SMB.CONF

Section:  (5)
Updated:
Index

NAME

smb.conf - Samba×é¼þµÄÅäÖÃÎļþ

×ÜÀÀ SYNOPSIS

smb.confÊÇSamba×é¼þµÄÅäÖÃÎļþ,°üº¬Samba³ÌÐòÔËÐÐʱµÄÅäÖÃÐÅÏ¢.smb.conf±»Éè¼Æ³É¿ÉÓÉswat (8)³ÌÐòÀ´ÅäÖú͹ÜÀí.±¾Îļþ°üº¬Á˹ØÓÚsmb.confµÄÎļþ¸ñʽºÍ¿ÉÄܳöÏÖµÄÑ¡ÏîµÄÍêÕûÃèÊöÒÔ¹©²Î¿¼.

Îļþ¸ñʽ FILE FORMAT

±¾ÎļþÓÉһϵÁжκÍÑ¡Ïî¹¹³É.Ò»¸ö¶ÎÓÉÒ»¶Ô·½À¨ºÅÖеĶÎÃû¿ªÊ¼,Ö±µ½ÏÂÒ»¸ö¶ÎÃû½áÊø.°üº¬ÔÚ¶ÎÖеÄÑ¡Ïî°´ÒÔϸñʽ¶¨Ò壺

Ñ¡ÏîÃû = Ñ¡ÏîÖµ

±¾ÎļþÊÇ»ùÓÚÎı¾ÐеÄ.Õâ¾ÍÊÇ˵,ÿһ¸öÒÔ»»Ðзû½áÊøµÄÐÐÃèÊöÁËÒ»¸öÏîÄ¿(×¢ÊÍ,¶ÎÃû,»òÑ¡Ïî).

¶ÎÃûºÍÑ¡ÏîÃûÊDz»Çø·Ö´óСдµÄ.

Ö»ÓÐÑ¡ÏîÉèÖÃÖеĵÚÒ»¸öµÈºÅ²ÅÓÐÒâÒå.µÚÒ»¸öµÈºÅÇ°ºóµÄ¿Õ¸ñ»á±»ºöÂÔ.¶ÎÃûºÍÑ¡ÏîÃûµÄÇ°ºóÒÔ¼°Öмä°üº¬µÄ¿Õ¸ñÊÇÎ޹صÄ.Ñ¡ÏîֵǰºóµÄ¿Õ¸ñ»á±»ºöÂÔ.Ñ¡ÏîÖµÖаüº¬µÄ¿Õ¸ñ»áÔ­Ñù±£Áô.

ËùÓÐÒÔ';'ºÍ'#'·û¿ªÍ·µÄÐж¼»á±»ºöÂÔ,¾ÍÏóÖ»ÓпոñµÄÐÐÄÇÑù.

°´ÕÕUNIXÉϵĹßÀý,ÒÔ''·ûºÅ½áβµÄÐÐÐøÏÂÒ»ÐÐ.(Ò²¾ÍÊÇ˵£º''ÊÇÐøÐзû,Èç¹ûÒ»ÐÐд²»ÏÂ,¿ÉÒÔÔÚÐÐβÒÔ''½áÊø,ÔÚÏÂÒ»ÐмÌÐøд--Òë×¢)

µÈºÅºóÃæ¸úµÄÊÇ×Ö·û´®(ÎÞÐèÒýºÅ)»òÕßÂß¼­Öµ(¿ÉÒÔÊÇyes/no,1/0,»òÕßtrue/false À´±íʾ).Âß¼­ÖµÊDz»Çø·Ö´óСдµÄ.×Ö·û´®ÖµÔòÔ­Ñù±£ÁôÁËÊäÈëµÄ´óСд.ijЩѡÏî (ÀýÈçcreate modes)µÄÖµÊÇÊýÖµÐ͵Ä.

¶ÎÃèÊö SECTION DESCRIPTIONS

ÅäÖÃÎļþµÄÿһ¶Î([global]¶Î³ýÍâ)ÃèÊöÒ»Ïî¹²Ïí×ÊÔ´.¶ÎÃû¾ÍÊǹ²ÏíÃû,¶ÎÄÚµÄÑ¡ÏîÉèÖÃÈ·¶¨Á˸ù²Ïí×ÊÔ´µÄÊôÐÔ.

Èý¸öÌØÊâ¶Î([global],[homes],[printers])½«ÔÚºóÃæ'special sections'µ¥¶À˵Ã÷,ÒÔϵÄÄÚÈÝÊÇÆÕͨ¶ÎµÄ˵Ã÷.

Ò»¸ö¹²Ïí×ÊÔ´ÓÉÒ»¸öÎļþĿ¼ºÍÓû§¶Ô´ËĿ¼µÄ²Ù×÷ȨÏÞµÄ˵Ã÷¹¹³É.ÁíÍâ,»¹ÁÐÈëÁËһЩÓÃÓÚÄÚ²¿¹ÜÀíµÄÑ¡Ïî.

ÿһ¶Î¶¨ÒåÁËÒ»ÏîÎļþ·þÎñ(¿Í»§¶Ë¿ÉÒÔ°ÑËü¿´×÷Æä±¾»úÎļþϵͳµÄÑÓÉì)»ò´òÓ¡·þÎñ(¿Í»§¶Ë¿ÉÒÔͨ¹ýËüÀ´Ê¹Ó÷þÎñÆ÷ÌṩµÄ´òÓ¡·þÎñ).

¶Î¿ÉÒÔ¶¨Òå³Éguest·þÎñÀàÐÍ,ÔÚÕâÖÖÇé¿öÏÂ,¿Í»§ÎÞÐè¿ÚÁî¾Í¿ÉÒÔ·ÃÎʸÃ×ÊÔ´.Ò»¸öÌض¨µÄUNIXϵͳϵÄguest accountͨ³£ÓÃÀ´Ö¸¶¨ÕâÖÖÇé¿öϵĿͻ§·ÃÎÊȨÏÞ.

³ýÁËguest·þÎñÀàÐÍÒÔÍâ,ÆäËûÀàÐ͵Ķζ¨ÒåµÄ¹²Ïí×ÊÔ´¶¼ÐèÒª¿ÚÁî²ÅÄÜ·ÃÎÊ.Óû§ÃûÊÇÓÉ¿Í»§¶ËÌṩµÄ.ÓÉÓÚijЩÀϵĿͻ§¶ËÖ»Ìṩ¿ÚÁî,ûÓÐÓû§Ãû,ÄãÐèÒªÔÚ¹²Ïí¶¨ÒåÖÐʹÓÃ"user="Ñ¡ÏîÀ´Ö¸¶¨Ò»¸öÓû§Áбí,ÒÔ±ã¸ù¾ÝÕâ¸öÓû§Áбí½øÐпÚÁîÑéÖ¤.¶ÔÓÚÏóWindos95/98ºÍWindowsNTÕâÑùµÄÏÖ´ú¿Í»§¶Ë³ÌÐò,Õâ¸öÑ¡ÏîÊDz»ÐèÒªµÄ.

×¢Òâ,¶ÔÓÚ×ÊÔ´µÄ²Ù×÷ȨÏÞ»¹È¡¾öÓÚÖ÷»úϵͳ¸³ÓèÖ¸¶¨Óû§»òÀ´·ÃÕßÕË»§µÄȨÏÞ.sambaÌṩµÄ·þÎñȨÏÞ²»Äܳ¬³öÖ÷»úϵͳָ¶¨µÄȨÏÞ·¶Î§.

ÏÂÃæµÄʾ·¶¶Î¶¨ÒåÁËÒ»ÏîÎļþ·þÎñ,Óû§ÓµÓжÔ/home/barĿ¼½øÐÐд²Ù×÷µÄȨÏÞ.Õâ¸ö¹²Ïí×ÊÔ´ÊÇͨ¹ý¹²ÏíÃû"foo"À´·ÃÎʵÄ.

[foo]
        path = /home/bar
        read only = no

ÏÂÃæʾ·¶¶Î¶¨ÒåÁËÒ»Ïî´òÓ¡·þÎñ,´Ë¹²Ïí×ÊÔ´ÊÇÖ»¶ÁµÄ,µ«ÊÇ¿ÉÒÔ½øÐдòÓ¡²Ù×÷.Ò²¾ÍÊÇ˵,ΨһÔÊÐíµÄд²Ù×÷Ö»ÄÜÊÇ´ò¿ª¡¢Ð´Èë²¢¹Ø±ÕÒ»¸ö´òÓ¡¼ÙÍÑ»úÎļþ.ÆäÖеÄguest okÑ¡ÏÒåÒâζ×ÅÔÊÐíÒÔȱʡµÄguestÓû§(Ôڱ𴦶¨ÒåµÄ)ȨÏÞ½øÐзÃÎÊ.

[aprinter]
        path = /usr/spool/public
        read only = yes
        printable = yes
        guest ok = yes

ÌØÊâ¶Î SPECIAL SECTIONS

[global] È«¾ÖÑ¡Ïî¶Î

ÕâÒ»¶ÎÖж¨ÒåµÄÑ¡ÏîÊÇ·þÎñÆ÷µÄÈ«¾ÖÐÔÉèÖÃ,Èç¹ûÔÚÆäËû¶ÎÖÐûÓÐÔÙ¶ÔÕâЩѡÏî½øÐÐÖØÐÂÉèÖõĻ°»¹¿ÉÒÔ×÷ΪËüÃǵÄȱʡѡÏî.¸ü¶àµÄ˵Ã÷Çë²ÎÔÄ'PARAMETERS'²¿·ÖµÄÄÚÈÝ.

[homes] ¸öÈËĿ¼¶Î

Èç¹ûÅäÖÃÎļþÖаüº¬ÃûΪ'homes'µÄ¶Î,¾Í¿ÉÒÔ½¨Á¢¿Í»§µ½×Ô¼ºÔÚ·þÎñÆ÷ÉϵĸöÈËĿ¼µÄÁ¬½Ó.

µ±·þÎñÆ÷ÊÕµ½Á¬½ÓÇëÇóʱ,Ê×ÏÈÔÚÒѶ¨ÒåµÄ¶ÎÖÐËÑË÷,Èç¹û¶ÎÃûÓë±»ÇëÇóµÄ¹²Ïí×ÊÔ´ÃûÒ»ÖÂ,Ôò¸Ã¶ÎµÄÄÚÈݾͱ»²ÉÓÃ.Èç¹ûûÓÐÕÒµ½Æ¥ÅäµÄ¶Î,Ôò±»ÇëÇóµÄ×ÊÔ´¾Í±»µ±×÷ÊÇÒ»¸öÓû§Ãû,ͬʱ·þÎñÆ÷²é¿´±¾µØµÄ¿ÚÁîÎļþ.Èç¹û¸ÃÓû§ÃûÔÚ¿ÚÁîÎļþÖдæÔÚÇÒÓû§¸ø³öÁËÕýÈ·µÄ¿ÚÁî,·þÎñÆ÷¾Í»á¸´ÖÆ[homes]¶ÎµÄÄÚÈÝÀ´Éú³ÉÒ»¸ö¹²Ïí×ÊÔ´(¹©¸ÃÓû§·ÃÎÊ).

¶Ôн¨¹²Ïí»á×öÒÔÏÂÐ޸ģº

¹²ÏíÃû´Ó'homes'¸ÄΪ²éµ½µÄÓû§Ãû.
Èç¹ûûÓÐÖ¸¶¨·ÃÎÊ·¾¶,ÔòÉèÖÃΪ¸ÃÓû§µÄ¸öÈËĿ¼.

Èç¹ûÒªÔÚ[homes]¶ÎÖж¨Òå·ÃÎÊ·¾¶path=,ºê%SÒ²Ðí¶ÔÄãºÜÓÐÓÃ.¾ÙÀýÈçÏ£º

path = /data/pchome/%S

Èç¹ûÄãµÄPC ÓÐÓëUNIX·þÎñÆ÷ÉϸöÈËĿ¼²»Í¬µÄĿ¼,ÏóÉÏÃæÕâÑùµÄÉèÖûáºÜÓÐÓõÄ.

ÕâÊÇΪ´óÁ¿Óû§Ìṩ¶ÔËûÃǸöÈËĿ¼µÄ·ÃÎʵÄÒ»ÖÖ¿ìËÙ¼ò½àµÄ°ì·¨.

Èç¹û±»ÇëÇó·ÃÎʵĹ²Ïí×ÊÔ´Ãû¾ÍÊÇ'homes',ÄÇô,³ýÁ˹²ÏíÃû²»±»¸Ä±äΪ·¢³öÇëÇóµÄÓû§ÃûÍâ,ÆäËû´¦Àí¹ý³ÌºÍÇ°ÃæÌáµ½µÄ¹ý³ÌÊÇÀàËƵÄ.ÕâÖÖ·½Ê½ÊʺÏÓÚ²»Í¬Óû§¹²Ïíһ̨Öն˵ÄÇé¿ö.

ÔÚ[homes]¶ÎÖпÉÒÔ¶¨ÒåËùÓÐÆÕͨ¶ÎÖпÉÒÔʹÓõÄÑ¡Ïî,¿ÉÊÇÓÐЩѡÏî¸üÓÐÒâÒå.ÏÂÃæÊÇÒ»¸öʵÓõġ¢µäÐ͵Ä[homes]¶ÎµÄÀý×Ó£º

[homes]
        read only = no

×¢Òâ,ºÜÖØÒªµÄÒ»µãÊÇ£ºÈç¹ûÔÚ[homes]¶ÎÖж¨ÒåÁËÔÊÐíÒÔguestÕË»§·ÃÎʵĻ°,ÈκÎÈ˶¼¿ÉÒÔÎÞÐë¿ÚÁî¶ø·ÃÎÊËùÓÐÕË»§µÄËÞÖ÷Ŀ¼.Ò²ÐíÔÚijЩÌØÊâÇé¿öÏÂ,ÕâÕýÊÇÏëÒªµÄ½á¹û,ÔÚÕâÖÖÇé¿öÏÂ,Äã×îºÃͬʱ°Ñ[homes]¶ÎÉèÖóÉÖ»¶Á.

×¢Òâ,×Ô¶¯µÄËÞÖ÷Ŀ¼¹²Ïí×ÊÔ´µÄ¿Éä¯ÀÀ±êÖ¾ÊÇ´Ó[global]¶Î¼Ì³ÐÀ´µÄ,¶ø²»ÊÇ[homes]¶Î.ÕâÑù,µ±ÔÚ[homes]¶ÎÖÐÉèÖÃbrowseable=noʱ,Óû§¾Í¿´²»µ½µ¥¶ÀµÄ'homes'¹²Ïí,µ«¿ÉÒÔ¿´µ½×Ô¶¯µÄËÞÖ÷Ŀ¼.

[printers] ´òÓ¡»ú¹²ÏíÉèÖöÎ

ÕâÒ»¶ÎºÜÏó[homes]¶Î,²»¹ýÊÇÓÃÓÚÉèÖù²Ïí´òÓ¡»úµÄ.

Èç¹ûÔÚ±¾ÅäÖÃÎļþÖдæÔÚ[printers]¶Î,Óû§¾Í¿ÉÒÔÁ¬½Óµ½ÔÚÖ÷»úÉϵÄprintcapÎļþ ÖÐÖ¸¶¨µÄÈÎÒ»´òÓ¡»ú.

µ±·þÎñÆ÷ÊÕµ½Á¬½ÓÇëÇóʱ,Ê×ÏÈÔÚÒѶ¨ÒåµÄ¶ÎÖÐËÑË÷,Èç¹ûÓжÎÃûÓë±»ÇëÇóµÄ¹²Ïí×ÊÔ´ÃûÒ»ÖÂ,Ôò¸Ã¶ÎµÄÄÚÈݾͱ»²ÉÓÃ.Èç¹ûûÓÐÕÒµ½Æ¥ÅäµÄ¶Î,ÇÒÔÚÅäÖÃÎļþÖдæÔÚ[homes]¶Î,Ôò°´ÕÕÇ°ÃæËù˵µÄ·½Ê½´¦Àí.·ñÔò,±»ÇëÇóµÄ×ÊÔ´¾Í±»µ±×÷ÊÇÒ»¸ö´òÓ¡»úÃû,·þÎñÆ÷ÔÚÊʵ±µÄprintcapÎļþÖвéÕÒ,¼ìÑé±»ÇëÇóµÄ¹²Ïí×ÊÔ´ÃûÊÇ·ñÊÇÓÐЧµÄ´òÓ¡»ú¹²ÏíÃû.Èç¹û¹²ÏíÃûÆ¥Åä,·þÎñÆ÷¾Í»á¸´ÖÆ[printers]¶ÎµÄÄÚÈÝÀ´Éú³ÉÒ»¸ö¹²Ïí´òÓ¡·þÎñ.

¶Ôн¨¹²ÏíµÄÐ޸ģº

¹²ÏíÃû±»ÉèÖÃΪ²éÕÒµ½µÄ´òÓ¡»úÃû.

Èç¹ûδ¸ø³ö´òÓ¡»úÃû,Ôò°Ñ´òÓ¡»úÃûÉèΪǰÃæ²éÕÒµ½µÄ´òÓ¡»úÃû.

Èç¹û¸Ã¹²Ïí×ÊÔ´²»ÔÊÐíÒÔguestÉí·Ý½øÐзÃÎÊ,ÇÒûÓиø³öÓû§Ãû,ÄÇôÓû§Ãû¾Í±»ÉèΪǰÃæ²éÕÒµ½µÄ´òÓ¡»úÃû.

×¢Òâ,[printers]¶Î±ØÐëÉèÖÃΪ¿É´òÓ¡,Èç¹ûÄã²»ÕâÑùÉèÖÃ,·þÎñÆ÷»á¾Ü¾ø×°ÔØÅäÖÃÎļþ.

Ö¸¶¨µÄµäÐÍ·¾¶Ó¦¸ÃÉèΪһ¸ö¹«ÓõĿÉд¼ÙÍÑ»úĿ¼(spooling)²¢ÇÒÉèÖÃsticky±êÖ¾.Ò»¸öµäÐ͵Ä[printers]¶ÎÈçÏÂËùʾ£º

[printers]
        path = /usr/spool/public
        guest ok = yes
        printable = yes 

ÉĮ̈´òÓ¡»úÔÚprintcapÎļþÖÐÁгöµÄËùÓбðÃû¶¼ÊÇ·þÎñÆ÷Ïà¹ØµÄÓÐЧ´òÓ¡»úÃû.Èç¹ûÄãϵͳµÄ´òÓ¡×ÓϵͳµÄ¹¤×÷·½Ê½²»ÊÇÕâÑù,Äã¾Í±ØÐëÉèÖÃÒ»¸öαprintcapÎļþ,ÆäÖаüº¬Ò»Ðлò¶àÐÐÈçϸñʽµÄÉèÖãº

±ðÃû1|±ðÃû2|±ðÃû3|±ðÃû4... 

ÿ¸ö±ðÃû±ØÐëÊÇÄãµÄ´òÓ¡×Óϵͳ¿ÉÒÔ½ÓÊܵĴòÓ¡»úÃû.ÔÚ[global]¶ÎÖÐÖ¸¶¨Õâ¸öÐÂÎļþ×÷ΪÄãµÄprintcapÎļþ.Õâ¸öαprintcapÎļþ¿ÉÒÔ°üº¬ÈκÎÄãÒªµÄ±ðÃû,¶ø·þÎñÆ÷ֻʶ±ðÔÚ´ËÎļþÖÐÁгöµÄÃû×Ö.Õâ¸ö¼¼Êõ¿ÉÒԺܷ½±ãµÄÓÃÓÚÏÞÖƶԱ¾µØ´òÓ¡»ú×Ó¼¯µÄ·ÃÎÊ.

˳±ãÌáÒ»ÏÂ,printcapÎļþÖеıðÃûÓÃÿ¸ö¼Ç¼µÚÒ»ÏîµÄÈκβ¿·ÖÀ´¶¨Òå.¼Ç¼ÓÉ»»ÐнøÐзָô.Èç¹ûÒ»Ìõ¼Ç¼ÖÐÓжà¸ö²¿·Ö,ÖмäÓÃ"|"·ûºÅ·Ö¸ô.

Note

×¢Òâ,ÔÚSYSVϵͳÖÐ,ÓÃlpstat¿ÉÒÔÈ·¶¨ÏµÍ³Öа²×°ÁËʲôÑùµÄ´òÓ¡»ú.Äã¿ÉÒÔÉèÖÃ"printcap name = lpstat"À´×Ô¶¯»ñµÃ´òÓ¡»úÁбí.ÏêÇé²Î¼û"printcap name"Ñ¡Ïî.

Ñ¡Ïî PARAMETERS

Ñ¡ÏÒåÁËÿ¸ö¶ÎµÄÊôÐÔ.

ÓÐЩѡÏîÊÇÔÚ[global]¶ÎÖÐÉ趨µÄ(±ÈÈçÓйذ²È«ÌØÐÔµÄÉèÖÃ),ÓÐЩ¿ÉÒÔÓÃÔÚÈκζÎÖеÄ(±ÈÈ罨Á¢·½Ê½ ),ʣϵľÍÖ»ÄÜÓÃÔÚÆÕͨµÄ¶ÎÖÐÁË.ÔÚÒÔϵÄÃèÊöÖÐ,[homes]ºÍ[printers]¶Î±»¿´×÷ÊÇÆÕͨ¶Î.±ê¼Ç(G)±íʾ´ËÑ¡ÏîÖ»ÄÜÔÚ[global]¶ÎÖÐʹÓÃ,±ê¼Ç(S)±íʾ´ËÑ¡Ïî¿ÉÒÔÔÚ·þÎñ¶¨Òå¶ÎÖÐʹÓÃ.×¢Òâ,ÓÐ(S)±ê¼ÇµÄÑ¡ÏîÒ²¿ÉÒÔÓÃÔÚ[global]¶ÎÖÐ,ÔÚÕâÖÖÇé¿öÏÂ,Õâ¸öÑ¡ÏîÉèÖñ»µ±×÷ËùÓÐÆäËû¶ÎµÄȱʡÉèÖÃ.

