Samba on Linux the Easy Way
glovesoff.substack.com
glovesoff.substack.com
Now the same person should write a “wireguard on Linux — the easy way”. (Which would probably be — use tailscale)
I agree that wireguard is the way. Besides tailscale, a bit of config autogeneration goes a long way there - easy-wg-quick and friends
A friend of mine has been trying to learning Linux this month, and he came to me frustrated, losing his mind. A whole day going all over the place on the Internet, obviously following tutorials he didn’t understand, and installing who knows what, and I asked, did you install SAMBA? He asked, what’s that? However the package was installed and I explained smb.conf file and SMB user.
The problem is people are lazy and don’t want to look stupid. So they will spend days searching the web, reading through the endless ‘blind leading the blind’ user forums (Ubuntu comes to mind), instead of RTFM. And won’t ask someone for help until they have wrapped their brain into a frustrated knot.
A lot of the shitty guides do the equivalent of saying "nmap? Just run sudo nmap -sS HOSTNAME to do a port scan!", but spread out across ten pages of SEO crap. It's not exactly wrong, but it's not exactly helpful either. The trouble is, of course, that now if you Google "how to do a port scan Linux" you get that guide, rather than the manual that explains in detail why it's a hard problem and a bunch of ways and subtleties about doing it. Fast forward ten years and anything other than -sS looks weird.
Samba is the same, but somehow, infinitely more complex in detail and, because the tools have different names, less searchable. Want to mount and active directory share? You probably need kinit and to know the word "Kerberos". Browse other shares? Smbtree. Make them persistent together and mount on boot? That's another silly, overly detailed guide. And each one of these guides comes with its own lack of detailed understanding by the authors, focus on ads and SEO, and further obscures the fact that the original FM covers all of this in detail, but it's long and complicated, because, well, it's complicated!
I personally think that open source projects would do well to maintain a cookbook FAQ of "here is a set of common usages of this tool". Many man pages do, with one liners, but anything more complex tends to be hidden. It would be great if those who understand the complex subtleties involved write a definitive way to do things, rather than expecting everyone to read all of TFM all the time -- and I equally realise that, as someone who makes complex software to do complex things, half the time you really would rather your users RTFM you spent so long writing at any rate...
Of course I'm more of a tinker, so I'll mess with something first intentionally before going to the manual. What you get stuck on is what teaches you what part of the manual is most important for you.
Also, I recall that reading though a Samba config file (it's been a decade, maybe it's gotten better) while instructive, is nearly equivalent to reading a novella. Sure I can configure domains and users, but I don't need any of that.
A mandatory half pager trying to setup a typical newbie use case would be a huge improvement for most manuals that I have seen.
Documentation needs two parts, a reference written by the authors and a tutorial written by someone with no prior experience with the software going though their process learning it from scratch.
I have docker clients on the linux boxes that use the samba share for storage. Eventually I figured out that didn't work well with sqlite files, so I mapped those to local folders instead. But there are still issues with permissions when the linux clients reboot. I usually have to shut down docker, unmount the share, and re-mount with `sudo mount -a`.
Fwiw, this is my fstab line below. I think the network is up when the fstab gets mounted, because there are files visible in the /media/data tree - it just sometimes needs to be unmounted and remounted for everything to work correctly. Haven't found anything in the logs.
//server/data /media/data cifs
nofail,rw,vers=3.0,credentials=/path/to/smbcredentials,uid=1000,gid=1000
I don't know as much about Windows, and the Windows server is not mine, otherwise I would get rid of that junk.I don't know if Ubuntu 22.04 changed this process or if your friend is using a less user friendly distro but I found this to be one of the easier things to do in Linux. You don't need to bother with smb.conf or whatever if your software ecosystem has built in SMB integrations (like they should, if they target the non-technically minded).
I do know that recent GNOME installs come with built in remote desktop over RDP which is a godsent. xrdp works great once you get it working but to do that you should be prepared to take the three hour deep dive into display/windows manager terminology, internals, and configuration files unless you're running a minimalist DE.
