加入收藏 | 设为首页 | 会员中心 | 我要投稿 李大同 (https://www.lidatong.com.cn/)- 科技、建站、经验、云计算、5G、大数据,站长网!
当前位置: 首页 > 综合聚焦 > 服务器 > Linux > 正文

Samba:允许不安全的宽链接

发布时间:2020-12-13 16:56:13 所属栏目:Linux 来源:网络整理
导读:allow insecure wide links: In normal operation the option wide links which allows the server to follow symlinks outside of a share path is automatically disabled when unix extensions are enabled on a Samba server. This is done for security
allow insecure wide links:

In normal operation the option wide links which allows the server to
follow symlinks outside of a share path is automatically disabled when
unix extensions are enabled on a Samba server. This is done for
security purposes to prevent UNIX clients creating symlinks to areas
of the server file system that the administrator does not wish to
export.

Setting allow insecure wide links to true disables the link between
these two parameters,removing this protection and allowing a site to
configure the server to follow symlinks (by setting wide links to
“true”) even when unix extensions is turned on.

根据手动设置允许不安全的宽链接=是应该足以允许符号链接在共享路径之外但是它不适合我,除非我设置unix extensions = no.

testparm甚至没有显示这个变量?!

# testparm -s
Load smb config files from /etc/samba/smb.conf
rlimit_max: increasing rlimit_max (1024) to minimum Windows limit (16384)
Processing section "[Public]"
Loaded services file OK.
Server role: ROLE_STANDALONE
[global]
    workgroup = test
    server string = SambaBox
    syslog = 0
    log file = /var/log/samba/smb.log
    max log size = 50
    smb ports = 139
    socket options = TCP_NODELAY IPTOS_LOWDELAY SO_RCVBUF=65536 SO_SNDBUF=65536
    load printers = No
    printcap name = /dev/null
    disable spoolss = Yes
    show add printer wizard = No
    idmap config * : backend = tdb

[Public]
    comment = Public
    path = /data/Public
    valid users = smbguest
    create mask = 0644
    force create mode = 0644
    force directory mode = 0755
    map archive = No
    wide links = Yes

解决方法

如果您启用了宽链接支持但它不起作用,SELINUX可能会阻止您.

尝试发出setenforce 0并重新测试您的配置.如果它有效,那么你找到了问题的来源.

如果这不起作用,请在[global]部分添加:

>宽链接=是
>允许不安全的宽链接=是
> unix extensions = no

然后重启samba并重新尝试你的测试用例.

(编辑:李大同)

【声明】本站内容均来自网络,其相关言论仅代表作者个人观点,不代表本站立场。若无意侵犯到您的权利,请及时与联系站长删除相关内容!

    推荐文章
      热点阅读