Ñ¡ÏîµÄÏêϸ˵Ã÷ÊÇ°´ÕÕ×Öĸ˳ÐòÅÅÁеÄ,ÕâÑùÒ²Ðí²»ÊÇ×îºÃµÄ·ÖÀ෽ʽ,µ«ÖÁÉÙ±£Ö¤Äã¿ÉÒÔÕҵõ½ËûÃÇ.Èç¹ûÓжà¸öͬÒå´Ê,ÄÇôÎÒÃÇÖ»¶ÔÊ×Ñ¡µÄÄǸö×÷Ïêϸ˵Ã÷,ÆäËûµÄͬÒå´Ê¶¼Ö»Ö¸Ã÷²ÎÔÄÄǸöÊ×Ñ¡µÄÑ¡ÏîÃû.

±äÁ¿Ìæ»» VARIABLE SUBSTITUTIONS

ÔÚÅäÖÃÎļþÖпÉÒÔÓúܶà×Ö·û´®½øÐÐÌæ»».ÀýÈç,µ±Óû§ÒÔjohnµÄÃû³Æ½¨Á¢Á¬½Óºó,Ñ¡Ïî"path = /tmp/%u"¾Í±»½âÊͳÉ"path = /tmp/john".

ÕâЩÖû»»áÔÚºóÃæµÄÃèÊöÖÐ˵Ã÷,ÕâÀï˵Ã÷һЩ¿ÉÒÔÓÃÔÚÈκεط½µÄͨÓÃÖû».ËüÃÇÊÇ£º

%U
¶Ô»°Óû§Ãû(¿Í»§¶ËÏëÒªµÄÓû§Ãû²»Ò»¶¨ÓëÈ¡µÃµÄÒ»ÖÂ.)

%G
%UµÄÓû§×éÃû

%h
ÔËÐÐSambaµÄÖ÷»úµÄinternetÖ÷»úÃû

%m
¿Í»§»úµÄNetBIOSÃû(·Ç³£ÓÐÓÃ)

%L
·þÎñÆ÷µÄNetBIOSÃû.ÕâʹµÃÄã¿ÉÒÔ¸ù¾Ýµ÷ÓõĿͻ§¶ËÀ´¸Ä±äÄãµÄÅäÖÃ,ÕâÑùÄãµÄ·þÎñÆ÷¾Í¿ÉÒÔÓµÓÐ"Ë«ÖظöÐÔ".

Note that this parameter is not available when Samba listens on port 445, as clients no longer send this information

%M
¿Í»§¶ËµÄinternetÖ÷»úÃû

%R
ЭÒéЭÉ̺óÑ¡ÔñµÄЭÒé,Ëü¿ÉÒÔÊÇCORE,COREPLUS,LANMAN1,LANMAN2»òNT1ÖеÄÒ»ÖÖ.

%d
µ±Ç°samba·þÎñÆ÷µÄ½ø³ÌºÅ.

%a
Ô¶³ÌÖ÷»úµÄ½á¹¹.ÏÖÔÚÖ»ÄÜÈϳöÀ´Ä³Ð©ÀàÐÍ,²¢ÇÒ²»ÊÇ100%¿É¿¿.Ä¿Ç°Ö§³ÖµÄÓÐSamba¡¢WfWg¡¢WinNTºÍWin95.ÈκÎÆäËûµÄ¶¼±»ÈÏ×÷"UNKNOWN".Èç¹û³öÏÖ´íÎó¾Í¸øsamba-bugs@samba.org·¢Ò»¸ö3¼¶µÄÈÕÖ¾ÒÔ±ãÐÞ¸´Õâ¸öbug.

%I
¿Í»§»úµÄIPµØÖ·.

%T
µ±Ç°µÄÈÕÆÚºÍʱ¼ä.

%D
Name of the domain or workgroup of the current user.

%$(envvar)
The value of the environment variable envar.

The following substitutes apply only to some configuration options(only those that are used when a connection has been established):

%S
µ±Ç°·þÎñÃû

%P
µ±Ç°·þÎñµÄ¸ùĿ¼

%u
µ±Ç°·þÎñµÄÓû§Ãû

%g
%uµÄÓû§×éÃû

%H
%uËù±íʾµÄÓû§µÄËÞÖ÷Ŀ¼

%N
tNIS·þÎñÆ÷µÄÃû×Ö.Ëü´Óauto.map»ñµÃ.Èç¹ûûÓÐÓÃ--with-auto-mountÑ¡Ïî±àÒësamba,ÄÇôËüµÄÖµºÍ%LÏàͬ.

%p
Óû§ËÞÖ÷Ŀ¼µÄ·¾¶.ËüÓÉNISµÄauot.mapµÃµ½.NISµÄauot.mapÈë¿ÚÏî±»·ÖΪ"%N:%p".

Áé»îÔËÓÃÕâЩÖû»ºÍÆäËûµÄsmb.confÑ¡Ïî¿ÉÒÔ×ö³ö·Ç³£Óд´ÔìÐÔµÄÊÂÇéÀ´.

NAME

SambaÖ§³Ö"Ãû³ÆÐÞÕý",ÕâÑùdosºÍwindows¿Í»§¶Ë¾Í¿ÉÒÔʹÓÃÓë8.3¸ñʽ²»Ò»ÖµÄÎļþ.Ò²¿ÉÒÔÓÃÀ´µ÷Õû8.3¸ñʽÎļþÃûµÄ´óСд.

ÓÐһЩѡÏî¿ÉÒÔ¿ØÖÆÃû³ÆÐÞÕýµÄÖ´ÐÐ,ÏÂÃ漯ÖÐÁгöÀ´.¶ÔÓÚȱʡÇé¿öÇë¿´testparm³ÌÐòµÄÊä³ö½á¹û.

ËùÓÐÕâЩѡÏ¿ÉÒÔÕë¶Ôÿ¸ö·þÎñÏîµ¥¶ÀÉèÖÃ(µ±È»Ò²¿ÉÒÔÉèΪȫ¾Ö±äÁ¿).

ÕâЩѡÏîÊÇ:

mangle case = yes/no
×÷ÓÃÊÇ¿ØÖÆÊÇ·ñ¶Ô²»·ûºÏȱʡд·¨µÄÃû³Æ½øÐÐÐÞÕý.ÀýÈç,Èç¹ûÉèΪyes,Ïó"Mail"ÕâÑùµÄÎļþÃû¾Í»á±»ÐÞÕý.ȱʡÉèÖÃÊÇno.

case sensitive = yes/no
¿ØÖÆÎļþÃûÊÇ·ñÇø·Ö´óСд.Èç¹û²»Çø·ÖµÄ»°,Samba¾Í±ØÐëÔÚ´«µÝÃû³Æʱ²éÕÒ²¢Æ¥ÅäÎļþÃû.ȱʡÉèÖÃÊÇno.

default case = upper/lower
¿ØÖÆÐÂÎļþÃû´óСдȱʡֵ.ȱʡÉèÖÃÊÇСд.

preserve case = yes/no
¿ØÖƽ¨ÐÂÎļþʱÊÇ·ñÓÿͻ§ËùÌṩµÄ´óСдÐÎʽ,»òÇ¿ÖÆÓÃȱʡÐÎʽ.ȱʡΪyes.

short preserve case = yes/no
¿ØÖÆн¨8.3¸ñʽµÄÎļþÃûʱÊÇÈ«²¿Óôóд¼°ºÏÊʳ¤¶È,»¹ÊÇÇ¿ÖÆÓÃȱʡÇé¿ö.Ëü¿ÉÒÔºÍÉÏÃæµÄ"preserve case = yes"ÁªÓÃÒÔÔÊÐí³¤ÎļþÃû±£³Ö´óСд²»±ä,¶ø¶ÌÎļþÃûΪСд.±¾ÏîµÄȱʡÉèÖÃÊÇyes.

ȱʡÇé¿öÏÂ,Samba3.0ÓëWindows NTÏàͬ,¾ÍÊDz»Çø·Ö´óС䵫±£³Ö´óСдÐÎʽ.

Óû§Ãû/¿ÚÁî¼ìÑéÖеÄ×¢ÒâÊÂÏî NOTE ABOUT USERNAME/PASSWORD VALIDATION

Óû§ÓжàÖÖÁ¬½Óµ½·þÎñÏîµÄ·½Ê½.·þÎñÆ÷°´ÕÕÏÂÃæµÄ²½ÖèÀ´È·¶¨ÊÇ·ñÔÊÐí¿Í»§¶ÔÖ¸¶¨·þÎñµÄÁ¬½Ó.Èç¹ûÏÂÃæ²½ÖèÈ«²¿Ê§°Ü,Ôò¾Ü¾øÓû§µÄÁ¬½ÓÇëÇó.Èç¹ûijһ²½Í¨¹ý,ÓàϵļìÑé¾Í²»ÔÙ½øÐÐ.

Èç¹û±»ÇëÇóµÄ·þÎñÏîÉèÖÃΪguest only = yes£¬²¢ÇÒ£¬·þÎñÔËÐÐÔÚ¹²Ïí¼¶°²È«Ä£Ê½(security = share) ,ÔòÌø¹ý1--5²½¼ì²é.

µÚÒ»²½£º
Èç¹û¿Í»§¶ËÌṩһ¶ÔÓû§ÃûºÍ¿ÚÁî,ÇÒÕâ¶ÔÓû§ÃûºÍ¿ÚÁî¾­unixϵͳ¿ÚÁî³ÌÐò¼ìÑéΪÓÐЧ,ÄÇô¾ÍÒÔ¸ÃÓû§Ãû½¨Á¢Á¬½Ó.×¢Òâ,Õâ°üÀ¨ÓÃ\\server\service%username·½Ê½´«µÝÓû§Ãû.

µÚ¶þ²½£º
Èç¹û¿Í»§¶ËÊÂÏÈÔÚϵͳÉÏ×¢²áÁËÒ»¸öÓû§Ãû,²¢ÇÒÌṩÁËÕýÈ·µÄ¿ÚÁî,¾ÍÔÊÐí½¨Á¢Á¬½Ó.

µÚÈý²½£º
¸ù¾ÝÌṩµÄ¿ÚÁî¼ì²é¿Í»§¶ËµÄnetbiosÃû¼°ÒÔÇ°ÓùýµÄÓû§Ãû,ÈçÆ¥Åä,¾ÍÔÊÐíÒÔ¸ÃÓû§Ãû½¨Á¢Á¬½Ó.

µÚËIJ½£º
Èç¹û¿Í»§¶ËÒÔÇ°ÓкϷ¨µÄÓû§ÃûºÍ¿ÚÁî,²¢»ñµÃÁËÓÐЧµÄÁîÅÆ,¾ÍÔÊÐíÒÔ¸ÃÓû§Ãû½¨Á¢Á¬½Ó.

µÚÎå²½£º
Èç¹ûÔÚsmb.confÀïÉèÖÃÁË"user = "×Ö¶Î,ÇÒ¿Í»§¶ËÌṩÁËÒ»¸ö¿ÚÁî,¿ÚÁî¾­UNIXϵͳ¼ìÑé,²¢Óë"user="×Ö¶ÎÀïijһ¸öÓû§Æ¥Åä,ÄÇô¾ÍÔÊÐíÒÔ"user="ÀïÆ¥Åäµ½µÄÓû§Ãû½¨Á¢Á¬½Ó.Èç¹û"user="×Ö¶ÎÊÇÒÔ@¿ªÊ¼,ÄÇô¸ÃÃû×Ö»áÕ¹¿ªÎªÍ¬Ãû×éÀïµÄÓû§ÃûÁбí .

µÚÁù²½£º
Èç¹ûÕâÊÇÒ»¸öÌṩ¸øguestÓõķþÎñÏî,ÄÇôÁ¬½ÓÒÔ"guest account ="Àï¸ø³öµÄÓû§Ãû½¨Á¢,¶ø²»¿¼ÂÇÌṩµÄ¿ÚÁî.

È«¾ÖÑ¡ÏîÍêÕûÁбí COMPLETE LIST OF GLOBAL PARAMETERS

ÒÔÏÂÁгöÁËËùÓеÄÈ«¾ÖÑ¡Ïî,¸÷Ñ¡ÏîµÄÏêϸ˵Ã÷Çë²Î¿´ºóÃæµÄÏàÓ¦¶ÎÂä.×¢Òâ,ÓÐЩѡÏîµÄÒâÒåÊÇÏàͬµÄ.

*
abort shutdown script

*
add group script

*
add machine script

*
addprinter command

*
add share command

*
add user script

*
add user to group script

*
afs username map

*
algorithmic rid base

*
allow trusted domains

*
announce as

*
announce version

*
auth methods

*
auto services

*
bind interfaces only

*
browse list

*
change notify timeout

*
change share command

*
client lanman auth

*
client ntlmv2 auth

*
client plaintext auth

*
client schannel

*
client signing

*
client use spnego

*
config file

*
deadtime

*
debug hires timestamp

*
debuglevel

*
debug pid

*
debug timestamp

*
debug uid

*
default

*
default service

*
delete group script

*
deleteprinter command

*
delete share command

*
delete user from group script

*
delete user script

*
dfree command

*
disable netbios

*
disable spoolss

*
display charset

*
dns proxy

*
domain logons

*
domain master

*
dos charset

*
enable rid algorithm

*
encrypt passwords

*
enhanced browsing

*
enumports command

*
get quota command

*
getwd cache

*
guest account

*
hide local users

*
homedir map

*
host msdfs

*
hostname lookups

*
hosts equiv

*
idmap backend

*
idmap gid

*
idmap uid

*
include

*
interfaces

*
keepalive

*
kernel change notify

*
kernel oplocks

*
lanman auth

*
large readwrite

*
ldap admin dn

*
ldap delete dn

*
ldap filter

*
ldap group suffix

*
ldap idmap suffix

*
ldap machine suffix

*
ldap passwd sync

*
ldap port

*
ldap server

*
ldap ssl

*
ldap suffix

*
ldap user suffix

*
lm announce

*
lm interval

*
load printers

*
local master

*
lock dir

*
lock directory

*
lock spin count

*
lock spin time

*
log file

*
log level

*
logon drive

*
logon home

*
logon path

*
logon script

*
lpq cache time

*
machine password timeout

*
mangled stack

*
mangle prefix

*
mangling method

*
map to guest

*
max disk size

*
max log size

*
max mux

*
max open files

*
max protocol

*
max smbd processes

*
max ttl

*
max wins ttl

*
max xmit

*
message command

*
min passwd length

*
min password length

*
min protocol

*
min wins ttl

*
name cache timeout

*
name resolve order

*
netbios aliases

*
netbios name

*
netbios scope

*
nis homedir

*
ntlm auth

*
nt pipe support

*
nt status support

*
null passwords

*
obey pam restrictions

*
oplock break wait time

*
os2 driver map

*
os level

*
pam password change

*
panic action

*
paranoid server security

*
passdb backend

*
passwd chat

*
passwd chat debug

*
passwd program

*
password level

*
password server

*
pid directory

*
prefered master

*
preferred master

*
preload

*
preload modules

*
printcap

*
private dir

*
protocol

*
read bmpx

*
read raw

*
read size

*
realm

*
remote announce

*
remote browse sync

*
restrict anonymous

*
root

*
root dir

*
root directory

*
security

*
server schannel

*
server signing

*
server string

*
set primary group script

*
set quota command

*
show add printer wizard

*
shutdown script

*
smb passwd file

*
smb ports

*
socket address

*
socket options

*
source environment

*
stat cache

*
syslog

*
syslog only

*
template homedir

*
template primary group

*
template shell

*
time offset

*
time server

*
timestamp logs

*
unicode

*
unix charset

*
unix extensions

*
unix password sync

*
update encrypted

*
use mmap

*
username level

*
username map

*
use spnego

*
utmp

*
utmp directory

*
winbind cache time

*
winbind enable local accounts

*
winbind enum groups

*
winbind enum users

*
winbind gid

*
winbind separator

*
winbind trusted domains only

*
winbind uid

*
winbind use default domain

*
wins hook

*
wins partners

*
wins proxy

*
wins server

*
wins support

*
workgroup

*
write raw

*
wtmp directory

·þÎñÑ¡ÏîÍêÕûÁбí COMPLETE LIST OF SERVICE PARAMETERS

ÒÔÏÂÁгöÁËËùÓйØÓÚ·þÎñÏîµÄÑ¡Ïî,¸÷Ñ¡ÏîµÄÏêϸ˵Ã÷Çë²Î¼ûºóÃæµÄÏàÓ¦¶ÎÂä.×¢Òâ,ÓÐЩѡÏîµÄÒâÒåÊÇÏàͬµÄ.

*
acl compatibility

*
admin users

*
afs share

*
allow hosts

*
available

*
blocking locks

*
block size

*
browsable

*
browseable

*
case sensitive

*
casesignames

*
comment

*
copy

*
create mask

*
create mode

*
csc policy

*
default case

*
default devmode

*
delete readonly

*
delete veto files

*
deny hosts

*
directory

*
directory mask

*
directory mode

*
directory security mask

*
dont descend

*
dos filemode

*
dos filetime resolution

*
dos filetimes

*
exec

*
fake directory create times

*
fake oplocks

*
follow symlinks

*
force create mode

*
force directory mode

*
force directory security mode

*
force group

*
force security mode

*
force user

*
fstype

*
group

*
guest account

*
guest ok

*
guest only

*
hide dot files

*
hide files

*
hide special files

*
hide unreadable

*
hide unwriteable files

*
hosts allow

*
hosts deny

*
inherit acls

*
inherit permissions

*
invalid users

*
level2 oplocks

*
locking

*
lppause command

*
lpq command

*
lpresume command

*
lprm command

*
magic output

*
magic script

*
mangle case

*
mangled map

*
mangled names

*
mangling char

*
map acl inherit

*
map archive

*
map hidden

*
map system

*
max connections

*
max print jobs

*
max reported print jobs

*
min print space

*
msdfs proxy

*
msdfs root

*
nt acl support

*
only guest

*
only user

*
oplock contention limit

*
oplocks

*
path

*
posix locking

*
postexec

*
preexec

*
preexec close

*
preserve case

*
printable

*
printcap name

*
print command

*
printer

*
printer admin

*
printer name

*
printing

*
print ok

*
profile acls

*
public

*
queuepause command

*
queueresume command

*
read list

*
read only

*
root postexec

*
root preexec

*
root preexec close

*
security mask

*
set directory

*
share modes

*
short preserve case

*
strict allocate

*
strict locking

*
strict sync

*
sync always

*
use client driver

*
user

*
username

*
users

*
use sendfile

*
-valid

*
valid users

*
veto files

*
veto oplock files

*
vfs object

*
vfs objects

*
volume

*
wide links

*
writable

*
writeable

*
write cache size

*
write list

*
write ok

ÿһ¸öÑ¡ÏîµÄÏêϸ½âÊÍ EXPLANATION OF EACH PARAMETER

abort shutdown script (G)
This parameter only exists in the HEAD cvs branch This a full path name to a script called by smbd(8) that should stop a shutdown procedure issued by the shutdown script.

This command will be run as user.

ȱʡÉèÖÃ: None.

ʾÀý: abort shutdown script = /sbin/shutdown -c

acl compatibility (S)
This parameter specifies what OS ACL semantics should be compatible with. Possible values are winnt for Windows NT 4, win2k for Windows 2000 and above and auto. If you specify auto, the value for this parameter will be based upon the version of the client. There should be no reason to change this parameter from the default.

ȱʡÉèÖÃ: acl compatibility = Auto

ʾÀý: acl compatibility = win2k

add group script (G)
This is the full pathname to a script that will be run AS ROOT by smbd(8) when a new group is requested. It will expand any %g to the group name passed. This script is only useful for installations using the Windows NT domain administration tools. The script is free to create a group with an arbitrary name to circumvent unix group name restrictions. In that case the script must print the numeric gid of the created group on stdout.

add machine script (G)
This is the full pathname to a script that will be run by smbd(8) when a machine is added to it's domain using the administrator username and password method.

This option is only required when using sam back-ends tied to the Unix uid method of RID calculation such as smbpasswd. This option is only available in Samba 3.0.

ȱʡÉèÖÃ: add machine script = <¿Õ×Ö·û´®>

ʾÀý: add machine script = /usr/sbin/adduser -n -g machines -c Machine -d /dev/null -s /bin/false %u

addprinter command (G)
With the introduction of MS-RPC based printing support for Windows NT/2000 clients in Samba 2.2, The MS Add Printer Wizard (APW) icon is now also available in the "Printers..." folder displayed a share listing. The APW allows for printers to be add remotely to a Samba or Windows NT/2000 print server.

For a Samba host this means that the printer must be physically added to the underlying printing system. The add printer command defines a script to be run which will perform the necessary operations for adding the printer to the print system and to add the appropriate service definition to the smb.conf file in order that it can be shared by smbd(8).

The addprinter command is automatically invoked with the following parameter (in order):

printer name

share name

port name

driver name

location

Windows 9x driver location

All parameters are filled in from the PRINTER_INFO_2 structure sent by the Windows NT/2000 client with one exception. The "Windows 9x driver location" parameter is included for backwards compatibility only. The remaining fields in the structure are generated from answers to the APW questions.

Once the addprinter command has been executed, smbd will reparse the smb.conf to determine if the share defined by the APW exists. If the sharename is still invalid, then smbd will return an ACCESS_DENIED error to the client.

The "add printer command" program can output a single line of text, which Samba will set as the port the new printer is connected to. If this line isn't output, Samba won't reload its printer shares.

