Skip to content

Samba File Sharing

Applies to CentOS Stream 9 & 10 / AlmaLinux 9.x & 10.x / Rocky Linux 9.x & 10.x

Samba implements the SMB/CIFS protocol on EL, letting your Linux server offer file shares that interoperate with Windows, macOS, and other Linux clients. If NFS is the go-to for Linux/Unix-only sharing, Samba is the complement for mixed environments—especially anywhere Windows devices are involved.

  • Install the Samba server and client tools
  • Edit /etc/samba/smb.conf and validate it with testparm
  • Create Samba users and a shared directory
  • Handle SELinux booleans and file labels correctly
  • Configure firewalld, start the services, and test from a client
  • Troubleshoot permission denials, invisible shares, and SMB1 issues
  • A system running EL 9.x or EL 10.x
  • A user account with sudo privileges
  • Familiarity with basic File Permissions
Live version data by pkgseek.com

The samba package provides the server daemons; samba-client provides test tools such as smbclient.

Install Samba
$ sudo dnf install samba samba-client

The installation brings in two daemons:

  • smb (smbd): handles file sharing and authentication
  • nmb (nmbd): provides NetBIOS name resolution and network browsing (legacy Windows Network Neighborhood)

This example uses /srv/samba/shared and grants access to the smbgroup group. Create the group first:

Create a group for the share
$ sudo groupadd smbgroup

Then create the directory and set its POSIX permissions (the group that chgrp needs now exists):

Create the directory and set permissions
$ sudo mkdir -p /srv/samba/shared
$ sudo chmod 2770 /srv/samba/shared
$ sudo chgrp smbgroup /srv/samba/shared

The main configuration file is /etc/samba/smb.conf, split into a global section [global] and one or more share sections. Here is a minimal working configuration.

/etc/samba/smb.conf
[global]
workgroup = WORKGROUP
server string = Samba Server on EL
security = user
server min protocol = SMB2
map to guest = Never
[shared]
comment = Shared Folder
path = /srv/samba/shared
browseable = yes
writable = yes
valid users = @smbgroup

What each setting means:

SettingDescription
workgroupWorkgroup name; must match the Windows clients (default WORKGROUP)
security = userRequires username + password authentication (recommended default on EL)
server min protocol = SMB2Disables insecure SMB1 by enforcing SMB2 as the minimum
pathThe local directory backing the share
browseable = yesThe share appears in the network browse list
writable = yesAllows writes (equivalent to read only = no)
valid usersUsers/groups allowed in; @smbgroup means all members of that group

After editing, always validate the syntax with testparm:

Validate the configuration syntax
$ testparm
Output (excerpt)
Loaded services file OK.
Server role: ROLE_STANDALONE

Seeing Loaded services file OK confirms the syntax is correct.

A Samba user must first be a system user, after which you set a separate Samba password with smbpasswd. The Samba password is independent of the system login password.

  1. Create the system user (here -M skips the home directory and -s /sbin/nologin blocks interactive login, since this account is only for file sharing):

    Create the system user
    $ sudo useradd -M -s /sbin/nologin -G smbgroup alice
  2. Set a Samba password for the user:

    Set the Samba password
    $ sudo smbpasswd -a alice
    Interactive output
    New SMB password:
    Retype new SMB password:
    Added user alice.
  3. Confirm the user is in the Samba database:

    List Samba users
    $ sudo pdbedit -L

EL systems enable SELinux by default, and it will block Samba from accessing directories that lack the correct label. This step trips up beginners the most—do not “fix” it by disabling SELinux.

Let Samba read and write the directories it exports:

Allow Samba to read/write shares (persistent)
$ sudo setsebool -P samba_export_all_rw on

For a read-only share, use instead:

Read-only scenario
$ sudo setsebool -P samba_export_all_ro on

For a custom directory outside the default locations, assign the samba_share_t type label:

Set and apply the SELinux file context
$ sudo semanage fcontext -a -t samba_share_t "/srv/samba/shared(/.*)?"
$ sudo restorecon -Rv /srv/samba/shared
restorecon output
Relabeled /srv/samba/shared from unconfined_u:object_r:var_t:s0 to unconfined_u:object_r:samba_share_t:s0

firewalld ships with a built-in samba service definition (covering the required ports), so you can allow it directly:

Allow the Samba service
$ sudo firewall-cmd --add-service=samba --permanent
$ sudo firewall-cmd --reload

Confirm the rule took effect:

List allowed services
$ sudo firewall-cmd --list-services

Enable and immediately start both daemons so they also start at boot:

Start smb and nmb
$ sudo systemctl enable --now smb nmb

Check the running status:

Check service status
$ sudo systemctl status smb

Use smbclient to list the server’s shares as a given user, verifying the server side works:

List shares
$ smbclient -L //localhost -U alice
Output (excerpt)
Sharename Type Comment
--------- ---- -------
shared Disk Shared Folder

On another Linux machine, mount the share with the cifs filesystem type. Install the mount helper first:

Install CIFS tools
$ sudo dnf install cifs-utils
Mount the share
$ sudo mkdir -p /mnt/samba
$ sudo mount -t cifs //server/shared /mnt/samba -o username=alice

You will be prompted for the Samba password during the mount.

Putting a plaintext password on the command line or in fstab is insecure. A better approach is to keep credentials in a protected file:

Create the credentials file
$ sudo install -m 600 /dev/null /etc/samba/creds-alice

Edit /etc/samba/creds-alice:

/etc/samba/creds-alice
username=alice
password=YourSambaPassword

Then reference it when mounting:

Mount using the credentials file
$ sudo mount -t cifs //server/shared /mnt/samba -o credentials=/etc/samba/creds-alice

To mount automatically at boot, add this to /etc/fstab:

/etc/fstab
//server/shared /mnt/samba cifs credentials=/etc/samba/creds-alice,_netdev 0 0

If a share needs to be accessible without a password (for example a public read-only area), you can enable guest access. Adjust [global] so authentication falls back to guest, and add guest ok = yes to the share section:

/etc/samba/smb.conf (excerpt)
[global]
map to guest = Bad User
[public]
comment = Public Read-Only
path = /srv/samba/public
browseable = yes
read only = yes
guest ok = yes

Guest access maps to the local nobody user, so make sure the directory’s POSIX permissions and SELinux label allow that user to read.

Check the three permission layers in order:

  1. SELinux: confirm the boolean is on and the directory carries the samba_share_t label.

    View the directory label
    $ ls -dZ /srv/samba/shared
    Confirm the boolean
    $ getsebool samba_export_all_rw
  2. POSIX permissions: the user must have write access to the directory (check group ownership and mode bits).

  3. valid users: confirm valid users in smb.conf includes the user or a group they belong to.

  • Confirm browseable = yes and that both smb and nmb are running.
  • Use smbclient -L //server -U <user> to list shares directly, bypassing browsing to isolate the issue.
  • Check that firewalld allows the samba service.

Old Devices Cannot Connect (SMB1 Disabled)

Section titled “Old Devices Cannot Connect (SMB1 Disabled)”

Modern Samba disables insecure SMB1 by default. Some legacy devices (older NAS units, printers) support only SMB1 and will fail to connect. Prefer updating the device’s firmware. If you truly must maintain compatibility, you can temporarily lower the minimum protocol in [global]:

Use only as a last resort
[global]
server min protocol = NT1

Make sure you are using the Samba password set with smbpasswd, not the system login password. The two are independent. Use sudo pdbedit -L to confirm the user exists in the Samba database.