Samba File Sharing
Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x
Samba implements the SMB/CIFS protocol on EL, letting your Linux server offer file shares that interoperate with Windows, macOS, and other Linux clients. If NFS is the go-to for Linux/Unix-only sharing, Samba is the complement for mixed environments—especially anywhere Windows devices are involved.
What You Will Learn
Section titled “What You Will Learn”- Install the Samba server and client tools
- Edit
/etc/samba/smb.confand validate it withtestparm - Create Samba users and a shared directory
- Handle SELinux booleans and file labels correctly
- Configure firewalld, start the services, and test from a client
- Troubleshoot permission denials, invisible shares, and SMB1 issues
Prerequisites
Section titled “Prerequisites”- A system running EL 9.x or EL 10.x
- A user account with
sudoprivileges - Familiarity with basic File Permissions
Versions Across Distributions
Section titled “Versions Across Distributions”Install Samba
Section titled “Install Samba”The samba package provides the server daemons; samba-client provides test tools such as smbclient.
$ sudo dnf install samba samba-clientThe installation brings in two daemons:
smb(smbd): handles file sharing and authenticationnmb(nmbd): provides NetBIOS name resolution and network browsing (legacy Windows Network Neighborhood)
Create the Shared Directory
Section titled “Create the Shared Directory”This example uses /srv/samba/shared and grants access to the smbgroup group. Create the group first:
$ sudo groupadd smbgroupThen create the directory and set its POSIX permissions (the group that chgrp needs now exists):
$ sudo mkdir -p /srv/samba/shared$ sudo chmod 2770 /srv/samba/shared$ sudo chgrp smbgroup /srv/samba/sharedConfigure smb.conf
Section titled “Configure smb.conf”The main configuration file is /etc/samba/smb.conf, split into a global section [global] and one or more share sections. Here is a minimal working configuration.
[global] workgroup = WORKGROUP server string = Samba Server on EL security = user server min protocol = SMB2 map to guest = Never
[shared] comment = Shared Folder path = /srv/samba/shared browseable = yes writable = yes valid users = @smbgroupWhat each setting means:
| Setting | Description |
|---|---|
workgroup | Workgroup name; must match the Windows clients (default WORKGROUP) |
security = user | Requires username + password authentication (recommended default on EL) |
server min protocol = SMB2 | Disables insecure SMB1 by enforcing SMB2 as the minimum |
path | The local directory backing the share |
browseable = yes | The share appears in the network browse list |
writable = yes | Allows writes (equivalent to read only = no) |
valid users | Users/groups allowed in; @smbgroup means all members of that group |
After editing, always validate the syntax with testparm:
$ testparmLoaded services file OK.Server role: ROLE_STANDALONESeeing Loaded services file OK confirms the syntax is correct.
Create a Samba User
Section titled “Create a Samba User”A Samba user must first be a system user, after which you set a separate Samba password with smbpasswd. The Samba password is independent of the system login password.
-
Create the system user (here
-Mskips the home directory and-s /sbin/nologinblocks interactive login, since this account is only for file sharing):Create the system user $ sudo useradd -M -s /sbin/nologin -G smbgroup alice -
Set a Samba password for the user:
Set the Samba password $ sudo smbpasswd -a aliceInteractive output New SMB password:Retype new SMB password:Added user alice. -
Confirm the user is in the Samba database:
List Samba users $ sudo pdbedit -L
Configure SELinux
Section titled “Configure SELinux”EL systems enable SELinux by default, and it will block Samba from accessing directories that lack the correct label. This step trips up beginners the most—do not “fix” it by disabling SELinux.