²Î¼û deleteprinter command, printing, show add printer wizard

ȱʡÉèÖÃ: none

ʾÀý: addprinter command = /usr/bin/addprinter

add share command (G)
Samba 2.2.0 introduced the ability to dynamically add and delete shares via the Windows NT 4.0 Server Manager. The add share command is used to define an external program or script which will add a new service definition to smb.conf. In order to successfully execute the add share command, smbd requires that the administrator be connected using a root account (i.e. uid == 0).

When executed, smbd will automatically invoke the add share command with four parameters.

configFile - the location of the global smb.conf file.

shareName - the name of the new share.

pathName - path to an **existing** directory on disk.

comment - comment string to associate with the new share.

This parameter is only used for add file shares. To add printer shares, see the addprinter command.

²Î¼û change share command, delete share command.

ȱʡÉèÖÃ: none

ʾÀý: add share command = /usr/local/bin/addshare

add user script (G)
Õâ¸öÑ¡ÏîÖ¸³öÒ»¸ö½Å±¾µÄÍêÕûÎļþ·¾¶,Õâ¸ö½Å±¾½«ÔÚÌض¨»·¾³ÏÂ(ÏÂÃæÓÐÏêϸ½âÊÍ)ÓÉsmbd (8)ÒÔrootÉí·ÝÖ´ÐÐ.

ͨ³£,samba·þÎñÆ÷ÐèҪΪËùÓзÃÎÊ·þÎñÆ÷ÉÏÎļþµÄÓû§½¨Á¢UNIXÓû§Õ˺Å.µ«ÊÇÔÚʹÓÃWindows NTÕ˺ÅÊý¾Ý¿â×÷ΪÖ÷Óû§Êý¾Ý¿âµÄÕ¾µã,½¨Á¢ÕâЩÓû§²¢ÔÚÓëNTµÄÖ÷Óò¿ØÖÆÆ÷±£³ÖÓû§Áбíͬ²½ÊÇÒ»¼þºÜÂé·³µÄÊÂÇé.Õâ¸öÑ¡Ïîʹsmbd¿ÉÒÔÔÚÓû§·ÃÎÊʱ¸ù¾ÝÐèÒª×Ô¶¯Éú³ÉUNIXÓû§Õ˺Å.

ΪÁËʹÓÃÕâ¸öÑ¡Ïî,smbd±ØÐë±»ÉèÖóÉsecurity=server»òÕßsecurity=domain,²¢ÇÒadd user script±ØÐëÉèΪÓÃ%u²ÎÊýÀ´½¨Á¢unixÕʺŵĽű¾ÎļþµÄȫ·¾¶,%uÀ©Õ¹³É½¨Á¢µÄunixÕʺÅÃû.

µ±windowsÓû§³¢ÊÔ·ÃÎÊsamba·þÎñÆ÷ʱ,Ôڵǽʱ(½¨Á¢SMBЭÒé»á»°),smbdÓë¿ÚÁî·þÎñÆ÷ÁªÏµ,²¢³¢ÊÔÑéÖ¤Óû§ÃûºÍ¿ÚÁî.Èç¹û³É¹¦,smbd¾Í»á¸ù¾ÝunixµÄ¿ÚÁîÎļþÊÔ׎«Õâ¸öwindowsÓû§Ó³Éä³ÉÒ»¸öunixÓû§.Èç¹û²éÕÒʧ°Ü,µ«ÉèÖÃÁËadd user script ,smbd¾Í»áÒÔrootµÄÉí·Ýµ÷ÓÃÕâ¸ö½Å±¾,½«%uÀ©Õ¹³É¸ÃÒª½¨Á¢µÄÓû§Õ˺Å.

Èç¹ûÕâ¸ö½Å±¾Ö´Ðгɹ¦,smbd¾ÍÈÏΪÕâ¸öÓû§ÒѾ­´æÔÚ.ÓÃÕâÖÖ·½Ê½,¿ÉÒÔ¶¯Ì¬½¨Á¢UNIXÓû§Õ˺Ų¢Æ¥ÅäÒÑÓеÄNTÕ˺Å.

²Î¼û security, password server, delete user script.

ȱʡÉèÖÃ: add user script = <¿Õ×Ö·û´®>

ʾÀý: add user script = /usr/local/samba/bin/add_user %u

add user to group script (G)
Full path to the script that will be called when a user is added to a group using the Windows NT domain administration tools. It will be run by smbd(8) AS ROOT. Any %g will be replaced with the group name and any %u will be replaced with the user name.

ȱʡÉèÖÃ: add user to group script =

ʾÀý: add user to group script = /usr/sbin/adduser %u %g

admin users (S)
admin users¶¨ÒåÒ»×é¶Ô¹²ÏíÓйÜÀíÌØȨµÄÓû§.¾ÍÏ൱ÓÚÕâЩÓû§¿ÉÒÔÏ󳬼¶Óû§ÄÇÑù²Ù×÷ËùÓеÄÎļþ.

СÐÄʹÓøÃÑ¡Ïî,ÒòΪÔÚÕâ¸öÃûµ¥ÀïµÄÓû§¿ÉÒÔ¶Ô¹²Ïí×ÊÔ´×÷ÈκÎËûÃÇÏë×öµÄÊÂ.

ȱʡÉèÖÃ: ûÓÐ admin users

ʾÀý: admin users = jason

afs share (S)
This parameter controls whether special AFS features are enabled for this share. If enabled, it assumes that the directory exported via the path parameter is a local AFS import. The special AFS features include the attempt to hand-craft an AFS token if you enabled --with-fake-kaserver in configure.

ȱʡÉèÖÃ: afs share = no

ʾÀý: afs share = yes

afs username map (G)
If you are using the fake kaserver AFS feature, you might want to hand-craft the usernames you are creating tokens for. For example this is necessary if you have users from several domain in your AFS Protection Database. One possible scheme to code users as DOMAIN+User as it is done by winbind with the + as a separator.

The mapped user name must contain the cell name to log into, so without setting this parameter there will be no token.

ȱʡÉèÖÃ: none

ʾÀý: afs username map = %u@afs.samba.org

algorithmic rid base (G)
This determines how Samba will use its algorithmic mapping from uids/gid to the RIDs needed to construct NT Security Identifiers.

Setting this option to a larger value could be useful to sites transitioning from WinNT and Win2k, as existing user and group rids would otherwise clash with sytem users etc.

All UIDs and GIDs must be able to be resolved into SIDs for the correct operation of ACLs on the server. As such the algorithmic mapping can't be 'turned off', but pushing it 'out of the way' should resolve the issues. Users and groups can then be assigned 'low' RIDs in arbitary-rid supporting backends.

ȱʡÉèÖÃ: algorithmic rid base = 1000

ʾÀý: algorithmic rid base = 100000

allow hosts (S)
ºÍhosts allowͬÒå.

allow trusted domains (G)
Õâ¸öÑ¡ÏîÖ»ÔÚsecurityÑ¡Ïî±»Éè³Éserver»òdomainģʽʱ²ÅÓÐЧ¹û.Èç¹ûÉèΪnoµÄ»°,³¢ÊÔÁª½Óµ½smbdÔËÐеÄÓò»ò¹¤×÷×éÒÔÍâµÄ×ÊԴʱ»áʧ°Ü,¼´Ê¹ÄǸöÓòÊÇÓÉÔ¶³Ì·þÎñÆ÷Ñé֤Ϊ¿ÉÐŵÄÒ²²»ÐÐ.

Èç¹ûÄãÖ»ÐèÒªÔÚÓòÖжԳÉÔ±Ìṩ·þÎñ×ÊÔ´µÄ»°Õâ¸öÑ¡ÏîÊǷdz£ÓÐÓõÄ.¾ÙÀýÀ´Ëµ,¼ÙÉèÓÐÁ½¸öÓòDOMAºÍDOMB,DOMAÒѾ­ÏòDOMB½øÐÐÁËίÍÐ,¶øsamba·þÎñÆ÷λÓÚDOMAÖÐ.ÔÚͨ³£Çé¿öÏÂ,ÔÚDOMBÖÐÓÐÕ˺ŵÄÓû§¿ÉÒÔÓÃͬÑùµÄsamba·þÎñÆ÷Õ˺ÅÃû·ÃÎÊUNIXÉϵÄ×ÊÔ´.¶øÎÞÐëËûÔÚDOMAÉÏÓÐÕ˺Å.²»¹ýÕâÑù¾Íʹ°²È«½çÏ߸üÄÑ·ÖÇåÁË.

ȱʡÉèÖÃ: allow trusted domains = yes

announce as (G)
Õâ¸öÑ¡ÏÒånmbd(8) ¶ÔÍøÂçÁÚ¾ÓÉù³ÆµÄ·þÎñÆ÷ÀàÐÍ.ȱʡΪwindows NT.¿ÉÑ¡ÏîÓÐ"NT",ËüÓë"NT Server"ͬÒå,"NT Server","NT Workstation","Win95"»ò"WfW",ËüÃÇ·Ö±ð´ú±íWindows NT Server,Windows NT Workstation,Windows 95ºÍWindows for Workgroups.³ý·ÇÓÐÌØÊâµÄÐèÒª²»ÏëÈÃsambaÒÔwindows NTµÄÉí·Ý³öÏÖ,Ò»°ã²»Òª¸Ä¶¯Õâ¸öÑ¡Ïî,ÒòΪÕâ¿ÉÄÜ»áÓ°Ïìsamba×÷Ϊä¯ÀÀ·þÎñÆ÷µÄÕýÈ·ÐÔ.

ȱʡÉèÖÃ: announce as = NT Server

ʾÀý: announce as = Win95

announce version (G)
´ËÑ¡ÏÒånmbdÓÃÓÚÉùÃ÷·þÎñÆ÷°æ±¾ºÅµÄÖ÷°æ±¾ºÅºÍ´Î°æ±¾ºÅ.ȱʡ°æ±¾ºÅµÄÊÇ4.9¡£³ý·ÇÓÐÌØÊâµÄ±ØÒªÏ뽫sambaÉèΪµÍ°æ±¾,Ò»°ã²»Òª¸Ä¶¯Õâ¸öÑ¡Ïî.

ȱʡÉèÖÃ: announce version = 4.9

ʾÀý: announce version = 2.0

auth methods (G)
This option allows the administrator to chose what authentication methods smbd will use when authenticating a user. This option defaults to sensible values based on security. This should be considered a developer option and used only in rare circumstances. In the majority (if not all) of production servers, the default setting should be adequate.

Each entry in the list attempts to authenticate the user in turn, until the user authenticates. In practice only one method will ever actually be able to complete the authentication.

Possible options include guest (anonymous access), sam (lookups in local list of accounts based on netbios name or domain name), winbind (relay authentication requests for remote users through winbindd), ntdomain (pre-winbindd method of authentication for remote domain users; deprecated in favour of winbind method), trustdomain (authenticate trusted users by contacting the remote DC directly from smbd; deprecated in favour of winbind method).

ȱʡÉèÖÃ: auth methods = <¿Õ×Ö·û´®>

ʾÀý: auth methods = guest sam winbind

auto services (G)
Óë preload ͬÒå.

available (S)
Õâ¸öÑ¡Ïî¿ÉÒÔÓÃÀ´¹ØµôÒ»¸ö·þÎñÏî.Èç¹ûavailable = no,ÄÇôËùÓжԸ÷þÎñµÄÁ¬½Ó¶¼»áʧ°Ü.¶øÕâЩʧ°Ü»á±»¼Ç¼ÏÂÀ´.

ȱʡÉèÖÃ: available = yes

bind interfaces only (G)
Õâ¸öÈ«¾ÖÑ¡ÏîÔÊÐísamba¹ÜÀíÔ±ÏÞÖÆһ̨Ö÷»úµÄijһ¸öÍøÂç½Ó¿ÚÓÃÓÚÏìÓ¦ÇëÇó.Õâ»á¶ÔÓÚsmbd(8)Îļþ·þÎñºÍnmbd(8)Ãû×Ö·þÎñÔì³ÉЩÐíÓ°Ïì.

¶ÔÓÚÃû×Ö·þÎñ,Ëü½«Ê¹nmbd °ó¶¨µ½'interfaces'Ñ¡ÏîÀïÁгöµÄÍøÂç½Ó¿ÚµÄ137ºÍ138¶Ë¿ÚÉÏ.ΪÁ˶ÁÈ¡¹ã²¥ÏûÏ¢,nmbdÒ²»á°ó¶¨µ½"ËùÓеØÖ·"½Ó¿Ú(0.0.0.0)µÄ137ºÍ138¶Ë¿ÚÉÏ.Èç¹ûûÓÐÉèÖÃÕâ¸öÑ¡Ïî,nmbd½«ÔÚËùÓеĽӿÚÉÏÏìÓ¦Ãû×Ö·þÎñÇëÇó.Èç¹ûÉèÖÃÁË"bind interfaces only",ÄÇônmbd½«Ôڹ㲥½Ó¿ÚÉϼì²éÈκηÖ×éµÄÔ´µØÖ·,¶ªÆúÈκβ»Æ¥ÅäinterfacesÑ¡ÏîËùÁнӿÚÖ®¹ã²¥µØÖ·µÄ·Ö×é.µ±ÔÚÆäËü½Ó¿ÚÉÏÊÕµ½µ¥²¥·Ö×é,´ËÑ¡Ïîʹnmbd¾Ü¾ø¶ÔÈκβ»ÊÇÊÇinterfacesÑ¡ÏîËùÁнӿÚÀ´·¢ËÍ·Ö×éµÄÖ÷»úµÄ·þÎñ.IPÔ´µØÖ·ºåÆ­¿ÉÒÔʹÕâ¸ö¼òµ¥µÄ¼ì²éʧЧ,ËùÒÔ²»Òª½«nmbd°²È«¹¦ÄÜÓÃÓÚÑÏËೡºÏ.

¶ÔÓÚÎļþ·þÎñ,¸ÃÑ¡Ïîʹsmbd(8)Ö»ÔÚ'interfaces'Ñ¡ÏîËùÁеÄÍøÂç½Ó¿ÚÉÏ°ó¶¨.Õâ¾ÍÏÞÖÆsmbd Ö»ÏìÓ¦ÄÇЩ½Ó¿ÚÉÏ·¢³öµÄ·Ö×é.×¢Òâ,²»Ó¦¸ÃÔÚPPPºÍʱ¶ÏʱÐøµÄ»úÆ÷ÉÏ»ò·Ç¹ã²¥ÍøÂç½Ó¿ÚÉÏʹÓÃÕâ¸öÑ¡Ïî,ÒòΪËü´¦Àí²»ÁË·ÇÓÀ¾ÃÁ¬½ÓµÄ½Ó¿Ú.

Èç¹ûÉèÖÃÁËbind interfaces only,³ý·ÇÍøÂçµØÖ·127.0.0.1±»¼Óµ½interfacesÑ¡ÏîµÄÁбíÖÐ,·ñÔòsmbpasswd(8)ºÍswat(8) ¿ÉÄܲ»»áÏóÎÒÃÇËùÆÚÍûµÄÄÇÑù¹¤×÷,Ô­ÒòÈçÏÂ:

ΪÁ˸ıäÓû§SMB¿ÚÁî,smbpasswdȱʡÇé¿öÏ»áÒÔsmb¿Í»§¶ËµÄÉí·ÝÁ¬½Ó±¾µØÖ÷»úµØÖ·localhost - 127.0.0.1,·¢³ö¸ü¸Ä¿ÚÁîÇëÇó.Èç¹ûÉèÖÃÁËbind interfaces only,smbpasswdÔÚȱʡÇé¿öϽ«»áÁ¬½Óʧ°Ü,³ý·Ç127.0.0.1Òѱ»¼ÓÈëµ½interfacesÑ¡Ïî.ÁíÍâ,¿ÉÒÔÓÃ-r remote machineÑ¡ÏîÖ¸¶¨±¾µØÖ÷»úµÄÖ÷ÍøÂç½Ó¿ÚipµØÖ·,ÕâÑùsmbpasswd¾Í»áÇ¿ÖÆʹÓñ¾µØµÄÖ÷ipµØÖ·.

swatµÄ״̬ҳÃæ»áÔÚ127.0.0.1³¢ÊÔÁ¬½ÓsmbdºÍ nmbd,ÒÔÈ·¶¨ËüÃÇÊÇ·ñÕýÔÚÔËÐÐ.Èç¹û²»¼ÓÈë127.0.0.1,½«»áʹsmbdºÍnmbd ×ܱíʾûÓÐÔËÐÐÉõÖÁʵ¼ÊÇé¿ö²¢²»ÊÇÕâÑù.Õâ¾Í×èÖ¹ÁË swatÆô¶¯/Í£Ö¹/ÖØÆô¶¯smbd ºÍnmbd½ø³Ì.

ȱʡÉèÖÃ: bind interfaces only = no

blocking locks (S)
´ËÏî¿ØÖÆÔÚ¿Í»§ÎªÁËÔÚ´ò¿ªÎļþ´¦»ñµÃÒ»¸ö×Ö½Ú·¶Î§µÄËø¶¨¶ø·¢³öÇëÇóʱsmbd(8)µÄ¶¯×÷,ͬʱ ¸ÃÇëÇó»áÓÐÒ»¸öÓëÖ®Ïà¹ØµÄʱÏÞ.

Èç¹ûÉèÖÃÁËÕâ¸öÑ¡Ïî,Ëø¶¨·¶Î§ÇëÇó²»ÄÜÁ¢¼´Âú×ãµÄ»°,samba½«»áÔÚÄÚ²¿¶ÔÇëÇó½øÐÐÅŶÓ,²¢ÇÒÖÜÆÚÐԵس¢ÊÔ»ñµÃËø¶¨,Ö±µ½³¬Ê±.

Èç¹ûÕâ¸öÑ¡ÏîÉèÖÃΪno,samba¾Í»áͬÒÔÇ°°æ±¾ÄÇÑù,ÔÚËø¶¨·¶Î§ÎÞ·¨»ñµÃʱÁ¢¼´Ê¹Ëø¶¨ÇëÇóʧ°Ü.

ȱʡÉèÖÃ: blocking locks = yes

block size (S)
This parameter controls the behavior of smbd(8) when reporting disk free sizes. By default, this reports a disk block size of 1024 bytes.

Changing this parameter may have some effect on the efficiency of client writes, this is not yet confirmed. This parameter was added to allow advanced administrators to change it (usually to a higher value) and test the effect it has on client write performance without re-compiling the code. As this is an experimental option it may be removed in a future release.

Changing this option does not change the disk free reporting size, just the block size unit reported to the client.

browsable (S)
Óë browseable ͬÒå¡£

browseable (S)
Õâ¸öÑ¡Ïî¿ØÖƹ²Ïí×ÊÔ´ÔÚ¿É»ñµÃ¹²ÏíÁÐ±í¡¢net viewÃüÁî¼°ä¯ÀÀÁбíÀïÊÇ·ñ¿É¼û.

ȱʡÉèÖÃ: browseable = yes

browse list (G)
Ëü¿ØÖÆsmbd(8)ÊÇ·ñÖ´ÐÐÒ»¸öNetServerEnumµ÷ÓÃÀ´Îª¿Í»§Ìṩһ¸öä¯ÀÀÁбí.Õý³£Çé¿öËü±»ÉèΪyes.Õâ¸öÑ¡Ïî¿ÉÄÜÓÀÔ¶²»ÐèÒª¸Ä¶¯.

ȱʡÉèÖÃ: browse list = yes

case sensitive (S)
²Î¼ûNAME MANGLING¶ÎµÄÌÖÂÛ.

ȱʡÉèÖÃ: case sensitive = no

casesignames (S)
Óë case sensitive ͬÒå.

change notify timeout (G)
sambaÔÊÐí¿Í»§¶Ë¸æËß·þÎñÆ÷¼àÊÓij¸öÌض¨Ä¿Â¼µÄÈκα仯,½öµ±Óб仯·¢ÉúµÄʱºò»Ø¸´SMBÇëÇó.ÕâÖÖÁ¬Ðø²»¶ÏµÄɨÃèÔÚunixϵͳÉÏ´ú¼ÛºÜ¸ß,Òò´Ë,smbd(8)Ö»Ôڵȴýchange notify timeoutʱ¼äºó²Å¶Ôÿ¸öÇëÇóµÄĿ¼ִÐÐÒ»´ÎɨÃè.

ȱʡÉèÖÃ: change notify timeout = 60

ʾÀý: change notify timeout = 300

Õ⽫°ÑɨÃèʱ¼ä¸ÄΪÿ5·ÖÖÓÒ»´Î.

change share command (G)
Samba 2.2.0 introduced the ability to dynamically add and delete shares via the Windows NT 4.0 Server Manager. The change share command is used to define an external program or script which will modify an existing service definition in smb.conf. In order to successfully execute the change share command, smbd requires that the administrator be connected using a root account (i.e. uid == 0).

When executed, smbd will automatically invoke the change share command with four parameters.

configFile - the location of the global smb.conf file.

shareName - the name of the new share.

pathName - path to an **existing** directory on disk.

comment - comment string to associate with the new share.

This parameter is only used modify existing file shares definitions. To modify printer shares, use the "Printers..." folder as seen when browsing the Samba host.

²Î¼û add share command, delete share command.

ȱʡÉèÖÃ: none

ʾÀý: change share command = /usr/local/bin/addshare

client lanman auth (G)
This parameter determines whether or not smbclient(8) and other samba client tools will attempt to authenticate itself to servers using the weaker LANMAN password hash. If disabled, only server which support NT password hashes (e.g. Windows NT/2000, Samba, etc... but not Windows 95/98) will be able to be connected from the Samba client.

The LANMAN encrypted response is easily broken, due to it's case-insensitive nature, and the choice of algorithm. Clients without Windows 95/98 servers are advised to disable this option.

