, either your version of the AirPort Express does not offer this feature or the modem that you are using is not compatible with this feature.
    Post back to let us know which version of the AirPort Express that you have, and we can go over some possible options with you.

  • Linksys e2000 guest connections, limit bandwidth

    How can I limit bandwith speed of guest accounts? Or are there free softwares available to do something like that? It's kinda like the hotspot softwares - where we can set hourly, daily, monthly allowances and see a report on their connectivity.
    Please help.
    Thank you

    As far as I know, you can't do that with the firmware that Linksys provides for that model. Your best bet be to check out DD-wrt and see if they have that feature. I know that you can set up your router as a hotspot using their firmware. Someone else on the forums might be able to provide a specific answer. Btw, what do you mean by guest accounts?
    I don't work for Cisco. I'm just here to help.

  • Is there any way to see what Guest connections are active?

    The DHCP reservation popup only shows connections with full access. I can't see any way to see who/what is connected using a Guest logon. Is there any way to do this?

    You can browse it a little more easily with TextWranger. You can also search it:
    http://homepage.mac.com/bagelturf/aparticles/library/libtw/libtw.html
    See what happens when you restore a vault:
    http://homepage.mac.com/bagelturf/aparticles/vaults/vrestore/vrestore.html
    It actually renames your existing library and creates a new one.

  • Samba guest sharing

    Hi,
    I have a media box (Klegg Mediashare Mega) connected to my TV and my LAN. It only connects to Windows-style guest folders (i.e. no password). After some effort, I was able to get this to find the appropriate shared folder on my iMac back in March using the following link and SharePoints after setting some permissions: http://haggaret.com/node/319 .
    After some updates (10.4.11 and security updates?) this no longer works. The Klegg sees the computer and my managed user but no files. I can't tell if it actually sees the correct folder, but only one folder is shared by this user. I've set every folder/file from "Users" down to the shared folder to "chmod 1777", but no luck. Is there any way still available to 10.4.11 users to share a folder with a Windows user without a password? Does it work in 10.5.x?
    Thanks.

    That problem here is that it is against the Terms of Use (that you accepted) to tell anyone how to do something illegally on these boards.
    The fact that you will be charging your neighbor for access to your account is indeed against every isp's rules that I am aware of. Telling you how to get around those rules is illegal.
    I don't think anyone is trying to be rude by not answering-they just want to keep their account in good standing on these boards.
    In a case like this Google is probably going to be your best friend.

  • Connecting with Tiger to Samba server?

    Hi all,
    We have a new G4 PowerBook running OS X 10.4.3. We have a Linux server running Samba which other machines (running 10.3) are able to connect to via Samba with no problems. Tiger cannot seem to connect. I did some research, and it looks like Tiger requires password authentication. However, several of the workarounds I have found appear to be contradictory. Can anyone succesfully use Samba to connect from Tiger to a Linux machine?
    Thanks,
    Matt

    Depending on the Linux box -Mine is SuSE 10 and I recently had a Fedora 3 box. They use different versions of Samba. Some Tiger likes and some it doesn't. In Fedora, I had no problems with encrypted passwords. In SuSE 10, however, Tiger would not connect with encryption turned on. It needed to be turned off on both Tiger and Linux. Let me know if you need any help with this or if it helps.

  • WRT1900AC Guest Network connection time limit

    I think this is a fresh topic.
    I have searched for this, but can't find any prior topics.
    I upgraded from a Cisco branded E4200 (v1) to a Linksys WRT1900AC.
    I have noticed that the guest network for the 1900AC kicks devices off after a period of time I have not managed to determine, despite them not being disconnected from the network. The device will simply tell me that a hotspot is detected and asks me to sign in. I have to open the browser and enter the password again. This is particularly annoying for work devices on the guest network that use VPN, as I have to get that running as well.
    The E4200 I had before kept guests connected as long as they were on the network; only disconnecting them or taking them out of range for more than a day required me to supply the password again.
    Is this expected behaviour? I'd prefer not to be repeatedly challenged for the guest password for devices that remain connected, just like I could with the E4200.
    I use the 5GHz network for all my permanently connected devices ( a mixture of fixed and dynamic IP's) and leave guests and my work devices to the guest network on 2.4GHz (all dynamic IP's). I have things spaced out well in my home as I had run into issues with interference caused to my Sonos system, which I have eliminated by moving my 2.4GHz connected equipment. The physical layout is the same from when I had my E4200 and my 1900AC, so I'm confident it isn't a physical issue.
    My 2.4GHz network has its SSID hidden to discourage people from using it.

    How many total guests allowed did you set on your router? Make sure that the total number of devices connecting to the Guest network would match the total guests allowed. 