Really, common distros should have a button in the installer that says "install the software packages I'll probably need" to install all of this stuff and not rely on the user knowing what arbitrarily named packages they need. Let the purists disable that stuff if they want to, but let the normal people start out with a desktop that Just Works.
doesn't describe
> they will spend days searching the web, reading through the endless ‘blind leading the blind’ user forums
as for "instead of RTFM" you have to know where and what to read
The first party Ubuntu tutorials are especially bad... It seems like for things like SAMBA and NFS they are at least 10 years out of date. Arch Linux and RHEL docs are a lot more reliable, even if you have to figure out the the Debian/Ubuntu ways to do things when they've diverged
It's not like setting up a share is hard, I'm missing the point of why something that's already easy would need an "easy way".
Now, Samba as an AD DC, across multiple sites, integrating with Kerberos and LDAP, so that users can have a single sign on experience across platforms... That, I'd be impressed at an "easy way" guide. ;-)
I think I'm not the target audience.
The biggest "problem" is that distros do not ship Samba packages with DC support, you either have to use 3rd-party build like Tranquil's or build your own.
I guess my only point was that samba for just sharing files is already super easy, so I don't get what an "easy way" is for. :) You might be saying "but hard things are easy too", implying that you're more experienced than me at samba and/or the software itself has improved. I wouldn't be surprised if both were true.
Creating a domain on a Samba domain controller is not too difficult if you follow the documents. But choosing the right way to join a client to the domain and then using SPNs? Synchronized uids? User management? I haven’t found it to be easy at all.
That said, the performance is pretty good and it seems rather stable, I haven't had many issues to date at all. Though my use case is also decidedly simple: just a "push" setup for files/backups when I want to move things from one of my local HDDs to another one that's running on a homelab server. Some might go for a NAS setup, though the simplicity of a SSH key for SFTP is hard to beat.
No idea why Windows doesn't support something like that natively.
I think the answer is right at hand. Or maybe I'm just too cynical.
I just use sshfs and I am done with it.
I just want to easily move files around my network and samba took too many hours of my life to look at what's wrong this year with client version or spaces in shared folders. It's always something.
1. Samba share is not discovered in the network. All my problems were gone after installing wsdd2.
2. Permissions. Especially Windows clients implicitly try to login with an empty password to check if the share can accessed without one. This can lead to problems with the "map to guest" directive in the Samba configuration. Also the Windows credential storage sometimes saves passwords that did not work and implicitly tries to login.
But don't get me started on the Gnome/gvfs client implementation of Samba. I have given up on that.
- https://bugs.launchpad.net/gvfs/+bug/1828107
- https://gitlab.gnome.org/GNOME/gvfs/-/issues/307
I put together a small writeup in case someone wants to take a deep-dive: https://blog.hiebl.cc/posts/why-your-samba-config-does-not-w...
- gvfs might not support ws-discovery for smb discovery, but neither does macos. They both support dns-sd/bonjour/zeroconf for that; so getting up avahi up and running with advertising the smb service is the easiest way to handle both. Synology does this OOB, for example.
- gvfs is not an implementation of samba. It is a frontend to libsmbclient library from the samba package. Unfortunately, libsmbclient does read smb.conf and adjusts itself accordingly, without the consumers of the library having a say in it. The best way to debug gvfs problems is to start with empty smb.conf.
For years I used Avahi to run afp shares on my Linux machines for my Macs, but I don’t even bother anymore. I have ssh setup on all my computers, it’s all I really need. Sometimes I’ll mount it, but 90% of the time I just scp over the file I want.
Nobody should use NFS ever if it can be avoided. Run screaming. The entire idea of “remote file system that is transparent to applications that just write files normally” fundamentally just does not work on Linux. There is too much software that assumes the characteristics and reliability of local filesystems like ext4 and xfs and there not enough control exposed by the kernel to handle when things go wrong. It’s the wrong layer.
Remote block storage as well as application layer object storage work really really well but the filesystem APIs are a mess intertwined with so many different parts of the system and assumptions made 40 years ago.
https://randthoughts.github.io/little-rant-about-gnomes-file...
https://gist.github.com/jftuga/8046ad3119d24690f5db2eb8992df...
I use this for mapping my $HOME directory onto a Windows computer.
Brings back memories of horror and achievement from my PFY-Geeks-Days while "chanting" smb.conf files and clicking on Network Neighbourhood (hoping against all hope) ! #goodtimes :)