Disabling this option will also disable the client plaintext auth option

Likewise, if the client ntlmv2 auth parameter is enabled, then only NTLMv2 logins will be attempted. Not all servers support NTLMv2, and most will require special configuration to us it.

Default : client lanman auth = yes

client ntlmv2 auth (G)
This parameter determines whether or not smbclient(8) will attempt to authenticate itself to servers using the NTLMv2 encrypted password response.

If enabled, only an NTLMv2 and LMv2 response (both much more secure than earlier versions) will be sent. Many servers (including NT4 < SP4, Win9x and Samba 2.2) are not compatible with NTLMv2.

Similarly, if enabled, NTLMv1, client lanman auth and client plaintext auth authentication will be disabled. This also disables share-level authentication.

If disabled, an NTLM response (and possibly a LANMAN response) will be sent by the client, depending on the value of client lanman auth.

Note that some sites (particularly those following 'best practice' security polices) only allow NTLMv2 responses, and not the weaker LM or NTLM.

Default : client ntlmv2 auth = no

client plaintext auth (G)
Specifies whether a client should send a plaintext password if the server does not support encrypted passwords.

ȱʡÉèÖÃ: client plaintext auth = yes

client schannel (G)
This controls whether the client offers or even demands the use of the netlogon schannel. client schannel = no does not offer the schannel, server schannel = auto offers the schannel but does not enforce it, and server schannel = yes denies access if the server is not able to speak netlogon schannel.

ȱʡÉèÖÃ: client schannel = auto

ʾÀý: client schannel = yes

client signing (G)
This controls whether the client offers or requires the server it talks to to use SMB signing. Possible values are auto, mandatory and disabled.

When set to auto, SMB signing is offered, but not enforced. When set to mandatory, SMB signing is required and if set to disabled, SMB signing is not offered either.

ȱʡÉèÖÃ: client signing = auto

client use spnego (G)
This variable controls controls whether samba clients will try to use Simple and Protected NEGOciation (as specified by rfc2478) with WindowsXP and Windows2000 servers to agree upon an authentication mechanism. SPNEGO client support for SMB Signing is currently broken, so you might want to turn this option off when operating with Windows 2003 domain controllers in particular.

ȱʡÉèÖÃ: client use spnego = yes

comment (S)
ÕâÊÇÒ»¶Îµ±¿Í»§ÓÃÍøÉÏÁÚ¾Ó(net view)²ì¿´·þÎñÆ÷ÉϹ²Ïí×ÊԴʱÏÔʾµÄ˵Ã÷ÎÄ×Ö.

Èç¹ûÏëÉèÖûúÆ÷ÃûºóµÄ˵Ã÷ÎÄ×ÖÇë²Î¿¼ server string ÃüÁî.

ȱʡÉèÖÃ: No comment string

ʾÀý: comment = Fred's Files

config file (G)
Õâ¿ÉÒÔʹsambaʹÓÃÖ¸¶¨µÄÅäÖÃÎļþÀ´Ìæ´úȱʡµÄÅäÖÃÎļþ,(ͨ³£ÊÇsmb.conf).Èç¹ûÉèÖÃÁËÕâ¸öÑ¡Ïî,»á³öÏÖÒ»¸öÏÈÓ즻¹ÊÇÏÈÓе°µÄÎÊÌâ!

ÓÉÓÚÕâ¸öÔ­Òò,Èç¹ûÔÚ¼ÓÔØÕâ¸öÑ¡ÏîµÄʱºò·¢ÏÖÅäÖÃÎļþÃû±ä»¯ÁË,¾Í»á´ÓеÄÅäÖÃÎļþÀïÖØмÓÔØÑ¡Ïî.

Õâ¸öÑ¡Ïî×÷Ϊ³£ÓõÄÌæ»»·Ç³£ÓÐÓÃ.

Èç¹ûÕâ¸öÅäÖÃÎļþ²»´æÔÚ,ÄÇô¾Í²»»á±»¼ÓÔØ.(ÔÊÐíÄãÌØÊâµØ´¦ÀíÉÙÊý¿Í»§µÄÅäÖÃÎļþ)

ʾÀý: config file = /usr/local/samba/lib/smb.conf.%m

copy (S)
ÕâʹÄã¿ÉÒÔ¿Ë¡·þÎñ. Ö¸¶¨µÄ·þÎñÒÔµ±Ç°·þÎñµÄÃû×Ö½øÐмòµ¥µÄ¸´ÖÆ,µ±Ç°·þÎñÀﶨÒåµÄÑ¡ÏÌæ´ú±»¿½·þÎñÀïÈκÎÏàÓ¦µÄÑ¡Ïî.

Õâ¸öÌØÐÔÔÊÐí½¨Á¢Ò»¸ö·þÎñµÄ'Ä£°æ',¿ÉÒÔºÜÈÝÒ×µÄÉú³ÉÏàËƵķþÎñ.×¢Òâ,±»¿½±´µÄ·þÎñÔÚÅäÖÃÎļþÀï±ØÐëÏÈÓÚ¿½±´µÄ·þÎñ³öÏÖ.

ȱʡÉèÖÃ: no value

ʾÀý: copy = otherservice

create mask (S)
Óë create mode ͬÒå.

µ±Éú³ÉÒ»¸öÎļþµÄʱºò,ÐèÒªÖªµÀ´ÓdosģʽӳÉäµ½unixϵÄÎļþȨÏÞ.×îºóµÄ½á¹ûÓÃÕâ¸ö²ÎÊý½øÐÐÖðλµÄÓëÔËËãµÃµ½.Õâ¸öÑ¡Ïî¿ÉÒÔÀí½â³ÉunixÏÂÎļþµÄλÑÚÂë.ÔÚÉú³ÉÎļþµÄʱºò,ÈκÎûÓÐÉèÖõÄ뽫»á´Ó´´½¨Ä£Ê½ÖÐÈ¥µô.

Õâ¸öÑ¡ÏîµÄȱʡֵÊÇ´ÓunixµÄÎļþ´´½¨Ä£Ê½ÖÐÈ¥µô×éºÍÆäËûÓû§µÄдºÍÖ´Ðбê־λ.

¸ù¾ÝÕâ¸ö¹æÔò,samba½«»á°ÑÕâ¸öÑ¡ÏîÉú³ÉµÄunixÎļþ´´½¨Ä£Ê½ºÍÓÉforce create modeÉèÖõÄÑ¡Ïî½øÐÐÖðλµÄ»òÔËËã,force create mode µÄȱʡѡÏîÊÇ000.

Õâ¸öÑ¡Ïî²»»áÓ°ÏìĿ¼´´½¨Ä£Ê½.ϸ½Ú²Î¼ûdirectory mode .

²Î¿¼force create modeÒÔ½øÒ»²½Á˽âÔÚ´´½¨ÎļþʱÉèÖõÄÌØÊâλ.¹ØÓÚ´´½¨Ä¿Â¼Ä£Ê½²Î¼ûdirectory modeÑ¡Ïî.²Î¼û inherit permissions parameter.

Note that this parameter does not apply to permissions set by Windows NT/2000 ACL editors. If the administrator wishes to enforce a mask on access control lists also, they need to set the security mask.

ȱʡÉèÖÃ: create mask = 0744

ʾÀý: create mask = 0775

create mode (S)
Óë create mask ͬÒå.

csc policy (S)
This stands for client-side caching policy, and specifies how clients capable of offline caching will cache the files in the share. The valid values are: manual, documents, programs, disable.

These values correspond to those used on Windows servers.

For example, shares containing roaming profiles can have offline caching disabled using csc policy = disable.

ȱʡÉèÖÃ: csc policy = manual

ʾÀý: csc policy = programs

deadtime (G)
Õâ¸öÖµ(Ê®½øÖÆÕûÊý)¶¨ÒåÁ¬½Ó·¢´ô³¬Ê±,µ¥Î»ÊÇ·ÖÖÓ.Èç¹ûÒ»¸öÁ¬½Ó·¢³¬¹ýÁËÕâ¸öʱ¼ä¾Í»á±»¶Ï¿ª.Èç¹ûÓÐÎļþ±»´ò¿ªÁË,Õâ¸öʱ¼ä¾Í²»Æð×÷ÓÃ.

Õâ¿ÉÒÔ±£»¤·þÎñÆ÷²»±»¹ý¶àµÄ·¢´ôÁ¬½ÓºÄ¾¡×ÊÔ´.

¶àÊý¿Í»§¶ËÓÐÁ¬½Ó¶Ï¿ªºóµÄ×Ô¶¯ÖØÁ¬¹¦ÄÜ,ËùÒÔ´ó¶àÊýÇé¿öÏÂ,Õâ¸öÑ¡Ïî¶ÔÓû§Ó¦¸ÃÊÇ͸Ã÷µÄ

¶Ô¶àÊýϵͳ½¨ÒéʹÓý϶̵ķ¢´ô³¬Ê±µÄÑ¡Ïî.

·¢´ô³¬Ê±Ñ¡Ïî±»ÉèΪ0Òâζ×Ų»»á×Ô¶¯¶Ï¿ªÁ¬½Ó..

ȱʡÉèÖÃ: deadtime = 0

ʾÀý: deadtime = 15

debug hires timestamp (G)
ÓÐЩʱºò¼Ç¼ÐÅÏ¢ÐèÒª±ÈÃë¸ü¸ß²ã´ÎµÄʱ¼ä±êʶ,ÓÃÕâ¸ö²¼¶ûÁ¿Ñ¡Ïî¿ÉÒÔÏòʱ¼ä±êʶÐÅϢͷÖмÓÈëÒÔ΢Ã뼶µÄƵÂÊ.

×¢ÒâҪʹÓÃÕâ¸öÑ¡Ïî,±ØÐë´ò¿ª debug timestampÑ¡Ïî.

ȱʡÉèÖÃ: debug hires timestamp = no

debuglevel (G)
Óë log level ͬÒå.

debug pid (G)
ΪºÜ¶à´Ósmbd(8)fork³öÀ´µÄ½ø³ÌʹÓÃͬһ¸ö¼Ç¼Îļþʱ£¬ºÜÄѾ«È·µØ¸ú×ÙÐÅÏ¢ÊÇÄĸö½ø³ÌÊä³öµÄ.ÓÃÕâ¸ö²¼¶ûÁ¿Ñ¡ÏîÏòʱ¼ä±êʶÐÅϢͷÖÐ×Ô¶¯Ìí¼Ó½ø³ÌºÅ.

×¢ÒâҪʹÓÃÕâ¸öÑ¡Ïî,±ØÐë´ò¿ª debug timestamp Ñ¡Ïî.

ȱʡÉèÖÃ: debug pid = no

debug timestamp (G)
sambaȱʡ»á¸øµ÷ÊԼͼÐÅÏ¢¼ÓÉÏʱ¼ä±êʶ.Èç¹ûÔËÐеÄÊǸ߼¶±ðdebug levelµÄµ÷ÊÔ,Õâ¸öʱ¼ä±êʶ¿ÉÒÔ±»×ªÒÆ.ÓÃÕâ¸öÑ¡Ïî¿ÉÒÔ½«Ê±¼ä±êʶ¹Ø±Õ.

ȱʡÉèÖÃ: debug timestamp = yes

debug uid (G)
sambaÓÐʱÒÔrootÉí·ÝÔËÐÐ,¶øÓÐʱÒÔÒÑÁª½ÓµÄÓû§À´ÔËÐÐ.ʹÓÃÕâ¸ö²¼¶ûÁ¿Ñ¡Ïî¿ÉÒÔÏò¼Ç¼ÎļþµÄʱ¼ä±êʶÐÅϢͷÖÐ×Ô¶¯²åÈ뵱ǰµÄeuid,egid,uidºÍgid±êʶ.

Note that the parameter must be on for this to have an effect. ×¢ÒâҪʹÓÃÕâ¸öÑ¡Ïî,±ØÐë´ò¿ª debug timestampÑ¡Ïî.

ȱʡÉèÖÃ: debug uid = no

default (G)
Óë default service ͬÒå.

default case (S)
²Î¼û"NAME MANGLING"¶Î. Ò²×¢ÒâÒ»ÏÂshort preserve caseÑ¡Ïî.

ȱʡÉèÖÃ: default case = lower

default devmode (S)
This parameter is only applicable to printable services. When smbd is serving Printer Drivers to Windows NT/2k/XP clients, each printer on the Samba server has a Device Mode which defines things such as paper size and orientation and duplex settings. The device mode can only correctly be generated by the printer driver itself (which can only be executed on a Win32 platform). Because smbd is unable to execute the driver code to generate the device mode, the default behavior is to set this field to NULL.

Most problems with serving printer drivers to Windows NT/2k/XP clients can be traced to a problem with the generated device mode. Certain drivers will do things such as crashing the client's Explorer.exe with a NULL devmode. However, other printer drivers can cause the client's spooler service (spoolsv.exe) to die if the devmode was not created by the driver itself (i.e. smbd generates a default devmode).

This parameter should be used with care and tested with the printer driver in question. It is better to leave the device mode to NULL and let the Windows client set the correct values. Because drivers do not do this all the time, setting default devmode = yes will instruct smbd to generate a default one.

For more information on Windows NT/2k printing and Device Modes, see the MSDN documentation.

ȱʡÉèÖÃ: default devmode = no

default service (G)
Õâ¸öÑ¡ÏÒåÒ»¸öµ±Ö¸¶¨·þÎñÕÒ²»µ½Ê±µÄȱʡ·þÎñ.×¢Òâ,ÔÚÑ¡ÏîÖµÀïûÓз½À¨ºÅ(¿´Ê¾Àý£¡).

Õâ¸öÑ¡ÏîûÓÐȱʡֵ. Èç¹ûû¸ø³öÕâ¸öÑ¡ÏîµÄ»°,¶Ô²»´æÔڵķþÎñµÄÇëÇ󽫷µ»Ø´íÎó.

ȱʡ·þÎñÒ»°ãÊÇÄÇЩÔÊÐíguest ok, read-onlyµÄ·þÎñ.

ÍâÔڵķþÎñÃû¿ÉÄܱ»Ìæ»»³ÉÇëÇóµÄ·þÎñÃû,ÕâÑù¾Í¿ÉÒÔÓÃÏó%SÕâÑùµÄºêÀ´×öÒ»¸öͨÓõķþÎñ.

×¢ÒâÔÚȱʡ·þÎñÑ¡ÏîÖ¸¶¨µÄ·þÎñÃûÀï, ×Ö·û'_'±»Ó³ÉäΪ'/'. ÕâÑù¿ÉÄÜ»á³öÏÖÓÐȤµÄÊÂÇé.

ʾÀý:

[global]
        default service = pub
[pub]
        path = /%S

delete group script (G)
This is the full pathname to a script that will be run AS ROOT smbd(8) when a group is requested to be deleted. It will expand any %g to the group name passed. This script is only useful for installations using the Windows NT domain administration tools.

deleteprinter command (G)
With the introduction of MS-RPC based printer support for Windows NT/2000 clients in Samba 2.2, it is now possible to delete printer at run time by issuing the DeletePrinter() RPC call.

For a Samba host this means that the printer must be physically deleted from underlying printing system. The deleteprinter command defines a script to be run which will perform the necessary operations for removing the printer from the print system and from smb.conf.

The deleteprinter command is automatically called with only one parameter: "printer name".

Once the deleteprinter command has been executed, smbd will reparse the smb.conf to associated printer no longer exists. If the sharename is still valid, then smbd will return an ACCESS_DENIED error to the client.

²Î¼û addprinter command, printing, show add printer wizard

ȱʡÉèÖÃ: none

ʾÀý: deleteprinter command = /usr/bin/removeprinter

delete readonly (S)
Õâ¸öÑ¡ÏîÔÊÐíɾ³ýÖ»¶ÁÎļþ,Õâ¸öÖ»¶Á²»ÊÇͨ³£dosÀïµÄº¬Òå,¶øÊÇunixÖеÄ.

Õâ¸öÑ¡Ïî¶ÔÓÚrcsÕâÑùµÄÓ¦ÓúÜÓÐÓÃ,ÔÚÕâÖÖÇé¿öÏÂ,unixÎļþµÄÊôÖ÷²»ÔÊÐí¸Ä±äȨÏÞ,dosÎļþÖ»¶Á.

ȱʡÉèÖÃ: delete readonly = no

delete share command (G)
Samba 2.2.0 introduced the ability to dynamically add and delete shares via the Windows NT 4.0 Server Manager. The delete share command is used to define an external program or script which will remove an existing service definition from smb.conf. In order to successfully execute the delete share command, smbd requires that the administrator be connected using a root account (i.e. uid == 0).

When executed, smbd will automatically invoke the delete share command with two parameters.

configFile - the location of the global smb.conf file.

shareName - the name of the existing service.

This parameter is only used to remove file shares. To delete printer shares, see the deleteprinter command.

²Î¼û add share command, change share command.

ȱʡÉèÖÃ: none

ʾÀý: delete share command = /usr/local/bin/delshare

delete user from group script (G)
Full path to the script that will be called when a user is removed from a group using the Windows NT domain administration tools. It will be run by smbd(8) AS ROOT. Any %g will be replaced with the group name and any %u will be replaced with the user name.

ȱʡÉèÖÃ: delete user from group script =

ʾÀý: delete user from group script = /usr/sbin/deluser %u %g

delete user script (G)
Ëü¶¨ÒåÒ»¸öÔÚʹÓÃRPC(NT)¹¤¾ß¹ÜÀíÓû§Ê±£¬fBsmbd(8)ÒÔrootÉí·ÝÔËÐеİüÀ¨Â·¾¶µÄÒ»¸ö½Å±¾.

µ±Ô¶³Ì¿Í»§Ê¹ÓÃ'User Manager for Domains' »òÊÇ rpcclient ´Ó·þÎñÆ÷ÉÏɾ³ýÒ»¸öÓû§Ê±Ö´Ðд˲Ù×÷¡£

Õâ¸ö½Å±¾É¾³ý¸ø¶¨µÄunixÓû§¡£

ȱʡÉèÖÃ: delete user script = <¿Õ×Ö·û´®>

ʾÀý: delete user script = /usr/local/samba/bin/del_user %u

delete veto files (S)
Õâ¸öÑ¡ÏîÓÃÓÚsambaÊÔͼɾ³ýÒ»¸ö»ò¶à¸ö°üº¬½ûÖ¹ÎļþµÄĿ¼µÄÇé¿ö(²Î¼ûveto filesÑ¡Ïî). Èç¹ûÕâ¸öÑ¡ÏîÉèÖÃΪno(ȱʡÇé¿ö),ÄÇôÈç¹ûÒ»¸ö½ûֹĿ¼Àï°üº¬ÁËÈκηǽûÖ¹µÄÎļþ»òĿ¼,ɾ³ý¾Í»áʧ°Ü.Õâͨ³£ÕýÊÇÄãËùÏ£ÍûµÄ.

Èç¹ûÕâ¸öÑ¡Ïî±»ÉèΪÁË yes,Samba½«ÊÔͼµÝ¹éɾ³ýÔÚ±»½ûֹĿ¼ÀïµÄÈκÎÎļþºÍĿ¼.Õâ¶ÔÓÚÕûºÏÏóNetAtalkÕâÑùµÄÎļþ·þÎñϵͳºÜÓÐÓÃ,Ëüͨ³£»áÔÚĿ¼ÀïÉú³ÉDos/windowsÓû§¿´²»¼ûµÄÖмäÎļþ(e.g. .AppleDouble).

ÉèÖÃdelete veto files = yes ʹÄÇЩÓÐȨÏÞµÄÓû§¿ÉÒÔÔÚɾ³ý¸¸Ä¿Â¼µÄʱºò͸Ã÷µÄɾ³ý×ÓĿ¼.

²Î¼û veto files Ñ¡Ïî.

ȱʡÉèÖÃ: delete veto files = no

deny hosts (S)
Óë hosts deny ͬÒå.

dfree command (G)
dfree commandÖ»ÐèÔÚ´ÅÅÌ¿Õ¼ä¼ÆËãÓÐÎÊÌâµÄϵͳÉÏʹÓÃ.Õâ¸ö¿Õ¼ä¼ÆËãµÄÎÊÌâ½öÔÚUltrixϵͳÉÏ·¢Éú¹ý,µ«ÔÚÆäËûµÄ²Ù×÷ϵͳÉÏÒ²ÓпÉÄÜ·¢Éú.·¢ÉúÕâ¸öÎÊÌâµÄÏÖÏóÊÇÔÚÿ¸öĿ¼Áбí×îºó·¢Éú´íÎó²¢Ìáʾ"Abort Retry Ignore".

Õâ¸öÉèÖÃÔÊÐíÓÃÍⲿ³ÌÐò´úÌæÄÚ²¿³ÌÐòÀ´¼ÆËã×ܹ²µÄ´ÅÅÌ¿Õ¼äºÍ¿ÉÓõĴÅÅÌ¿Õ¼ä.ÏÂÃæµÄÀý×Ó¸ø³öÁËÒ»¸öÄÜÍê³ÉÕâ¸ö¹¦ÄܵĽű¾.

Õâ¸öÍⲿ³ÌÐòµÄÊäÈëÊÇÎļþϵͳÀïÒ»¸öÐèÒª¼ÆËãµÄĿ¼,µäÐ͵İüÀ¨./×Ö·û´®.ÒÔasciiÂë·µ»ØÁ½¸öÕûÊý.µÚÒ»¸öÊÇ×ܹ²µÄ´ÅÅÌ¿Õ¼ä(ÒÔ¿éΪµ¥Î»),µÚ¶þ¸öÊÇ¿ÉÓÿéÊ÷.¿ÉÑ¡µÄµÚÈý¸ö·µ»ØÖµ¿ÉÒÔÒÔ×Ö½ÚΪµ¥Î»¸ø³ö¿éµÄ´óС.ȱʡµÄ¿éµÄ´óСÊÇ1024×Ö½Ú.