  • How to connect my iPad and iPhone to my new apple tv ?

    how to connect my iPad and iPhone to my new apple tv ?

    Also, make sure that all devices are on the same Wi-Fi network (e.g. not on a "guest" connection), and verify the ATV settings to see that AirPlay (and HomeSharing while you're at it) are turned on.

  • Leopard Clients Take 10 Minutes to Connect to Tiger 10.4.11 Server

    I have a single Tiger server OS X 10.4.11, on a LAN with 5 Tiger Clients and 2 Leopard clients, all with up-to-date patches.
    My problem is, that ALL of the Tiger clients can access any of the server shares almost instantaneously, but when I try to connect a Leopard client the the server, it initially takes a minimum of 10 minutes! If I just click on the server <as displayed on the Finder SHARED tab>, the connection eventually fails. However, if I click on the "Connect as" button, after about 10 minutes, I get the user/password login, and the Leopard client connects immediately, and all the data on all the share points are accessible.
    But, if I don't actually mount a share point (i.e. see a the Network drive icon on the desktop), and use finder column mode to navigate through the shares, if I click on a local drive in the same finder window, I have to go through the whole 10 minute wait again before I see the user/password login.
    So my question:
    Why is it taking a minimum of 10 minutes for the Leopard clients to connect, where as the Tiger clients connect immediately?
    So, if anyone can help me trouble shoot or resolve the server settings so that the Leo clients can connect as quickly as the Tiger clients, I would be extremely grateful.
    BTW - I followed the setup instructions precisely as per the Linda.com *+Mac OS X Server v10.4 Tiger Essential Training+* CD.
    TIA
    Gary
    All the shares are setup as:
    General:
    Share this item and its contents.
    Access:
    Owner=Root (Read & Write);
    Group=Staff (Read & Write);
    Everyone (Read Only);
    No ACL
    Protocols:
    Apple File Settings:
    Share this item using AFP;
    Allow AFP guest access;
    Custom Name=<unique name>;
    Default permissions for new files and folders=Use standard POSIX behavior
    Windows File Settings:
    Share this item using SMB
    Allow SMB guest access
    Enable strict locking
    Default permissions for new files and folders:
    Assign as follows: Owner=Read & Write; Group=Read & Write; Everyone=Read Only
    FTP Settings
    Share this item using FTP
    Allow FTP guest access
    Common FTP name: <same unique name>
    Network Mount
    Where: LDAPv3.127.0.0.1 (locked)
    AFP is setup as follows:
    General:
    Enable Bonjour registration
    Access:
    Authentication=Standard
    Enable Secure connections
    Client & Guest connections=Unlimited
    Logging:
    (Everything); Archive every 7 days
    Idle Users: (nothing checked
    All staff members are defined as part of the "staff" group.

    Windows File Settings:
    Share this item using SMB
    Allow SMB guest access
    Enable strict locking
    Default permissions for new files and folders:
    Do you have any Windows clients on your network? If not turn OFF the SMB server and change the settings here so there is no SMB sharing.
    FTP Settings
    Share this item using FTP
    Allow FTP guest access
    Common FTP name: <same unique name>
    Do your users access this sharepoint with FTP from inside your network? If not, stop the FTP server and change the settings to not share this via FTP.
    General:
    Enable Bonjour registration
    Turn this off for all sharepoints. If you have no Bonjour-only printers -like some of those POS HP color Laserjet 26xx or 36xx series- enter this in Terminal.app or through the 'Send UNIX command...' in ARD to all of your Leopard clients:
    launchctl unload -w /System/Library/LaunchDaemons/com.apple.mDNSResponder.plist
    user should be root if sent from ARD, prepend 'sudo' (without quotes) if in Terminal.app or if you're using an admin username from ARD. This turns off Bonjour.
    Also, in WGM, look at each individual user account and see if the 'Primary Group ID' is listed in the 'Other Groups' list. If it's not, click the '+' sign and drag the user's primary group into the 'Other Groups' list and then save. You can 'shift-click' and select groups of users and add the group to them all at once if they are all in the same groups.
    Access:
    Authentication=Standard
    Change the access to 'Any Method'. If your clients are all bound to the OD master and the sharepoints are listed in the directory (meaning Kerberos SSO works for all clients and users), the clients will try Kerberos first and anything else -like DHX authentication- if that fails. Also, if you are managing your clients with MCX you should have those shares mounting before log-in -meaning at startup- using guest access or at login with the username/pass.

  • WIRELESS IOS AUTONOMOUS + Guest to internet + authenticated via a web page.