Turn On the Read-Write Boolean
Section titled “Turn On the Read-Write Boolean”Let Samba read and write the directories it exports:
$ sudo setsebool -P samba_export_all_rw onFor a read-only share, use instead:
$ sudo setsebool -P samba_export_all_ro onLabel a Custom Path
Section titled “Label a Custom Path”For a custom directory outside the default locations, assign the samba_share_t type label:
$ sudo semanage fcontext -a -t samba_share_t "/srv/samba/shared(/.*)?"$ sudo restorecon -Rv /srv/samba/sharedRelabeled /srv/samba/shared from unconfined_u:object_r:var_t:s0 to unconfined_u:object_r:samba_share_t:s0Configure the Firewall
Section titled “Configure the Firewall”firewalld ships with a built-in samba service definition (covering the required ports), so you can allow it directly:
$ sudo firewall-cmd --add-service=samba --permanent$ sudo firewall-cmd --reloadConfirm the rule took effect:
$ sudo firewall-cmd --list-servicesStart the Services
Section titled “Start the Services”Enable and immediately start both daemons so they also start at boot:
$ sudo systemctl enable --now smb nmbCheck the running status:
$ sudo systemctl status smbTest the Share
Section titled “Test the Share”List Shares Locally
Section titled “List Shares Locally”Use smbclient to list the server’s shares as a given user, verifying the server side works:
$ smbclient -L //localhost -U alice Sharename Type Comment --------- ---- ------- shared Disk Shared FolderMount from a Linux Client
Section titled “Mount from a Linux Client”On another Linux machine, mount the share with the cifs filesystem type. Install the mount helper first:
$ sudo dnf install cifs-utils$ sudo mkdir -p /mnt/samba$ sudo mount -t cifs //server/shared /mnt/samba -o username=aliceYou will be prompted for the Samba password during the mount.
Use a Credentials File (More Secure)
Section titled “Use a Credentials File (More Secure)”Putting a plaintext password on the command line or in fstab is insecure. A better approach is to keep credentials in a protected file:
$ sudo install -m 600 /dev/null /etc/samba/creds-aliceEdit /etc/samba/creds-alice:
username=alicepassword=YourSambaPasswordThen reference it when mounting:
$ sudo mount -t cifs //server/shared /mnt/samba -o credentials=/etc/samba/creds-aliceTo mount automatically at boot, add this to /etc/fstab:
//server/shared /mnt/samba cifs credentials=/etc/samba/creds-alice,_netdev 0 0Optional: Anonymous Guest Share
Section titled “Optional: Anonymous Guest Share”If a share needs to be accessible without a password (for example a public read-only area), you can enable guest access. Adjust [global] so authentication falls back to guest, and add guest ok = yes to the share section:
[global] map to guest = Bad User
[public] comment = Public Read-Only path = /srv/samba/public browseable = yes read only = yes guest ok = yesGuest access maps to the local nobody user, so make sure the directory’s POSIX permissions and SELinux label allow that user to read.
Common Issues
Section titled “Common Issues”Permission Denied (Writes Fail)
Section titled “Permission Denied (Writes Fail)”Check the three permission layers in order:
-
SELinux: confirm the boolean is on and the directory carries the
samba_share_tlabel.View the directory label $ ls -dZ /srv/samba/sharedConfirm the boolean $ getsebool samba_export_all_rw -
POSIX permissions: the user must have write access to the directory (check group ownership and mode bits).
-
valid users: confirm
valid usersinsmb.confincludes the user or a group they belong to.
Client Cannot See the Share
Section titled “Client Cannot See the Share”- Confirm
browseable = yesand that bothsmbandnmbare running. - Use
smbclient -L //server -U <user>to list shares directly, bypassing browsing to isolate the issue. - Check that firewalld allows the
sambaservice.
Old Devices Cannot Connect (SMB1 Disabled)
Section titled “Old Devices Cannot Connect (SMB1 Disabled)”Modern Samba disables insecure SMB1 by default. Some legacy devices (older NAS units, printers) support only SMB1 and will fail to connect. Prefer updating the device’s firmware. If you truly must maintain compatibility, you can temporarily lower the minimum protocol in [global]:
[global] server min protocol = NT1Wrong Password
Section titled “Wrong Password”Make sure you are using the Samba password set with smbpasswd, not the system login password. The two are independent. Use sudo pdbedit -L to confirm the user exists in the Samba database.
Further Reading
Section titled “Further Reading”- NFS and Mounting — the sharing solution for Linux/Unix
- File Permissions and ACLs — understand the POSIX permission layer
- SELinux Basics — troubleshoot file labels and booleans
man smb.conf/man smbclient