×¢Òâ:Õâ¸ö½Å±¾Ó¦¸ÃÊôÖ÷Ϊroot,Ö»ÓÐroot¿Éд,²¢ÇÒ²»ÄÜ´øÓÐÓû§±êʶλºÍ×é±êʶλ(setuid or setgid)!

ȱʡÉèÖÃ: ȱʡÓÃÄÚ²¿³ÌÐòÀ´¼ÆËã´ÅÅÌÈÝÁ¿ºÍ¿ÉÓÿռä.

ʾÀý: dfree command = /usr/local/samba/bin/dfree

ÈçÏÂÕâ¸ödfree½Å±¾±ØÐëÊÇ¿ÉÖ´ÐеÄ.

 
#!/bin/sh
df $1 | tail -1 | awk '{print $2" "$4}'

ÔÚSys VÒ»ÀàµÄϵͳÉÏ¿ÉÄÜÊÇ:

 
#!/bin/sh
/usr/bin/df -k $1 | tail -1 | awk '{print $3" "$5}'

×¢ÒâÔÚÌض¨µÄϵͳÉÏ¿ÉÄÜÐèÒª¸ø³öÏàÓ¦µÄ´øÓÐȫ·¾¶µÄÃüÁî.

directory (S)
Óë path ͬÒå.

directory mask (S)
Õâ¸öÑ¡ÏîÊÇ8½øÖƵÄģʽ¡£ÓÃÀ´¿ØÖÆÔÚÉú³ÉUNIXĿ¼ʱ£¬½«Æä´Ódosģʽת»»Îªunixģʽ¡£

µ±Éú³ÉÒ»¸ö·¾¶µÄʱºò,±ØÐëÖ¸¶¨µÄĿ¼ȨÏÞ´ÓdosģʽӳÉäµ½unixģʽ,È»ºóÕâ¸ö½á¹ûºÍÕâ¸öÑ¡Ïî½øÐÐÖðλµÄÓëÔËËã.Õâ¸öÑ¡Ïî¿ÉÒÔÀí½â³ÉunixģʽϵÄλÑÚÂë.Õâ¸öÑ¡ÏîÀïÈκÎûÓÐÉèÖõÄλÔÚÉú³ÉunixϵÄĿ¼ʱ½«»á±»È¥µô

ȱʡÇé¿öÏÂ,Õâ¸öÑ¡Ïî°Ñ×éºÍÆäËûÓû§µÄдȨÏÞλȥµô,Ö»ÔÊÐíĿ¼µÄÊôÖ÷¶ÔĿ¼½øÐÐÐÞ¸Ä.

Samba½«°ÑÕâ¸öÑ¡ÏîºÍforce directory modeµÄÑ¡Ïî½øÐÐÖðλµÄ»òÔËËã,Õâ¸öÑ¡ÏîȱʡʱÉèÖÃΪ000(Ò²¾ÍÊDz»¼Ó¶îÍâµÄÏÞÖÆ).

Note that this parameter does not apply to permissions set by Windows NT/2000 ACL editors. If the administrator wishes to enforce a mask on access control lists also, they need to set the directory security mask.

ÔÚÉú³ÉĿ¼ʱÈç¹ûÐèÒªÉèÖÃÌØÊâµÄģʽλ,²Î¼ûforce directory modeÑ¡Ïî.

¹ØÓÚÉú³ÉÎļþʱµÄģʽλ²Î¼ûcreate mode Ñ¡ÏîºÍdirectory security maskÑ¡Ïî.

Also refer to the inherit permissions parameter.

ȱʡÉèÖÃ: directory mask = 0755

ʾÀý: directory mask = 0775

directory mode (S)
Óë directory mask ͬÒå¡£

directory security mask (S)
´ËÑ¡Ïî¿ØÖÆÁËNT¿Í»§ÔÚËûµÄ±¾µØNT°²È«¶Ô»°¿òÖвÙ×ÝunixĿ¼ȨÏÞʱ¿ÉÒÔÐÞ¸ÄÄÄЩȨÏÞλ.

Õâ¸öÑ¡ÏîÒÔÑÚÂëÀ´ÊµÏָıäȨÏÞλ,ËùÒÔÔÚÐÞ¸ÄʱҪ·ÀÖ¹²»ÔÚÑÚÂëÖÐÉæ¼°µÄÄÇЩλ.ʵ¼ÊÉÏ,ÔÚÕâ¸öÑÚÂëÖеÄλ0¿ÉÒÔʹÓû§ÎÞ·¨¸Ä±äÈκ櫶«.

Èç¹ûûÓÐÃ÷È·É趨µÄ»°,Õâ¸öÑ¡Ïî»áÓÃÓëdirectory maskÑ¡ÏîͬÑùµÄÖµ.ÒªÔÊÐíÓû§ÔÚĿ¼ÖпÉÒÔÐÞ¸ÄËùÓеÄuser/group/worldȨÏÞ,¿ÉÒÔ°ÑÕâ¸öÑ¡ÏîÉèΪ0777.

×¢Òâ,ÄÜ·ÃÎÊsamba·þÎñÆ÷µÄÓû§Í¨¹ýÆäËü·½·¨Ò²¿ÉÒÔºÜÈÝÒ×µØÈƹýÕâ¸öÏÞÖÆ,ËùÒÔ¶Ô¶ÀÁ¢¹¤×÷µÄϵͳÀ´ËµÕâ¸öÑ¡ÏîÊÇ×î¸ù±¾×îÓÐÓõÄ.ºÜ¶àϵͳ¹ÜÀíµÄ¹ÜÀíÔ±¶¼»á°ÑËüÉèΪĬÈϵÄ0777.

²Î¼û force directory security mode, security mask, force security mode Ñ¡Ïî¡£

ȱʡÉèÖÃ: directory security mask = 0777

ʾÀý: directory security mask = 0700

disable netbios (G)
Enabling this parameter will disable netbios support in Samba. Netbios is the only available form of browsing in all windows versions except for 2000 and XP.

Note that clients that only support netbios won't be able to see your samba server when netbios support is disabled.

ȱʡÉèÖÃ: disable netbios = no

ʾÀý: disable netbios = yes

disable spoolss (G)
Enabling this parameter will disable Samba's support for the SPOOLSS set of MS-RPC's and will yield identical behavior as Samba 2.0.x. Windows NT/2000 clients will downgrade to using Lanman style printing commands. Windows 9x/ME will be uneffected by the Ñ¡Ïî¡£ However, this will also disable the ability to upload printer drivers to a Samba server via the Windows NT Add Printer Wizard or by using the NT printer properties dialog window. It will also disable the capability of Windows NT/2000 clients to download print drivers from the Samba host upon demand. Be very careful about enabling this Ñ¡Ïî¡£

See also use client driver

Default : disable spoolss = no

display charset (G)
Specifies the charset that samba will use to print messages to stdout and stderr and SWAT will use. Should generally be the same as the unix charset.

ȱʡÉèÖÃ: display charset = ASCII

ʾÀý: display charset = UTF8

dns proxy (G)
Ö¸¶¨nmbd(8)ÏóWINS·þÎñÆ÷ÄÇÑùÑ°ÕÒûÓеǼǵÄNetBIOSÃû,Ïó¶Ô´ýDNSÃûÄÇÑùÖð×ֵĶԴýNetBIOSÃû,ÏòDNS·þÎñÆ÷²éѯ¸ÃÃû³ÆËù´ú±íµÄ¿Í»§¶Ë.

×¢Òâ,NetBISOÃûµÄ×î´ó³¤¶ÈÊÇ15¸ö×Ö·û,ËùÒÔDNSÃû(»òDNS±ðÃû)ͬÑù×î¶àÖ»ÄÜÓÐ15¸ö×Ö·û.

nmbd ÔÚ×öDNSÃû²éѯµÄʱºò½«×ÔÉí¸´ÖÆÒ»·Ý,ÒòΪÓòÃû²éѯÊÇÒ»¸ö×èÈûµÄ¶¯×÷.

²Î¼û wins support ¡£

ȱʡÉèÖÃ: dns proxy = yes

domain logons (G)
Èç¹ûÕâ¸öÑ¡ÏîΪyes,Samba·þÎñÆ÷½«ÎªworkgroupÌṩWindows 95/98 µÇ½Óò·þÎñ.Samba 2.2Ö»ÄÜʵÏÖWindows NT 4 ÓòÖÐÓò¿ØÖÆÆ÷µÄÓÐÏÞ¹¦ÄÜ¡£ÓйØÉèÖÃÕâ¸ö¹¦ÄܵĸüÏêϸÐÅÏ¢²Î¼ûSamba ÎĵµÖеÄSamba-PDC-HOWTO¡£

ȱʡÉèÖÃ: domain logons = no

domain master (G)
Õâ¸öÑ¡Ïî¸æËßsmbd(8)ÊÕ¼¯¹ãÓòÍøÄÚµÄä¯ÀÀÁбí.ÉèÖÃÕâ¸öÑ¡Ïîºó,nmbdÓÃÒ»¸öÌض¨µÄNetBIOSÃûÏòËüµÄ¹¤×÷×é±êʶËü×Ô¼ºÊÇÒ»¸öÖ÷¿Øä¯ÀÀÆ÷.ÔÚͬһ¹¤×÷×鲻ͬ×ÓÍøÖеı¾µØÖ÷¿Øä¯ÀÀÆ÷½«°Ñ×Ô¼ºµÄä¯ÀÀÁÐ±í´«¸ønmbd,È»ºóÏòsmbd(8) ÇëÇóÕû¸öÍøÂçÉÏä¯ÀÀÁбíµÄÍêÕû¿½±´.¿Í»§¶Ë½«ºÍËûÃǵı¾µØÖ÷¿Øä¯ÀÀÆ÷ÁªÏµ,µÃµ½Õû¸öÓò·¶Î§ÄÚµÄä¯ÀÀÁбí,¶ø²»Ö»ÊÇ×ÓÍøÉϵÄÁбí.

×¢Òâ,windows NTÖ÷Óò¿ØÖÆÆ÷ĬÈÏÇé¿ö×ÜÊÇÕ¼ÓÐÕâ¸öÔÚ¹¤×÷×éÖеÄÌØÊâµÄNetBIOSÃû£¬Ðû³Æ×Ô¼ºÊǹ¤×÷×éµÄÖ÷Óòä¯ÀÀÆ÷(Ò²¾ÍÊÇ˵,ûÓÐʲô·½·¨¿ÉÒÔ×èÖ¹Ò»¸öWindows NTÖ÷Óò¿ØÖÆÆ÷ÕâÑù×ö). ÕâÑùÈç¹ûÉèÖÃÁËÕâ¸öÑ¡Ïî,²¢ÇÒnmbd ÔÚWindows NT֮ǰÏò¹¤×÷×éÐû³ÆÁËÕâ¸öÌØÊâµÄÃû×Ö,ÄÇô¿ç×ÓÍøµÄä¯ÀÀÐÐΪ»á±äµÃÆæ¹Ö,²¢ÇÒ¿ÉÄÜ»áʧ°Ü.

If domain logons = yes , then the default behavior is to enable the domain master Ñ¡Ïî¡£ If domain logons is not enabled (the default setting), then neither will domain master be enabled by default.

ȱʡÉèÖÃ: domain master = auto

dont descend (S)
ÓÐЩϵͳÉÏ´æÔÚijЩÌØÊâµÄ·¾¶(±ÈÈçlinuxÖеÄ/proc),ÕâЩĿ¼²»ÐèÒª(Ò²²»Ï£Íû)¿Í»§¶Ë¹ØÐÄ,ÉõÖÁ¿ÉÄܾßÓÐÎÞÏ޵IJã´ÎÉî¶È(µÝ¹éµÄ).Õâ¸öÑ¡ÏîÔÊÐíÄãÖ¸¶¨Ò»¸öÓɶººÅ·Ö¸ôµÄÁбí,·þÎñÆ÷½«°ÑÁбíÄÚ°üº¬µÄĿ¼ʼÖÕÏÔʾ³É¿ÕĿ¼.

×¢Òâ,Samba¶Ô'dont descend'Ñ¡ÏîµÄÊäÈë¸ñʽʮ·ÖÌôÌÞ.ÀýÈçËûÒ²ÐíÒªÇóÄãÊäÈë./proc¶ø²»Êǽö½öÊÇ/proc.ʵ¼ùÊÇ×îºÃµÄ²ßÂÔ.

ȱʡÉèÖÃ: none (Ò²¾ÍÊÇ˵,ËùÓÐĿ¼µÄÄÚÈÝ»áÕý³£µÄ´«µÝ¸ø¿Í»§¶Ë)

ʾÀý: dont descend = /proc,/dev

dos charset (G)
DOS SMB clients assume the server has the same charset as they do. This option specifies which charset Samba should talk to DOS clients.

The default depends on which charsets you have installed. Samba tries to use charset 850 but falls back to ASCII in case it is not available. Run testparm(1) to check the default on your system.

dos filemode (S)
The default behavior in Samba is to provide UNIX-like behavior where only the owner of a file/directory is able to change the permissions on it. However, this behavior is often confusing to DOS/Windows users. Enabling this parameter allows a user who has write access to the file (by whatever means) to modify the permissions on it. Note that a user belonging to the group owning the file will not be allowed to change permissions if the group is only granted read access. Ownership of the file/directory is not changed, only the permissions are modified.

ȱʡÉèÖÃ: dos filemode = no

dos filetime resolution (S)
ÔÚDOSºÍWindows FATÎļþϵͳÖÐ,ʱ¼äµÄ¼ÆÁ¿¾«¶ÈÊÇ2Ãë¡£¶Ô¹²Ïí×ÊÔ´ÉèÖÃÕâ¸öÑ¡Ïî,¿ÉÒÔʹµÃÔÚÒ»¸öÏòsmbd(8)µÄ²éѯÐèÒª1Ã뾫¶Èʱ£¬Samba°Ñ±¨¸æµÄʱ¼ä¾«¶È½µµÍµ½2Ãë×óÓÒ¡£

Õâ¸öÑ¡ÏîµÄÖ÷ÒªÓÃÓÚ½â¾öVisual C++ÓëSambaµÄ¼æÈÝÐÔÎÊÌâ.µ±¹²ÏíÎļþ±»Ëø¶¨Ê±(oplocksÑ¡Ïî±»ÉèÖÃΪÔÊÐí),Visual C++ʹÓÃÁ½¸ö²»Í¬µÄ¶Áȡʱ¼äµÄº¯Êýµ÷ÓÃÀ´¼ì²éÎļþ×Ô´Ó×îºóÒ»´Î¶Á²Ù×÷ÒÔÀ´ÊÇ·ñÓиıä.ÆäÖÐÒ»¸öº¯ÊýʹÓÃ1ÃëµÄʱ¼ä³ß¶È,¶øÁíÒ»¸öÔòʹÓÃ2ÃëµÄʱ¼ä³ß¶È.ÓÉÓÚʹÓûùÓÚ2ÃëµÄ·½·¨ÒªÉáÈ¥ÈκεÄÆæÊýÃë,µ±ÎļþµÄʱ¼ä¼Ç¼ÊÇÆæÊýÃëʱ,Visual C++µÄÁ½´Îº¯Êýµ÷Óýá¹û¾Í»á²»Ò»ÖÂ,Visual C++¾Í»á×ÜÊÇÈÏΪÎļþ±»¸Ä±ä.ÉèÖÃÕâ¸öÑ¡Ïî¿ÉÒÔʹµÃÁ½´Îº¯Êýµ÷ÓõĽá¹ûÒ»ÖÂ,Visual C++»áºÜ¸ßÐ˵ĽÓÊÜÕâÒ»ÇÐ.

ȱʡÉèÖÃ: dos filetime resolution = no

dos filetimes (S)
ÔÚDOSºÍWindows²Ù×÷ϵͳÖÐ,Èç¹ûÓû§¶ÔÎļþ½øÐÐд²Ù×÷,¾Í»á¸Ä±äÎļþµÄʱ¼ä¼Ç¼.¶øÔÚPOSIX¹æÔòÖÐ,Ö»ÓÐÎļþµÄËùÓÐÕߺÍroot²ÅÓиıäÎļþʱ¼ä¼Ç¼µÄÄÜÁ¦.ȱʡµÄ,Samba°´ÕÕPOSIX¹æÔòÔËÐÐ,Èç¹ûsmbdµÄÓû§²»ÊÇÎļþµÄËùÓÐÕß,ÄÇôËû¶ÔÎļþµÄ²Ù×÷²»»á¸Ä±äÎļþµÄʱ¼ä¼Ç¼.Èç¹ûÉèÖÃÕâ¸öÑ¡ÏîΪ yes,ÄÇôsmbd(8)¾Í°´ÕÕDOSµÄ¹æÔòÔËÐÐ,²¢ÇÒ°´ÕÕDOSϵͳµÄÒªÇó¸Ä±äÎļþµÄʱ¼ä¼Ç¼.

ȱʡÉèÖÃ: dos filetimes = no

enable rid algorithm (G)
This option is used to control whether or not smbd in Samba 3.0 should fallback to the algorithm used by Samba 2.2 to generate user and group RIDs. The longterm development goal is to remove the algorithmic mappings of RIDs altogether, but this has proved to be difficult. This parameter is mainly provided so that developers can turn the algorithm on and off and see what breaks. This parameter should not be disabled by non-developers because certain features in Samba will fail to work without it.

ȱʡÉèÖÃ: enable rid algorithm = <yes>

encrypt passwords (G)
Õâ¸ö²¼¶ûÐÍÖµ¿ØÖÆ×ÅÊÇ·ñÓë¿Í»§¶ËÓüÓÃÜ¿ÚÁî½øÐн»Ì¸.×¢Òâ,NT4.0 SP3 ¼°ÒÔÉÏ»¹ÓÐWINDOWS 98ÔÚȱʡÇé¿öÏÂʹÓüÓÃÜ¿ÚÁî½øÐн»Ì¸,³ý·Ç¸Ä±äÁË×¢²á±íµÄÏàÓ¦½¡Öµ.ÏëҪʹÓüÓÃÜ¿ÚÁî,Çå²ÎÔÄSamba HOWTO CollectionÖÐµÄ "User Database" Õ½ڡ£

ÏëҪʹ¼ÓÃÜ¿ÚÁîÄÜÕýÈ·µÄ¹¤×÷, smbd(8)±ØÐëÄÜ·ÃÎʱ¾µØµÄsmbpasswd(5)Îļþ(ÈçºÎÕýÈ·ÉèÖúÍά»¤Õâ¸öÎļþ,Çë²ÎÔÄsmbpasswd(8)ÊÖ²á),»òÕß,ÉèÖÃÑ¡Ïîsecurity= [server|domain|ads],ÕâÑùÉèÖý«Ê¹µÃsmbdÒÀÀµÆäËüµÄ·þÎñÆ÷À´°ïËü¼ø±ð¿ÚÁî.

ȱʡÉèÖÃ: encrypt passwords = yes

enhanced browsing (G)
This option enables a couple of enhancements to cross-subnet browse propagation that have been added in Samba but which are not standard in Microsoft implementations.

The first enhancement to browse propagation consists of a regular wildcard query to a Samba WINS server for all Domain Master Browsers, followed by a browse synchronization with each of the returned DMBs. The second enhancement consists of a regular randomised browse synchronization with all currently known DMBs.

You may wish to disable this option if you have a problem with empty workgroups not disappearing from browse lists. Due to the restrictions of the browse protocols these enhancements can cause a empty workgroup to stay around forever which can be annoying.

In general you should leave this option enabled as it makes cross-subnet browse propagation much more reliable.

ȱʡÉèÖÃ: enhanced browsing = yes

enumports command (G)
The concept of a "port" is fairly foreign to UNIX hosts. Under Windows NT/2000 print servers, a port is associated with a port monitor and generally takes the form of a local port (i.e. LPT1:, COM1:, FILE:) or a remote port (i.e. LPD Port Monitor, etc...). By default, Samba has only one port defined--"Samba Printer Port". Under Windows NT/2000, all printers must have a valid port name. If you wish to have a list of ports displayed (smbd does not use a port name for anything) other than the default "Samba Printer Port", you can define enumports command to point to a program which should generate a list of ports, one per line, to standard output. This listing will then be used in response to the level 1 and 2 EnumPorts() RPC.

ȱʡÉèÖÃ: no enumports command

ʾÀý: enumports command = /usr/bin/listports

exec (S)
Óë preexec ͬÒå¡£

fake directory create times (S)
NTFSºÍWindows VFATÎļþϵͳΪÿһ¸öÎļþºÍĿ¼±£ÁôÒ»¸ö´´½¨Ê±¼ä. Õâ¸öʱ¼äºÍUNIXϵÄ״̬¸Ä±äʱ¼ä--ctime²»Í¬. ËùÒÔ, ÔÚȱʡ״̬ÏÂ, Samba½«±¨¸æUNIXϵͳËù±£³ÖµÄ¸÷ÖÖʱ¼äÊôÐÔÖеÄ×îÔçµÄÄǸö×÷Ϊ(Îļþ/Ŀ¼)½¨Á¢Ê±¼ä. Èç¹ûÔÚÒ»¸ö¹²ÏíÖÐÉèÖÃÁËÕâ¸öÑ¡Ïî, ½«»áʹµÃSambaαÔìÒ»¸öĿ¼Éú³Éʱ¼ä, Õâ¸öʱ¼ä¾ÍÊÇ1980.01.01µÄÎçÒ¹.