    Hi to all,
    need to configure with:
    - AUTONOMOUS IOS AP (NOT use a wireless controller)
    - CISCO IOS router 2811
    a guest wireless network that only has access to the internet through a vlan WITH HTTP/S GUEST AUTHENTICATION WEB PAGE ?
    I know:
    "web authorization isn't native to the access point. It is a web authorization portal that is on the WLC."
    "Cisco IT example: At present we use GRE tunnels for guest traffic which was a part of legacy guest networking solution we had at Cisco for several years. GRE tunnels get terminated at one the DMZ routers. Each request for a guest connection to the Internet gets authenticated over https by either a Cisco Building BroadBand Services Manager (BBSM) or a Cisco NAC Appliance. Guests get provided with an access code in advance as we use a web based portal/application to produce those. Also we support guest connections for both wireless and wired clients from some switch ports. "
    I am looking for any suggestions (are there any feature on CISCO IOS ROUTER for "HTTP/S GUEST AUTHENTICATION WEB PAGE").
    Thanks.
    Roberto Taccon

    If the router with auth proxy is the one providing the ip address on the client connecting to the autonomous AP, it may be an option.
    Local AAA will not work with auth proxy as then there you are no longer in a scenario where the router is proxy.
    You could get a WLC526 (small controller) to get the web auth, or a free radius server (many out there) that will run on a linux server and then use the http proxy feature.
    I personally recommend you to get a WLC, in the long run you will benefit of many more features and you will be able to very easily add other access points.
    The WLC526 is the smaller one:
    http://www.cisco.com/en/US/docs/wireless/controller/526/1.5/configuration/guide/2_add_contr.html

  • WLC to ISE authentication for Guest

    Hi Experts,
    Hope if you could guide me with our setup for Guest users. Below is what we are doing
    a)     Guest connects to SSID
    b)     WLC is being used to redirect Guest HTTP to WLC internal Portal
    c)     WLC forwards guest authentication details to cisco ISE [ISE and WLC radius]
    The guest connects to SSID and does get WLC portal for authentication, when the username and password entered on Cisco ISE i see error message as
    'User Identity not found in any of Identity Store' though it is going through correct Store and the Guest name is certainly configured on Cisco ISE. ISE version is 1.2 and WLC is 7.4, please let me know if i am missing anything here.
    Appreciate your help

    The first method is local web authentication. In this case, the WLC redirects the HTTP traffic to an internal or external server where the user is prompted to authenticate. The WLC then fetches the credentials (sent back via an HTTP GET request in the case of external server) and makes a RADIUS authentication. In the case of a guest user, an external server (such as Identity Services Engine (ISE) or NAC Guest Server (NGS)) is required as the portal provides features such as device registering and self-provisioning. The flow includes these steps:
    Please follow below guide for step by step configuration:
    http://www.cisco.com/en/US/products/ps11640/products_configuration_example09186a0080bead09.shtml

  • Why did Mavericks disconnet my wi-fi connection?

    I downloaded the free Mavericks upgrade and installed with no problem. However, for some reason my Linksys wi-fi network connection was disconnected and now I cannot reconnect unless I use the guest connection. I've tried entering the password for the main connection for my iMac but it won't go.
    Any help?
    Thanks.

    I can establish an unsecure connection but nothing else. I tried uninstalling my Cisco Linksys router and resetting and reinstalling with the Cisco Setup Install CD, but I just keep getting a message that the router only supports certain OS and no other dialog windows. If this keeps up maybe I should just get a new wi-fi router and start from scratch? My current one is about two years old.

Maybe you are looking for

  • Apple won't let me change my ID from hotmail to icloud address.  Why?

    My old hotmail address gets full of spam, and I no longer want to use it as my Apple ID.  Can I change it to my new icloud email address?  When I change my ID to my icloud email address, Apple tells me I cannot use it.  Help.

  • How can I burn somgs I have on my Zen Xtra to

    Hello guys again. I have so man songs on my mp3 player now and my friend wants me to burn him a cd of an album i have on there. When I open media source organizer I do not have a burn cd option or anything. I know there is a update for this but whne

  • SQL LOADER. Numeric values loaded as Varchar2 characters

    Dear all, please I need your help in this little problem . I am loading using SQL Loader a data file where a field X has a numeric value, and in the Control file it is defined as numeric value as well in the database table but the strange thing is th

  • CR4E Question on PDF exports

    Hello, I am using Crystal Reports for Eclipse and I can't seem to find the answer to this quesiton in the documentation.  I am wondering if there is a way, using the CR4E JRC library, to run a report (my reports use POJOs in case that matters) and ex

  • Hyperlink in a jTextArea

    Hi I've different strings of text which I wrote in a jTextArea. How can I implement that when I click on one of these text-lines I can excute an ActionEvent? Should be something like the hyperlink system; however to an other jTextArea. Thanks in adva