12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Samba File Sharing 305To verify that the setting has been changed, execute the following:getsebool samba_enable_home_dirsIf enabled, the output should be the following:samba_enable_home_dirs --> onIf more than one file sharing protocol is configured to share the same set of files such asFTP and Samba, the security context of the files must be set to public_content_t orpublic_content_rw_t instead. Additional SE<strong>Linux</strong> booleans must be enabled as well. Referto the “Security Context for Multiple File-Sharing Protocols” section in Chapter 23 forcomplete instructions.13To use Samba to mount home directories from a Samba server, the use_samba_home_dirsboolean must be set to 1 on each system mounting the home directories.Any of these SE<strong>Linux</strong> booleans can also be modified by running the SE<strong>Linux</strong> ManagementTool. Start it by selecting <strong>Administration</strong>, SE<strong>Linux</strong> Management from the System menuon the top panel of the desktop or by executing the system-config-selinux command.Enter the root password when prompted if running as a non-root user. Select Booleanfrom the list on the left. On the right, click the triangle icon next to Samba. The SE<strong>Linux</strong>booleans affecting Samba appear. A check box appears next to each boolean enabled.Changes take place immediately after modifying the check box.TIPThe SE<strong>Linux</strong> booleans that affect Samba are described in the samba_selinux manpage viewable with the man samba_selinux command.Allowing Samba ConnectionsBefore configuring the Samba server, configure your firewall settings to allow the incomingconnections. The following ports must be opened:. UDP port 137 for netbios-ns, the NETBIOS Name Service. UDP port 138 for netbios-dgm, the NETBIOS Datagram Service. TCP port 139 for netbios-ssn, the NETBIOS session service. TCP port 445 for microsoft-ds, the Microsoft Domain ServiceIf custom IPTables rules are being used, refer to Chapter 24 for details on how to allowthese ports.If the default security level is enabled instead of custom IPTables rules, use the SecurityLevel Configuration tool to allow Samba connections. Start it by selecting <strong>Administration</strong>,Security Level and Firewall from the System menu on the top panel of the desktop or by

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!