Õâ¸öÑ¡ÏîµÄÖ÷ÒªÓÃÓÚ½â¾öVisual C++ÓëSambaµÄ¼æÈÝÐÔÎÊÌâ.Visual C++Éú³ÉmakefilesÎļþʱ, °üº¬Ä¿±êÎļþËùÒÀÀµµÄÄ¿µÄĿ¼. °üº¬½¨Á¢Ä¿Â¼µÄ¹æÔò. ͬÑùµÄ, µ±NMAKE±È½Ïʱ¼äÊôÐÔʱ, Ëü¼ì²éĿ¼½¨Á¢Ê±¼ä. Ä¿±êĿ¼²»´æÔڵĻ°, »á½¨Á¢Ò»¸ö£»Èç¹û´æÔÚ,ËüµÄ½¨Á¢Ê±¼ä×ÜÊDZÈËüËù°üº¬µÄÄ¿±êÎļþµÄ½¨Á¢Ê±¼äÔç.

UNIXµÄʱ¼ä¹æÔòÒâζ×ÅÖ»ÒªÓÐÎļþÔÚ¹²ÏíĿ¼Öн¨Á¢»òɾ³ý,Samba½«¸üйØÓÚ¸ÃĿ¼½¨Á¢Ê±¼äµÄ±¨¸æ. NMAKE½«·¢ÏÖĿ¼ÖгýÁË×îºó½¨Á¢µÄÎļþÒÔÍâµÄËùÓÐÄ¿±êÎļþ¶¼¹ýÆÚÁË(ÓëĿ¼µÄ½¨Á¢Ê±¼äÏà±È½Ï), È»ºóÖØбàÒëÄ¿±êÎļþ.ÉèÖÃÕâ¸öÑ¡ÏîÖµ½«±£Ö¤Ä¿Â¼µÄ½¨Á¢Ê±¼äÔçÓÚËüÀïÃæµÄÎļþ,NMAKE¾ÍÄܹ»Õý³£¹¤×÷.

ȱʡÉèÖÃ: fake directory create times = no

fake oplocks (S)
oplocksÊÇÕâÑùÒ»¸öÑ¡Ïî, ËüÔÊÐíSMB¿Í»§¶ËÔÚ±¾µØ»º´æ¶Ô·þÎñÆ÷µÄÎļþ²Ù×÷. Èç¹û·þÎñÆ÷ÔÊÐíoplock(opportunistic lock)²Ù×÷, ¿Í»§¶Ë¿ÉÒÔ¼òµ¥µÄÈÏΪ, Ëü×Ô¼ºÊÇΨһµÄÎļþ·ÃÎÊÕß, ¿ÉÒÔËæÒâµÄ»º´æÎļþ. ÓÐЩoplocksÀàÐÍÉõÖÁÔÊÐí»º´æÎļþµÄ´ò¿ªºÍ¹Ø±Õ²Ù×÷. Õâ¸ö²Ù×÷»»À´ÐÔÄÜÉϵľ޴óÌáÉý.

µ±ÄãÉèÖÃfake oplocks = yesºó,smbd(8)×ÜÊÇÔÊÐíoplockÇëÇó, ¶ø²»¹Üµ½µ×ÓжàÉٵĿͻ§¶ËÔÚʹÓÃÕâ¸öÎļþ.

ÔÚͨ³£Çé¿öÏÂ, ʹÓÃÕæʵµÄoplocksÖ§³Ö×ÜÊDZÈʹÓÃÕâ¸öÑ¡ÏîºÃ.

Èç¹ûÄãʹÓÃÕâ¸öÑ¡ÏîÔÚһЩֻ¶ÁµÄ¹²ÏíÉÏ(ÀýÈç: CDROM¹²Ïí),»òÕßÄãÖªµÀÕâ¸ö¹²ÏíÖ»Äܹ»±»Ò»¸ö¿Í»§¶ËËù·ÃÎÊ(ÀýÈç: ¿Í»§Ö÷Ŀ¼). Ä㽫»á×¢Òâµ½ÐÔÄÜÉϵÄÖØ´óÌáÉý. Èç¹ûÄ㽫Õâ¸öÑ¡ÏîÓÃÔÚ¶à¸ö¿Í»§¶Ë¶¼¿ÉÒÔ¶ÁдµÄ¹²ÏíÉÏ, ÓÉÓÚ¿Í»§¿ÉÄÜͬʱ·ÃÎÊÒ»¸ö¹²ÏíÎļþ, ÕâÑù»áÔì³ÉÎļþËð»µ. ÇëÒ»¶¨Ð¡ÐÄʹÓÃ.

ȱʡÉèÖÃ: fake oplocks = no

follow symlinks (S)
Õâ¸öÑ¡ÏîÔÊÐíSamba¹ÜÀíÔ±½ûֹij¸öÌØÊâ¹²ÏíÏÂsmbd(8)¶Ô·ûºÅÁ´½ÓµÄ·ÃÎÊ. ½«Õâ¸öÑ¡ÏîÉèÖÃΪno½«»á×èÖ¹Õâ¸ö¹²ÏíϵÄÈκÎÁ´½ÓÐÎʽµÄÎļþ»òĿ¼±»²é¿´(Óû§½«»áµÃµ½Ò»¸ö´íÎóÐÅÏ¢).ÀýÈç: Õâ¸öÑ¡Ï×èÖ¹¿Í»§½«/etc/passwdÎļþÁ´½Óµ½×Ô¼ºµÄÖ÷Ŀ¼. (ÎÒÃÇ¿´µ½, ÕâÊǺÜÓÐÓõÄ). µ«ÊÇ, Ëü½«»áʹÎļþÃû×ֵIJéÕÒËÙ¶ÈÂýһЩ.

Õâ¸öÑ¡ÏîȱʡÊÇÔÊÐí(Ò²¾ÍÊÇ, smbd½«ÔÊÐí·ÃÎÊ·ûºÅÁ´½Ó)

ȱʡÉèÖÃ: follow symlinks = yes

force create mode (S)
Õâ¸öÑ¡ÏîÉèÖÃÒ»×éUNIX¸ñʽµÄȨÏÞ´úÂë, µ±Samba½¨Á¢ÐÂÎĵµµÄʱºò, ×ÜÊÇ»áʹÓÃÕâ¸öȨÏÞÉèÖÃÐÂÎĵµ, ͨ¹ý½«ÐÂÎĵµµÄȨÏÞλºÍÕâ×éȨÏÞ´úÂë×öÖðλÓë, ¾ÍÍê³ÉÁËÉèÖù¤×÷.ȱʡ״̬ÏÂ, Õâ¸öÑ¡ÏîÉèÖÃΪ°Ë½øÖÆ000,ÔÚcreate mask¼Óµ½Ð½¨Á¢µÄÎļþµÄȨÏÞλÉϺó, ÓëÕâ¸öÖµ½øÐа´Î»Óë²Ù×÷, ¾ÍµÃµ½Îļþ½¨Á¢Ê±µÄȨÏÞÉèÖÃ.

²Î¼û create mask À´»ñµÃ¹ØÓÚ½¨Á¢ÎļþʱµÄÑÚÂëµÄÏêϸ×ÊÁÏ¡£

ÁíÍâÒ²²Î¼û inherit permissions ²ÎÊý.

ȱʡÉèÖÃ: force create mode = 000

ʾÀý: force create mode = 0755

Õâ¸öÀý×ÓÖÐ, ½«ÆÈʹËùÓб»½¨Á¢µÄÎĵµ¶Ô"ͬ×é/ÆäËü(Óû§)"ÓжÁºÍÖ´ÐÐȨ. ¶ÔÓû§×Ô¼ºÓжÁ/д/Ö´ÐÐȨÁ¦.

force directory mode (S)
Õâ¸öÑ¡ÏîÉèÖÃÒ»×éUNIX¸ñʽµÄȨÏÞ´úÂë, µ±Samba½¨Á¢ÐÂĿ¼µÄʱºò, ×ÜÊÇ»áʹÓÃÕâ¸öȨÏÞÉèÖÃÐÂĿ¼, ͨ¹ý½«ÐÂĿ¼µÄȨÏÞλºÍÕâ×éȨÏÞ´úÂë×öÖðλÓë, ¾ÍÍê³ÉÁËÉèÖù¤×÷.ȱʡ״̬ÏÂ, Õâ¸öÑ¡ÏîÉèÖÃΪ°Ë½øÖÆ000,ÔÚdirectory mask¼Óµ½Ð½¨Á¢µÄĿ¼µÄȨÏÞλÉϺó,ÓëÕâ¸öÖµ½øÐа´Î»Óë²Ù×÷, ¾ÍµÃµ½Ä¿Â¼½¨Á¢Ê±µÄȨÏÞÉèÖÃ.

²Î¼û directory mask À´»ñµÃ¹ØÓÚ½¨Á¢Ä¿Â¼Ê±µÄÑÚÂëµÄÏêϸ×ÊÁÏ¡£

ÁíÍâÒ²²Î¼û inherit permissions²ÎÊý.

ȱʡÉèÖÃ: force directory mode = 000

ʾÀý: force directory mode = 0755

Õâ¸öÀý×ÓÖÐ, ½«ÆÈʹËùÓб»½¨Á¢µÄĿ¼¶Ô"ͬ×é/ÆäËü(Óû§)"ÓжÁºÍ½øÈëȨ. ¶ÔÓû§×Ô¼ºÓжÁ/д/½øÈëȨÁ¦.

force directory security mode (S)
´ËÑ¡Ïî¿ØÖÆNTÓû§Í¨¹ý±¾µØNT°²È«¶Ô»°¿ò¿ÉÒÔ²Ù×÷ÄÄЩĿ¼ÉϵÄunixȨÏÞλ.

´ËÑ¡ÏîÒÔÑÚÂë('or')À´ÊµÏÖȨÏÞλµÄ¸Ä±ä,ËùÒÔËüÇ¿ÖÆÁËÈκÎÑÚÂëÖÐÓû§¿ÉÒÔ¸ü¸ÄµÄλ.ʵ¼ÊÉÏ,µ±ÔÚÐÞ¸ÄĿ¼µÄ°²È«ÐÔʱ,Õâ¸öÑÚÂëÖеÄÒ»¸ö0λ¿ÉÒÔ×÷Ϊһ×éÓû§ÒѾ­ÉèΪ'on'µÄλÀ´¿´´ý.

Èç¹ûûÓÐÃ÷È·É趨µÄ»°,Õâ¸öÑ¡Ïî»áÓÃÓëforce directory modeÑ¡ÏîͬÑùµÄÖµ.ÒªÔÊÐíÓû§ÔÚĿ¼ÖпÉÒÔÐÞ¸ÄËùÓеÄuser/group/worldȨÏÞ,¿ÉÒÔ°ÑÕâ¸öÑ¡ÏîÉèΪ0000.

×¢Òâ,ÄÜ·ÃÎÊsamba·þÎñÆ÷µÄÓû§Í¨¹ýÆäËü·½·¨Ò²¿ÉÒÔºÜÈÝÒ×µØÈƹýÕâ¸öÏÞÖÆ,ËùÒÔÕâ¸ö²ÎÊýÖ»¶Ô¶ÀÁ¢¹¤×÷µÄÓ¦ÓÃϵͳÀ´ËµÓÐÓÃ.ºÜ¶àϵͳ¹ÜÀíµÄ¹ÜÀíÔ±¶¼»á°ÑËüÉèΪĬÈϵÄ0000.

²Î¼û directory security mask, security mask, force security mode ²ÎÊý¡£

ȱʡÉèÖÃ: force directory security mode = 0

ʾÀý: force directory security mode = 700

force group (S)
Õâ¸öÑ¡ÏîÖ¸¶¨Ò»¸öUNIX×é, ËùÓÐÁ¬½Óµ½·þÎñÉϵÄÓû§¶¼±»Ç¿ÆÈʹÓÃÕâ¸ö×é×÷Ϊ"Ö÷×é". ËùÓзÃÎÊÎļþµÄÓû§¶¼Ê¹ÓÃÕâ¸ö×éµÄ·ÃÎÊȨÏÞ×öȨÏÞ¼ì²é. Òò´Ë, ͨ¹ý·ÖÅäÎļþºÍĿ¼µÄ·ÃÎÊȨÏÞ¸øÕâ¸öÓû§×é, SambaµÄ¹ÜÀíÔ±¿ÉÒÔÏÞÖÆ»òÔÊÐí¶Ô¹²ÏíÎļþµÄ·ÃÎÊ.

ÔÚsamba 2.0.5¼°¸üеİ汾ÖÐÕâ¸öÑ¡ÏîÒѾ­°´ÏÂÃæµÄ·½·¨ÓÐÁËһЩÀ©Õ¹¹¦ÄÜ.Èç¹ûÔÚ´ËÁгöµÄ×éÃûÓÐÒ»¸ö'+'×Ö·û¼ÓÔÚÃû³ÆÇ°µÄ»°,µ±Ç°Óû§ÕýÔÚ·ÃÎʵĹ²Ïí×ÊÔ´Ö»Óгõʼ×鱻ȱʡ·ÖÅäµ½Õâ¸ö×éÖÐ,¶ø¿ÉÄܵÄÇé¿öÊÇÓû§ÒѾ­ÊÇÆäËü×é³ÉÔ±ÁË.ÕâÑù,¹ÜÀíÔ±¿ÉÒÔ¾ö¶¨Ö»ÓÐÔÚÌØÊâ×éÀïµÄÓû§²ÅÄÜÒÔÉ趨µÄ×éÉí·Ý½¨Á¢Îļþ,¸üÓÐÒæÓÚËùÓÐȨ·ÖÅä¹ÜÀí.ÀýÈç,É趨force group = +sysµÄ»°,Ö»ÓÐÔÚsys×éÀïµÄÓû§²ÅÄÜÔÚ·ÃÎÊsamba¹²Ïí×ÊԴʱӵÓÐȱʡµÄ³õʼ×é±êʶ.¶øÆäËüËùÓÐÓû§±£ÁôËûÃÇԭʼµÄ×é±êʶ.

Èç¹ûÓÖÉ趨ÁË force userÑ¡ÏîµÄ»°,force groupÑ¡ÏîÖÐÖ¸¶¨µÄ×齫»áÔ½¹ýÔÚ force userÖÐÖ¸¶¨µÄ³õʼ×é. If the force user parameter is also set the group specified in force group will override the primary group set in force user.

²Î¼û force userÑ¡Ïî.

ȱʡÉèÖÃ: no forced group

ʾÀý: force group = agroup

force security mode (S)
´ËÑ¡Ïî¿ØÖÆNTÓû§Í¨¹ý±¾µØNT°²È«¶Ô»°¿ò¿ÉÒÔ²Ù×÷ÄÄЩĿ¼ÉϵÄunixȨÏÞλ.

´ËÑ¡ÏîÒÔÑÚÂë('or')À´ÊµÏÖȨÏÞλµÄ¸Ä±ä,ËùÒÔËüÇ¿ÖÆÁËÈκÎÑÚÂëÖÐÓû§¿ÉÒÔ¸ü¸ÄµÄλ.ʵ¼ÊÉÏ,µ±ÔÚÐÞ¸ÄĿ¼µÄ°²È«ÐÔʱ,Õâ¸öÑÚÂëÖеÄÒ»¸ö0λ¿ÉÒÔ×÷Ϊһ×éÓû§ÒѾ­ÉèΪ'on'µÄλÀ´¿´´ý.

Èç¹ûûÓÐÃ÷È·É趨µÄ»°,Õâ¸öÑ¡Ïî»áÓÃÓëforce create modeÑ¡ÏîͬÑùµÄÖµ.ÒªÔÊÐíÓû§ÔÚÎļþÉÏ¿ÉÒÔÐÞ¸ÄËùÓеÄuser/group/worldȨÏÞ,¿ÉÒÔ°ÑÕâ¸öÑ¡ÏîÉèΪ000.

×¢Òâ,ÄÜ·ÃÎÊsamba·þÎñÆ÷µÄÓû§Í¨¹ýÆäËü·½·¨¿ÉÒÔºÜÈÝÒ×µØÈƹýÕâ¸öÏÞÖÆ,ËùÒÔÕâ¸öÑ¡Ïî¶Ô¶ÀÁ¢¹¤×÷µÄϵͳÀ´Ëµ²ÅÓÐÓõÄ.ºÜ¶àϵͳ¹ÜÀíµÄ¹ÜÀíÔ±¶¼»á°ÑËüÉèΪĬÈϵÄ0000.

²Î¼û force directory security mode, directory security mask, security mask ²ÎÊý¡£

ȱʡÉèÖÃ: force security mode = 0

ʾÀý: force security mode = 700

force user (S)
Õâ¸öÑ¡ÏîÖ¸¶¨Ò»¸öUNIXÓû§µÄÃû×Ö, ËùÓÐÁ¬½Óµ½·þÎñÉϵÄÓû§µÄȱʡÃû×Ö¾ÍʹÓÃÕâ¸öÃû×Ö. (ÓÉÓÚȨÏÞµÄÔ­Òò)ÔÚ¹²ÏíÎļþʱÕâ¸öÑ¡ÏîÊÇÓÐÓõÄ.Äã±ØÐëСÐÄʹÓÃÕâ¸öÑ¡Ïî, ËüÓпÉÄÜ´øÀ´°²È«ÉϵÄÎÊÌâ.

Õâ¸öÑ¡ÏîÖ»Óе±Ò»¸öÁ¬½Ó½¨Á¢ÆðÀ´ºó²ÅÓÐÓÃ. ÔÚ½¨Á¢Á¬½ÓµÄʹÓÃ, Óû§»¹ÊDZØÐëÓкϷ¨µÄÓû§ÃûºÍ¿ÚÁî. Ò»µ©Á¬½Ó½¨Á¢ÆðÀ´, ËùÓеIJÙ×÷½«Ç¿ÆÈÒÔÕâ¸öÃû×Ö½øÐÐ, ¶ø²»¹ÜËüÊÇÒÔʲôÃû×ֵǼµÄ.

samba 2.0.5ºÍ¸üеİ汾ÖÐÕâ¸öÑ¡Ïî»áµ¼ÖÂÓû§µÄ³õʼ×é±»×÷ΪËùÓÐÎļþ²Ù×÷µÄ³õʼ×é.2.0.5ÒÔÇ°µÄ³õʼ×é±»ÔÊÐí×÷ΪÁª½ÓÓû§µÄ³õʼ×é(ÕâÊǸöbug)

²Î¼û force group Ñ¡Ïî¡£

ȱʡÉèÖÃ: no forced user

ʾÀý: force user = auser

fstype (S)
Õâ¸öÑ¡ÏîÔÊÐí¹ÜÀíÔ±ÉèÖÃÒ»¸ö×Ö·û´®ËµÃ÷¹²ÏíµÄÎļþϵͳµÄÀàÐÍ, µ±¿Í»§¶ËÓвéѯʱ, smbd(8)½«Õâ¸ö×Ö·û´®×÷ΪÕýÔÚʹÓõÄÎļþϵͳµÄÀàÐͱ¨¸æ¸ø¿Í»§¶Ë. ΪÁ˺ÍWindows NT¼æÈÝȱʡֵÉèÖÃÊÇNTFS, µ±È»,Èç¹û±ØÒªµÄ»°,Ò²¿ÉÒԸıäΪÆäËüµÄ×Ö·û´®,ÀýÈçSamba»òFAT.

ȱʡÉèÖÃ: fstype = NTFS

ʾÀý: fstype = Samba

get quota command (G)
The get quota command should only be used whenever there is no operating system API available from the OS that samba can use.

This parameter should specify the path to a script that queries the quota information for the specified user/group for the partition that the specified directory is on.

Such a script should take 3 arguments:

directory

type of query

uid of user or gid of group

The type of query can be one of :

1 - user quotas

2 - user default quotas (uid = -1)

3 - group quotas

4 - group default quotas (gid = -1)

This script should print its output according to the following format:

Line 1 - quota flags (0 = no quotas, 1 = quotas enabled, 2 = quotas enabled and enforced)

Line 2 - number of currently used blocks

Line 3 - the softlimit number of blocks

Line 4 - the hardlimit number of blocks

Line 5 - currently used number of inodes

Line 6 - the softlimit number of inodes

Line 7 - the hardlimit number of inodes

Line 8(optional) - the number of bytes in a block(default is 1024)

²Î¼û set quota command Ñ¡Ïî¡£

ȱʡÉèÖÃ: get quota command =

ʾÀý: get quota command = /usr/local/sbin/query_quota

getwd cache (G)
ÕâÊÇÒ»¸öÐÔÄܵ÷½ÚÑ¡Ïî. µ±Õâ¸öÑ¡ÏîÔÊÐíʱ, Ò»¸ö¸ßËÙ»º³åËã·¨½«±»ÓÃÀ´¼õÉÙµ÷ÓÃ"getwd()"µÄʱ¼ä. Õâ¸öÑ¡Ïî¶ÔÐÔÄÜ»á²úÉúºÜ´óµÄÓ°Ïì, ÌرðÊÇÔÚwide linksÑ¡ÏîÉèΪnoµÄʱºò.

ȱʡÉèÖÃ: getwd cache = yes

group (S)
Óë force group ͬÒå¡£

guest account (G,S)
ÕâÊÇÒ»¸öÓÃÀ´·ÃÎÊ·þÎñµÄÓû§Ãû(×÷Ϊ¿Í»§À´·ÃÕË»§,Çø±ðÓÚϵͳÉϵÄÓû§), µ±È», ±»·ÃÎʵķþÎñ±ØÐëÏÈÉèÖÃÁËÑ¡ÏîfI guest ok. Õâ¸öÕË»§ËùÓµÓеÄËùÓÐȨÀû¶¼»á·´Ó³µ½ÒÔ"·ÃÎÊ¿Í»§(guest)"Éí·ÝÁ¬½Ó½øÀ´µÄ¿Í»§ÉíÉÏ. µäÐ͵Ä, Õâ¸ö¿Í»§±ØÐëÔÚpasswdÎļþÖдæÔÚ, µ«ÊÇûÓÐÓÐЧµÄµÇ¼ȨÏÞ.ͨ³£ÏµÍ³ÖдæÔÚ×ÅÃûΪ"ftp"µÄÕË»§,°ÑÕâ¸öÕË»§ÃûʹÓÃÔÚÕâÀïÊǸöºÃÖ÷Òâ.×¢Òâ:Èç¹ûÒ»¸ö·þÎñÖ¸¶¨ÁËÒ»¸öרÓõķÃÎÊÓû§Ãû,Õâ¸öרÓÃÃû½«´úÌæÕâÀïµÄÓû§Ãû.

ÔÚijЩϵͳÉÏ,ȱʡµÄ·ÃÎÊÓû§Ãû"nobody"ÕË»§¿ÉÄܲ»ÄÜ´òÓ¡.Èç¹ûÓöµ½ÕâÖÖÇé¿ö,ÇëʹÓÃÆäËüµÄÕË»§Ãû(ÀýÈçftp)¡£ÏëÒª²âÊÔÕâÖÖÇé¿ö,¿ÉÒÔÊÔ×ÅÓÃÀ´·ÃÕË»§µÇ¼(¿ÉÒÔÓÃsu -ÃüÁî),È»ºó,ʹÓÃϵͳ´òÓ¡ÃüÁîlpr(1)»òlp(1).

Õâ¸ö²ÎÊý²»½ÓÊÜ%ºê£¬ÒòΪSambaϵͳµÄºÜ¶à×é¼þÒªÕýÈ·¹¤×÷¶¼ÐèÒªÕâ¸öÖµÊÇÒ»¸ö³£Á¿¡£

ȱʡÉèÖÃ: ±àÒëʱָ¶¨£¬Í¨³£ÊÇ"nobody"

ʾÀý: guest account = ftp

guest ok (S)
Èç¹ûÒ»¸ö·þÎñµÄÕâ¸öÑ¡ÏîµÄÖµÉèΪyes, ÄÇÄ©, Á¬½Óµ½Õâ¸ö·þÎñ²»ÐèÒª¿ÚÁî, ȨÏÞÉèÖÃΪ guest accountµÄȨÏÞ.

Õâ¸öÑ¡ÏîµÖÏûÁËÉèÖà restrict anonymous = 2 µÄºÃ´¦¡£

²Î¼ûÏÂÃæµÄ securityÀ´»ñµÃ¸ü¶àÐÅÏ¢¡£

ȱʡÉèÖÃ: guest ok = no

guest only (S)
Èç¹ûÒ»¸ö·þÎñµÄÕâ¸öÑ¡ÏîÉèÖÃΪ yes, ÄÇÄ©, Ö»Óпͻ§(guest)·ÃÎʱ»ÔÊÐí, Ò²¾ÍÊÇ˵, ²»ÔÊÐíÒÔÆäËûÓû§µÄÉí·Ý·ÃÎÊ.Èç¹ûûÓÐÉèÖÃguest okÑ¡Ïî, Ôò´ËÑ¡ÏîÎÞЧ.

²Î¼ûÏÂÃæµÄ security ²ÎÊýÀ´»ñµÃ¸ü¶àÐÅÏ¢¡£

ȱʡÉèÖÃ: guest only = no

hide dot files (S)
ÕâÊÇÒ»¸ö²¼¶ûֵѡÏî. ¿ØÖÆÎļþÃû×îÇ°ÃæÒ»¸ö×Ö·ûΪ"."µÄÎļþÊÇ·ñ±íÏÖΪÒþº¬Îļþ(UNIXÎļþϵͳÖÐ, ×îÇ°ÃæΪ"."µÄÎļþÊÇÒþº¬Îļþ).

ȱʡÉèÖÃ: hide dot files = yes

hide files (S)
ÕâÊÇÒ»¸öÒþ²ØÎļþ»òĿ¼µÄÁбí.ÕâЩÎļþ²»Äܱ»¿´¼ûµ«ÊÇÄܱ»·ÃÎÊ.ÁбíÖеÄÎļþ»òĿ¼½«±»¸³ÓèDOSϵÄ"Òþ²Ø"ÊôÐÔ.

ÿ¸öÌõÄ¿±ØÐëÒÔ"/"·Ö¸ôÒÔ±ãÔÊÐíÔÚÌõÄ¿ÖÐʹÓÿոñ.¿ÉÒÔʹÓÃDOS·ç¸ñµÄͨÅä·û"*"ºÍ"?"Æ¥Åä¶à¸öĿ¼ºÍÎļþ¡£

ÿһ¸öÌõÄ¿±ØÐëʹÓÃUNIX¸ñʽµÄ·¾¶,¶ø²»ÊÇDOS¸ñʽµÄ·¾¶,ͬʱ,²»ÄÜ°üº¬UNIX·¾¶·Ö¸ô·û"/".

×¢Òâ:´óСдÃô¸ÐµÄÌØÐÔÒ²ÊÊÓÃÓÚÒþº¬Îļþ.

ÉèÖÃÕâ¸öÑ¡Ïî»áÓ°ÏìSambaµÄÐÔÄÜ,Ëü»áÆÈʹϵͳ¼ì²éËùÓеÄÎļþºÍĿ¼ÒÔÈ·¶¨ÊÇ·ñÓëËüµÄËùҪѰÕÒµÄÏîÄ¿Æ¥Åä.

²Î¼û hide dot files, veto files ºÍ case sensitive.

ȱʡÉèÖÃ: ûÓÐÒþ²ØÎļþ

ʾÀý: hide files = /.*/DesktopFolderDB/TrashFor%m/resource.frk/

ÉÏÃæµÄÀý×ÓÖеÄÎļþ´ÓThursby¹²Ïí³öÀ´,¸øMacintoshµÄSMB¿Í»§¶Ë(DAVE),¹©ÄÚ²¿Ê¹ÓÃ,ÈÔÈ»Òþ²ØÁË"."´òÍ·µÄÎļþ.

hide local users (G)
This parameter toggles the hiding of local UNIX users (root, wheel, floppy, etc) from remote clients.

ȱʡÉèÖÃ: hide local users = no

hide special files (S)
This parameter prevents clients from seeing special files such as sockets, devices and fifo's in directory listings.

ȱʡÉèÖÃ: hide special files = no

hide unreadable (S)
This parameter prevents clients from seeing the existance of files that cannot be read. Defaults to off.

ȱʡÉèÖÃ: hide unreadable = no

hide unwriteable files (S)
This parameter prevents clients from seeing the existance of files that cannot be written to. Defaults to off. Note that unwriteable directories are shown as usual.

ȱʡÉèÖÃ: hide unwriteable = no

homedir map (G)
Èç¹ûnis homedir Ñ¡ÏîµÄֵΪyes,ͬʱ, smbd(8)Ò²×÷Ϊwin95/98µÄµÇ¼·þÎñÆ÷,ÄÇô,Õâ¸öÑ¡ÏîÖ¸Ã÷Ò»¸öNIS(»òÕßYP)Ó³Éä.Ö¸ÏòÓû§Ö÷Ŀ¼ËùÔڵķþÎñÆ÷.Ä¿Ç°,Ö»ÈÏʶSunµÄauto.homeÓ³Éä¸ñʽ.Ó³Éä¸ñʽÈçÏÂ:

username server:/some/file/system

³ÌÐò´Ó":"ºÅÇ°È¡µÃ·þÎñÆ÷Ãû×Ö.½«À´Ò²Ðí»áÓиüºÃµÄ½âÊÍϵͳÀ´´¦Àí²»Í¬µÄÓ³Éä¸ñʽ,µ±È»,Ò²°üÀ¨Amd(ÁíÒ»ÖÖ×Ô¶¯×°ÔØ·½Ê½)Ó³Éä.

ÐèҪϵͳÖÐÓÐÒ»¸öÔËÐеÄNIS¿Í»§À´Ê¹Õâ¸öÑ¡Ï×÷¡£

²Î¼û nis homedir , domain logons .

ȱʡÉèÖÃ: homedir map = <¿Õ×Ö·û´®>

ʾÀý: homedir map = amd.homedir

host msdfs (G)
If set to yes, Samba will act as a Dfs server, and allow Dfs-aware clients to browse Dfs trees hosted on the server.

²Î¼û msdfs root share level Ñ¡Ïî¡£ For more information on setting up a Dfs tree on Samba, refer to ???.

ȱʡÉèÖÃ: host msdfs = no

hostname lookups (G)
Specifies whether samba should use (expensive) hostname lookups or use the ip addresses instead. An example place where hostname lookups are currently used is when checking the hosts deny and hosts allow.

ȱʡÉèÖÃ: hostname lookups = yes

ʾÀý: hostname lookups = no

hosts allow (S)
Óëallow hosts ͬÒå.

Õâ¸öÑ¡ÏîÊÇÒ»¸öÓɶººÅ,¿Õ¸ñ»òÕßtab×Ö·û¸ô¿ªµÄÒ»×éÖ÷»úÃû.ÁÐÈëÆäÖеÄÖ÷»ú²ÅÔÊÐí·ÃÎÊ.

Èç¹û¸ÃÑ¡Ïî³öÏÖÔÚ[global]¶ÎÖÐ,Ëü»á×÷ÓÃÓÚËùÓзþÎñ¶øºöÂÔµ¥¸ö·þÎñËù×÷µÄ²»Í¬ÉèÖÃ.

Äã¿ÉÒÔÓÃipµØÖ·»òÖ÷»úÃûÀ´Ö¸¶¨Ö÷»ú.±ÈÈç,Äã¿ÉÒÔÓÃÀàËÆ allow hosts = 150.203.5. À´ÏÞ¶¨Ö»ÔÊÐí·ÃÎÊÔÚÕâ¸öcÀà×ÓÍøÖеÄÖ÷»ú.hosts_access(5)ÖÐÏêϸÃèÊöÁ˹ØÓÚÕâ¸öÑ¡ÏîÉèÖõÄÍêÕûÓï·¨.×¢Òâµ½ÄãµÄϵͳÖÐÒ²ÐíûÓÐÕâ¸ö²Î¿¼ÊÖ²á,ÕâÀïÒ²×÷Ò»¸ö¼òµ¥µÄ˵Ã÷.

×¢Ò⣬±¾»úµØÖ·127.0.0.1 ×ÜÊÇÔÊÐíÁ¬½Ó,³ý·ÇÔÚhosts deny Ñ¡ÏîÖмÓÒÔ½ûÖ¹.

ÄãÒ²¿ÉÒÔʹÓÃ×ÓÍøºÅ/×ÓÍøÑÚÂë¶ÔÀ´Ö¸¶¨Ö÷»ú.Èç¹ûÄãµÄÍøÂçÖ§³ÖÍøÂç×é,Ä㻹¿ÉÒÔÓÃÍøÂç×éÃûÀ´Ö¸¶¨×éÄÚµÄÖ÷»ú.EXCEPT(³ýÁË...)¹Ø¼ü×Ö¿ÉÒÔÔÚʹÓÃÁËͨÅä·ûµÄÇé¿öÏÂÆðµ½ÏÞ¶¨×÷ÓÃ.

Example 1: ÔÊÐí150.203.*.* ÖгýÁËһ̨»úÆ÷Ö®ÍâµÄËùÓÐIP·ÃÎÊ

hosts allow = 150.203. EXCEPT 150.203.6.66

Example 2: ÔÊÐíÂú×ã¸ø¶¨µÄ×ÓÍøºÅ/×ÓÍøÑÚÂëµÄIP·ÃÎÊ

hosts allow = 150.203.15.0/255.255.255.0

Example 3: ÔÊÐíһϵÁÐÖ÷»ú·ÃÎÊ

hosts allow = lapland, arvidsjaur

Example 4: ÔÊÐíNISÍøÂç×é"foonet"·ÃÎÊ,µ«ÊǽûÖ¹ÆäÖеÄһ̨Ö÷»ú

hosts allow = @foonet

hosts deny = pirate

×¢Òâ,·ÃÎÊʱ»¹ÊÇÐèÒªÓÐÊʵ±µÄÓû§¼¶¿ÚÁî.

²Î¼ûtestparm(1) À´¼ì²âÖ÷»úÊÇ·ñ¿ÉÒÔ°´ÕÕÄãÏ£ÍûµÄ·½Ê½±»·ÃÎÊ.

ȱʡÉèÖÃ: none (Ò²¾ÍÊÇ˵,ËùÓлúÆ÷¶¼¿ÉÒÔ·ÃÎÊ)

ʾÀý: allow hosts = 150.203.5. myhost.mynet.edu.au

hosts deny (S)
hosts allowÑ¡ÏîµÄ·´Òå´Ê.ËùÓб»ÁÐÈëÕâ¸öÑ¡ÏîÖеÄÖ÷»úµÄ·þÎñ¶¼²»ÔÊÐí±»·ÃÎÊ,³ý·ÇÕâ¸ö±»·ÃÎʵķþÎñ¶¨ÒåÁË×Ô¼ºµÄÔÊÐíÁбí.µ±ÔÊÐíµÄÖ÷»úÁбíºÍ½ûÖ¹µÄÖ÷»úÁÐ±í·¢Éú³åÍ»µÄʱºò,allowÓÅÏÈ.

ȱʡÉèÖÃ: none (ûÓнûÖ¹·ÃÎʵÄÖ÷»ú)

ʾÀý: hosts deny = 150.203.4. badhost.mynet.edu.au

hosts equiv (G)
Èç¹ûÕâ¸öÑ¡ÏîÖµ²»ÊÇ¿Õ×Ö·û´®,¾ÍÖ¸¶¨ÁËÒ»¸öÎļþÃû.Õâ¸öÎļþÖÐÁгöÁË¿ÉÒÔ²»ÓÿÚÁî¾ÍÔÊÐí·ÃÎʵÄÖ÷»úºÍÓû§µÄÃû×Ö.

²»Òª°ÑÕâ¸öÑ¡ÏîºÍhosts allow ¸ã»ìÁË,ÄÇÊǹØÓÚ¿ØÖÆÖ÷»ú¶Ô·þÎñµÄ·ÃÎʵÄ,ÓÃÓÚ¹ÜÀí¶ÔÀ´·ÃÕߵķþÎñ.¶ø hosts equivÊÇÓÃÓÚÖ§³ÖÄÇЩ²»¶ÔsambaÌṩ¿ÚÁîµÄNT¿Í»§µÄ.

×¢Òâ:ʹÓÃhosts equiv ¿ÉÄÜ»á³ÉΪһ¸öºÜ´óµÄ°²È«Â©¶´.ÕâÊÇÒòΪÄãÏàÐÅ·¢Æð·ÃÎʵÄPCÌṩÁËÕýÈ·µÄÓû§Ãû.ÕÒһ̨PCÀ´Ìṩһ¸ö¼ÙµÄÓû§ÃûÊǺÜÈÝÒ×µÄ.ÎÒ½¨ÒéÄãÖ»ÓÐÔÚÍêÈ«Ã÷°×ÄãÔÚ¸ÉʲôµÄÇé¿öϲÅʹÓÃhosts equivÑ¡Ïî,»òÕßÔÚÄã×Ô¼ºµÄ¼ÒÀï(ÄÇÀïÓÐÄã¿ÉÒÔÍêÈ«ÐÅÈεÄÅäżºÍº¢×Ó)ʹÓÃËü.½ö½öÊÇÔÚÄãÍêÈ«¿ÉÒÔÐÅÈÎËûÃǵÄʱºò²ÅÓà :-)

ȱʡÉèÖÃ: no host equivalences

ʾÀý: hosts equiv = /etc/hosts.equiv

idmap backend (G)
The purpose of the idmap backend parameter is to allow idmap to NOT use the local idmap tdb file to obtain SID to UID / GID mappings, but instead to obtain them from a common LDAP backend. This way all domain members and controllers will have the same UID and GID to SID mappings. This avoids the risk of UID / GID inconsistencies across UNIX / Linux systems that are sharing information over protocols other than SMB/CIFS (ie: NFS).

ȱʡÉèÖÃ: idmap backend = <¿Õ×Ö·û´®>

ʾÀý: idmap backend = ldap:ldap://ldapslave.example.com

idmap gid (G)
The idmap gid parameter specifies the range of group ids that are allocated for the purpose of mapping UNX groups to NT group SIDs. This range of group ids should have no existing local or NIS groups within it as strange conflicts can occur otherwise.

The availability of an idmap gid range is essential for correct operation of all group mapping.

ȱʡÉèÖÃ: idmap gid = <¿Õ×Ö·û´®>

ʾÀý: idmap gid = 10000-20000

idmap uid (G)
The idmap uid parameter specifies the range of user ids that are allocated for use in mapping UNIX users to NT user SIDs. This range of ids should have no existing local or NIS users within it as strange conflicts can occur otherwise.

ȱʡÉèÖÃ: idmap uid = <¿Õ×Ö·û´®>

ʾÀý: idmap uid = 10000-20000

include (G)
Õâ¸öÑ¡ÏîʹµÃÄã¿ÉÒÔ°ÑÒ»¸öÅäÖÃÎļþ²åÈëµ½ÁíÒ»¸öÅäÖÃÎļþÖÐÈ¥.ÕâÖ»ÊÇÒ»ÖÖÎı¾Ìæ»»,¾ÍÔÚºÃÏñ±»²åÈëµÄÎļþµÄÄǸöλÖÃÖ±½ÓдÈëÄǸö²åÈëÎļþÒ»Ñù.

ËüÖ§³Ö±ê×¼Ìæ»»,³ý%u , %P ºÍ %SÒÔÍâ.

ȱʡÉèÖÃ: ûÓаüº¬ÆäËûÎļþ

ʾÀý: include = /usr/local/samba/lib/admin_smb.conf

inherit acls (S)
This parameter can be used to ensure that if default acls exist on parent directories, they are always honored when creating a subdirectory. The default behavior is to use the mode specified when creating the directory. Enabling this option sets the mode to 0777, thus guaranteeing that default directory acls are propagated.

ȱʡÉèÖÃ: inherit acls = no

inherit permissions (S)
The permissions on new files and directories are normally governed by create mask, directory mask, force create mode and force directory mode but the boolean inherit permissions parameter overrides this.

New directories inherit the mode of the parent directory, including bits such as setgid.

New files inherit their read/write bits from the parent directory. Their execute bits continue to be determined by map archive , map hidden and map system as usual.

Note that the setuid bit is never set via inheritance (the code explicitly prohibits this).

This can be particularly useful on large systems with many users, perhaps several thousand, to allow a single [homes] share to be used flexibly by each user.

²Î¼û create mask , directory mask, force create mode and force directory mode .

ȱʡÉèÖÃ: inherit permissions = no

interfaces (G)
Õâ¸öÑ¡ÏîÔÊÐíÄ㳬ԽĬÈϵÄSambaÓÃÀ´´¦Àíä¯ÀÀ,Ãû×Ö×¢²áºÍÆäËûNBTÍøÂçÁ÷Á¿µÄÍøÂç½è¿ÚÁбí. ĬÈÏÇé¿öSambaÏòÄں˲éѯËùÓлµÄ½Ó¿ÚÁÐ±í²¢ÇÒʹÓóýÁË127.0.0.1 Ö®ÍâµÄ½Ó¿Ú.

Õâ¸öÑ¡ÏîµÄÄÚÈÝÊÇÒ»¸ö½Ó¿Ú×Ö·û´®µÄÁбí, ÿ¸ö×Ö·û´®¿ÉÒÔÊÇÏÂÁÐÈκÎÒ»ÖÖ¸ñʽ:

Ò»¸öÍøÂç½Ó¿ÚÃû(ÀýÈçeth0).Ëü¿ÉÒÔ°üº¬ÏóÔÚshell·ç¸ñµÄͨÅä·ûÈçeth*À´Æ¥ÅäÈκÎÒÔ×Ó×Ö·ûÆ·"eth"ÆðʼµÄÍøÂç½Ó¿Ú.

Ò»¸öIPµØÖ·.ÕâÖÖÇé¿öÏÂ,ÍøÂçÑÚÂëÊÇ´ÓÄÚºËÖлñµÃµÄ½Ó¿ÚÁбíÖмì²âµÄ.

Ò»¸öIP/ÑÚÂë¶Ô.

Ò»¸ö¹ã²¥µØÖ·/ÑÚÂë¶Ô.

"mask"Ñ¡Ïî¿ÉÒÔÊÇÒ»¸ö볤¶È(ÀýÈçCÀàÍøÂç¿ÉÒÔÊÇ24)»òÕßÊÇÒÔµã·Ö¸ñʽ³öÏÖµÄÍêÕûÍøÂçµØÖ·ÑÚÂë.

"IP"Ñ¡Ïî¿ÉÒÔÊÇÍêÕûµã·ÖÊ®Áù½øÖÆIPµØÖ·»òÊÇ°´²Ù×÷ϵͳͨ³£Ê¹ÓõÄÖ÷»úÃû½âÎö»úÖƲéÕÒµÄÖ÷»úÃû.

ÀýÈç,ÏÂÃæÕâÒ»ÐÐ:

interfaces = eth0 192.168.2.10/24 192.168.3.10/255.255.255.0

½«ÅäÖÃÈý¸öÍøÂç½Ó¿Ú,¶ÔÓ¦eth0É豸ÒÔ¼°IPµØÖ·192.168.2.10 ºÍ192.168.3.10¡£ºóÁ½¸ö½Ó¿ÚµÄÍøÂçÑÚÂ뽫ÉèÖÃΪ255.255.255.0¡£

²Î¼ûbind interfaces only.

ȱʡÉèÖÃ: ³ýÁË127.0.0.1 Ö®ÍâµÄËùÓл½Ó¿Ú that are broadcast capable

invalid users (S)
ÕâÊÇÒ»¸ö²»ÔÊÐíÔÚÕâ¸ö·þÎñÉϵǼµÄÓû§µÄÃûµ¥.ÕâµÄÈ·ÊÇÒ»¸ö·Ç³£ÑϸñµÄ(paranoid)¼ì²é,È·±£ÈκοÉÄܵIJ»Êʵ±µÄÉèÖö¼²»»áÆÆ»µÄãµÄϵͳµÄ°²È«.

ÒÔ@¿ªÍ·µÄÓû§ÃûÊ×Ïȱ»µ±×÷NISÍøÂç×éÃû(Èç¹ûÄãµÄϵͳ֧³ÖNISµÄ»°),Èç¹ûÔÚNISµÄÍøÂç×éÊý¾Ý¿âÖÐÕÒ²»µ½Õâ¸ö×é,ÄÇôÕâ¸öÃû×־ͱ»µ±×÷Ò»¸öUNIXÓû§×éÃûÀ´´¦Àí.

ÒÔ+¿ªÍ·µÄÓû§Ãû½ö±íʾUNIXÓû§×éÃû,ÒÔ&¿ªÍ·µÄÓû§Ãû½ö±íʾNIXÍøÂç×éÃû(Õâ¸öÉèÖÃÒªÇóÄãµÄϵͳÖÐÓÐNISÔÚÔËÐÐ).'+'ºÍ'&'·ûºÅ¿ÉÒÔÒÔÈκÎ˳Ðò³öÏÖÔÚÓû§×éÃûÇ°,Òò´Ë,Äã¿ÉÒÔÖ¸¶¨¶ÔÕâ¸öÃû³ÆµÄ²éÕÒ´ÎÐò,±ÈÈç+&group±íʾÏÈÔÚUNIXÓû§×éÖвéÕÒ,ÔÙÔÚNISÍøÂç×éÖвéÕÒ,¶ø&+groupÔòÏà·´,ÏÈÔÚNIXÍøÂç×éÖвéÕÒ,ÔÙµ½UNIXÓû§×éÖвéÕÒ.(ÕâÓëʹÓÃ@ǰ׺µÄЧ¹ûÏàͬ).

µ±Ç°µÄ·þÎñÃû¿ÉÒÔÓÃ%SÀ´±íʾ,ÕâÔÚ[homes]¶ÎÖÐÊǺÜÓÐÓõÄ.

²Î¼û valid users .

ȱʡÉèÖÃ: ûÓзǷ¨Óû§

ʾÀý: invalid users = root fred admin @wheel

keepalive (G)
Õâ¸öÑ¡ÏîÊÇÒ»¸öÕûÊý,Ëü±íʾÓÃÓÚkeepalive°ü¼ä¸ôµÄÃëÊý.Èç¹ûÕâ¸öÑ¡ÏîÊÇ0,ÄÇô¾Í²»·¢Ëͱ£³ÖÁ¬½ÓµÄ°ü.·¢Ëͱ£³ÖÁ¬½ÓµÄ°üʹµÃÖ÷»ú¿ÉÒÔÈ·¶¨¿Í»§¶ËÊÇ·ñ»¹ÔÚÏìÓ¦¡£

ͨ³£,Èç¹ûÓÃÓÚÁ¬½ÓµÄsocketʹÓÃÁËSO_KEEPALIVEÊôÐÔÉèÖÃ(²Î¼ûsocket options),ÄÇô·¢Ëͱ£³ÖÁ¬½ÓµÄ°üÊDz»ÐèÒªµÄ.»ù±¾ÉÏ,³ý·ÇÄãÓöµ½ÁËijЩÀ§ÄÑ,Õâ¸öÑ¡ÏîÊÇÓò»µ½µÄ.

ȱʡÉèÖÃ: keepalive = 300

ʾÀý: keepalive = 600

kernel change notify (G)
This parameter specifies whether Samba should ask the kernel for change notifications in directories so that SMB clients can refresh whenever the data on the server changes.

This parameter is only usd when your kernel supports change notification to user programs, using the F_NOTIFY fcntl.

ȱʡÉèÖÃ: Yes

kernel oplocks (G)
ÔÚÖ§³Ö»ùÓÚÄÚºËµÄ oplocks(opportunistic lock)µÄUNIXϵͳÉÏ(Ä¿Ç°Ö»ÓÐIRIX ºÍLinux2.4ÄÚºË),Õâ¸öÑ¡ÏîÔÊÐí´ò¿ª»ò¹Ø±Õ¶ÔÕâ¸öÌØÐÔµÄÀûÓÃ.

Äں˻ú»áÐÔËø¶¨²Ù×÷ʹµÃ±¾µØUNIX½ø³Ì»òNFS¶ÔÎļþ½øÐвÙ×÷ʱ¿ÉÒÔËø¶¨(¶³½á)smbd(8)¶Ôͬһ¸öÎļþµÄoplocks ²Ù×÷.Õâ¿ÉÒÔ±£³ÖSMB/CIFS,NFSºÍ±¾µØÎļþ²Ù×÷Ö®¼äµÄÊý¾ÝÒ»ÖÂÐÔ.(ÕâÊÇÒ»¸öºÜcoolµÄÌØÐÔŶ :-)

Èç¹ûÄãµÄϵͳ֧³ÖÕâ¸öÉèÖÃ,ȱʡÉèÖþÍÊÇon(´ò¿ª),Èç¹ûϵͳ²»Ö§³Ö,ȱʡÉèÖþÍÊÇOff(¹Ø±Õ).Äã¸ù±¾²»±ØÈ¥¹ÜÕâ¸öÑ¡Ïî.

²Î¼û oplocks ºÍ level2 oplocks ²ÎÊý.

ȱʡÉèÖÃ: kernel oplocks = yes

lanman auth (G)
This parameter determines whether or not smbd(8) will attempt to authenticate users using the LANMAN password hash. If disabled, only clients which support NT password hashes (e.g. Windows NT/2000 clients, smbclient, etc... but not Windows 95/98 or the MS DOS network client) will be able to connect to the Samba host.

The LANMAN encrypted response is easily broken, due to it's case-insensitive nature, and the choice of algorithm. Servers without Windows 95/98 or MS DOS clients are advised to disable this option.

Unlike the encypt passwords option, this parameter cannot alter client behaviour, and the LANMAN response will still be sent over the network. See the client lanman auth to disable this for Samba's clients (such as smbclient)

If this option, and ntlm auth are both disabled, then only NTLMv2 logins will be permited. Not all clients support NTLMv2, and most will require special configuration to us it.

Default : lanman auth = yes

large readwrite (G)
This parameter determines whether or not smbd(8) supports the new 64k streaming read and write varient SMB requests introduced with Windows 2000. Note that due to Windows 2000 client redirector bugs this requires Samba to be running on a 64-bit capable operating system such as IRIX, Solaris or a Linux 2.4 kernel. Can improve performance by 10% with Windows 2000 clients. Defaults to on. Not as tested as some other Samba code paths.

ȱʡÉèÖÃ: large readwrite = yes

ldap admin dn (G)
The ldap admin dn defines the Distinguished Name (DN) name used by Samba to contact the ldap server when retreiving user account information. The ldap admin dn is used in conjunction with the admin dn password stored in the private/secrets.tdb file. See the smbpasswd(8) man page for more information on how to accmplish this.

ldap delete dn (G)
This parameter specifies whether a delete operation in the ldapsam deletes the complete entry or only the attributes specific to Samba.

ȱʡÉèÖÃ: ldap delete dn = no

ldap filter (G)
Õâ¸öÑ¡ÏîÖ¸¶¨ÁËRFC2254¼æÈݵÄLDAPËÑË÷¹ýÂËÆ÷¡£Ä¬È϶ÔËùÓÐÆ¥ÅäsambaAccount¶ÔÏóÀàµÄÌõÄ¿½øÐеǼÃûºÍ uid ÊôÐÔÖ®¼äµÄÆ¥Åä¡£×¢ÒâÕâ¸ö¹ýÂËÆ÷Ö»Ó¦µ±·µ»ØÒ»¸öÌõÄ¿.

ȱʡÉèÖÃ: ldap filter = (&(uid=%u)(objectclass=sambaAccount))

ldap group suffix (G)
This parameters specifies the suffix that is used for groups when these are added to the LDAP directory. If this parameter is unset, the value of ldap suffix will be used instead.

ȱʡÉèÖÃ: none

ʾÀý: dc=samba,ou=Groups

ldap idmap suffix (G)
This parameters specifies the suffix that is used when storing idmap mappings. If this parameter is unset, the value of ldap suffix will be used instead.

ȱʡÉèÖÃ: none

ʾÀý: ou=Idmap,dc=samba,dc=org

ldap machine suffix (G)
It specifies where machines should be added to the ldap tree.

ȱʡÉèÖÃ: none

ldap passwd sync (G)
This option is used to define whether or not Samba should sync the LDAP password with the NT and LM hashes for normal accounts (NOT for workstation, server or domain trusts) on a password change via SAMBA.

The ldap passwd sync can be set to one of three values:

Yes = Try to update the LDAP, NT and LM passwords and update the pwdLastSet time.

No = Update NT and LM passwords and update the pwdLastSet time.

Only = Only update the LDAP password and let the LDAP server do the rest.

ȱʡÉèÖÃ: ldap passwd sync = no

ldap port (G)
Õâ¸öÑ¡ÏîÖ»ÓÐÔÚ±àÒëʱÅäÖÃÁË"--with-ldap"Ñ¡ÏîµÄÇé¿öϲſÉÓÃ.

Õâ¸öÑ¡Ïî¿ØÖÆÓÃÓÚºÍLDAP·þÎñÆ÷ͨѶµÄtcp¶Ë¿ÚºÅ¡£Ä¬ÈÏÓ¦Óñê×¼µÄLDAP¶Ë¿Ú636¡£

²Î¼û: ldap ssl

Default : ldap port = 636 ; Èç¹û ldap ssl = on

Default : ldap port = 389 ; Èç¹û ldap ssl = off

ldap server (G)
Õâ¸öÑ¡ÏîÖ»ÓÐÔÚ±àÒëʱÅäÖÃÁË"--with-ldapsam"Ñ¡ÏîµÄÇé¿öϲſÉÓÃ.

Õâ¸öÑ¡ÏîÓ¦µ±°üº¬ldapĿ¼·þÎñÆ÷µÄFQDN£¬ÓÃÀ´²éѯºÍ¶¨Î»Óû§ÕÊ»§ÐÅÏ¢¡£

Default : ldap server = localhost

ldap ssl (G)
This option is used to define whether or not Samba should use SSL when connecting to the ldap server This is NOT related to Samba's previous SSL support which was enabled by specifying the --with-ssl option to the configure script.

The ldap ssl can be set to one of three values:

Off = Never use SSL when querying the directory.

Start_tls = Use the LDAPv3 StartTLS extended operation (RFC2830) for communicating with the directory server.

On = Use SSL on the ldaps port when contacting the ldap server. Only available when the backwards-compatiblity --with-ldapsam option is specified to configure. See passdb backend

Default : ldap ssl = start_tls

ldap suffix (G)
Ö¸¶¨Óû§ºÍ»úÆ÷ÕʺŴÓÄÄÀï¼ÓÈëÊ÷ÖС£¿ÉÒÔ±»ldap user suffixºÍldap machine suffixÑ¡ÏîÔ½¹ý¡£ËüÒ²ÓÃ×÷ËùÓÐldapËÑË÷µÄbase dn¡£

ȱʡÉèÖÃ: none

ldap user suffix (G)
This parameter specifies where users are added to the tree. If this parameter is not specified, the value from ldap suffix.

ȱʡÉèÖÃ: none

level2 oplocks (S)
Õâ¸ö²ÎÊý¿ØÖÆÁËÊÇ·ñSambaÔÚÒ»¸ö¹²ÏíÉÏÖ§³ÖµÚ¶þ¼¶(Ö»¶Á)oplocks¡£

2¼¶,»òÕßÖ»¶ÁoplocksÔÊÐíWindows NT¿Í»§ÔÚÎļþÖпÉÒÔ±£³ÖÒ»¸öoplocks,Ò»µ©µÚ¶þ¸öÓû§ÇëÇóͬһÎļþʱ¿ÉÒÔ´Ó¶Áдoplocks¼¶½µÎªÖ»¶Áoplocks(¶ø²»ÊÇÏñ´«Í³µÄ×ö·¨£¬±£³ÖΨһµÄoplocks£¬ÔÚµÚ¶þ´Î´ò¿ªÊ±ÊÍ·ÅËùÓеÄoplocks).ÕâÑù¾Í¿ÉÒÔÔÊÐíÖ§³Ö2¼¶oplocksµÄÎļþ´ò¿ªÕß»º´æÓÃÓÚÖ»¶ÁµÄÎļþ(Ò²¾ÍÊÇ˵,ËûÃǵÄдºÍËø¶¨ÇëÇ󲻿ÉÄܱ»»º³å),²¢ÇÒʹֻ¶ÁÎļþµÄ´óÁ¿·ÃÎÊÌáÉýÐÔÄÜ(ÀýÈç.exeÎļþ).

Ò»µ©ÔÚÓµÓÐÖ»¶ÁoplocksµÄ¿Í»§ÖÐÓÐһλ¶ÔÎļþ½øÐÐÁËд²Ù×÷,ËùÓеĿͻ§¶¼»á±»Í¨Öª(²»ÐèÒª»Ø¸´¼°µÈ´ý), told to break their oplocks to "none",È»ºóɾ³ýËùÓÐread-ahead caches.

ÍƼö´ò¿ªÕâ¸öÑ¡ÏΪ¹²ÏíµÄ¿ÉÖ´ÐгÌÐòÌá¸ß·ÃÎÊËٶȡ£

¸ü¶à¹ØÓÚ2¼¶oplocksµÄÌÖÂÛÇë²é¿´CIFSµÄ¹æÔ¼.

µ±Ç°,Èç¹ûʹÓÃÁËkernel oplocksµÄ»°,¾Í²»»áÈÏ¿É2¼¶oplocks(¼´Ê¹°ÑÄǸöÑ¡ÏîÉèΪyesҲûÓÃ).»¹Òª×¢Òâ,oplocks Ñ¡Ïî±ØÐëÔÚ¹²ÏíÉϱ»Éè³Éyes²ÅÓÐЧ¹û.

²Î¼û oplocks ºÍ kernel oplocks Ñ¡Ïî¡£

ȱʡÉèÖÃ: level2 oplocks = yes

lm announce (G)
Õâ¸öÑ¡Ïî¾ö¶¨nmbd(8)ÊÇ·ñ²úÉú"LanmanÐû¸æ¹ã²¥",OS/2µÄ¿Í»§¶ËÐèÒªÕâ¸ö¹ã²¥ÓÃÒÔÔÚËüÃǵÄä¯ÀÀÁбíÀï¿´µ½Samba·þÎñÆ÷.Õâ¸öÑ¡ÏîÓÐ3¸öÖµ:yes¡¢no¡¢auto.ȱʡֵÊÇauto.Èç¹ûÕâֵΪno,Samba½«²»»á²úÉúÕâÖֹ㲥.Èç¹ûÉèÖÃΪyes,Samba½«ÒÔlm intervalÑ¡ÏîµÄֵΪƵÂʲúÉúÕâÖֹ㲥.Èç¹ûÉèÖÃΪauto,Samba²¢²»·¢³öÕâÀà¹ã²¥,µ«ÊÇÕìÌýËûÃÇ.Èç¹ûÊÕµ½ÕâÑùµÄ¹ã²¥,Ëü¾Í¿ªÊ¼·¢ËÍÕâÖֹ㲥,ƵÂÊ»¹ÊÇÒÔlm intervalÑ¡ÏîÉ趨µÄΪ׼.

²Î¼û lm interval.

ȱʡÉèÖÃ: lm announce = auto

ʾÀý: lm announce = yes

lm interval (G)
Èç¹ûSambaÉèÖÃΪ²úÉú"LanmanÐû¸æ¹ã²¥£¨¸øOS/2¿Í»§¶ËʹÓÃ,²Î¼ûlm announceÑ¡Ï.ÄÇô,ÕâÀïµÄÑ¡ÏîÉ趨ÁËÒÔÃëΪµ¥Î»µÄ·¢ÉúƵÂÊ.Èç¹ûÕâ¸öÑ¡ÏîÉèÖÃΪ"0",Ôò²»¹Ülm announceÑ¡ÏîµÄÖµ,ÓÀÔ¶²»»á·¢³öÈκÎ"LanmanÐû¸æ¹ã²¥".

²Î¼ûlm announce.

ȱʡÉèÖÃ: lm interval = 60

ʾÀý: lm interval = 120

load printers (G)
Õâ¸ö²¼¶ûÖµ¿ØÖÆÊÇ·ñÔÚ"printcap"ÎļþÖеÄËùÓдòÓ¡»ú½«»á±»È±Ê¡µÄ°²×°µ½Samba»·¾³,²¢ÇÒ¿ÉÒÔ±»ä¯ÀÀ.²Î¼û"printers"¶Î»ñµÃ¸ü¶àϸ½Ú.

ȱʡÉèÖÃ: load printers = yes

local master (G)
Õâ¸öÑ¡ÏîÔÊÐínmbd(8)ÊÔ×ÅÈ¥³ÉΪ±¾µØ×ÓÍøµÄÖ÷¿Øä¯ÀÀÆ÷.Èç¹ûÑ¡ÏîֵΪno, nmbd²»»áÈ¥ÕùÈ¡Õâ¸öȨÀû.ÔÚȱʡÇé¿öÏÂ,Õâ¸öֵΪyes.ÉèÖÃÕâ¸öֵΪyes,²¢²»Òâζ×Åbecome ¾ÍÒ»¶¨»á³ÉΪ±¾µØµÄÖ÷ä¯ÀÀÆ÷,Ö»ÊÇÒâζ×Åbecome »á²Î¼Ó³ÉΪÖ÷ä¯ÀÀÆ÷µÄÑ¡¾Ù.

ÉèÖÃÕâ¸öֵΪ no ½«Ê¹ nmbd ÓÀÔ¶²»»á ³ÉΪÖ÷¿Øä¯ÀÀÆ÷¡£

ȱʡÉèÖÃ: local master = yes

lock dir (G)
Óë lock directory ͬÒå.

lock directory (G)
Õâ¸öÑ¡ÏîÖ¸³ö"¼ÓËøÎļþ"·ÅÖõÄĿ¼.¼ÓËøÎļþÓÃÒÔʵÏÖ×î´óÁ¬½ÓÊýmax connections.

ȱʡÉèÖÃ: lock directory = ${prefix}/var/locks

ʾÀý: lock directory = /var/run/samba/locks

locking (S)
Õâ¸öÑ¡Ïî¿ØÖƵ±¿Í»§¶Ë·¢³öËø¶¨ÇëÇóʱ,·þÎñÆ÷ÊÇ·ñÖ´ÐÐ"Ëø¶¨".

Èç¹û locking = no ,ËùÓеÄËø¶¨ÇëÇóºÍ½â³ýËø¶¨ÇëÇ󽫱íÏÖΪ³É¹¦Ö´ÐÐ.¶ÔËø¶¨µÄ²éѯ½«»áÏÔʾûÓÐËø¶¨.

Èç¹ûlocking = yes ·þÎñÆ÷½«Ö´ÐÐÕæÕýµÄËø¶¨¡£

Õâ¸öÑ¡Ïî¿ÉÄܶÔÖ»¶ÁÎļþϵͳÓÐÓÃ,ÒòΪËü¿ÉÄܲ»ÐèÒªËø¶¨£¨ÀýÈç:CDROM£©.¼´Ê¹ÔÚÕâÖÖÇé¿öÏÂ,ÎÒÃÇÒ²²»ÕæÕýÍƼöʹÓÃno.

ÒªÌرðСÐÄ,²»¹ÜÊÇÈ«¾ÖµÄ¹Ø±ÕÕâ¸öÑ¡Ïî»òÕßÔÚij¸ö·þÎñÉϹرÕÕâ¸öÑ¡Ïî,¶¼ÓпÉÄÜÓÉÓÚȱÉÙËø¶¨¶øµ¼ÖÂÊý¾ÝËð»µ.Æäʵ,Äã¸ù±¾¾Í²»ÐèÒªÉèÖÃÕâ¸öÑ¡Ïî.

ȱʡÉèÖÃ: locking = yes

lock spin count (G)
This parameter controls the number of times that smbd should attempt to gain a byte range lock on the behalf of a client request. Experiments have shown that Windows 2k servers do not reply with a failure if the lock could not be immediately granted, but try a few more times in case the lock could later be aquired. This behavior is used to support PC database formats such as MS Access and FoxPro.

ȱʡÉèÖÃ: lock spin count = 3

lock spin time (G)
The time in microseconds that smbd should pause before attempting to gain a failed lock. See lock spin count for more details.

ȱʡÉèÖÃ: lock spin time = 10

log file (G)
Õâ¸öÑ¡ÏîÔÊÐíÉèÖÃÆäËüµÄÎļþÃû×ÖÀ´Ìæ´úSambaÈÕÖ¾Îļþ£¨Ò²¾ÍÊǵ÷ÊÔÎļþ).

Õâ¸öÑ¡ÏîÖ§³Ö±ê×¼µÄÎļþÃû´ú»»±äÁ¿,ÔÊÐí·½±ãµÄΪÿ¸öÓû§»òÕß»úÆ÷ÉèÖÃרÓõÄÈÕÖ¾Îļþ.

ʾÀý: log file = /usr/local/samba/var/log.%m

log level (G)
Õâ¸öÖµ(×Ö·û´®)ÔÊÐíÔÚsmb.confÀﶨÒåµ÷ÊÔˮƽ(¼Ç¼ˮƽ).This parameter has been extended since the 2.2.x series, now it allow to specify the debug level for multiple debug classes. Õâ¸øϵͳÅäÖôøÀ´¸ü´óµÄÁé»îÐÔ.

ȱʡµÄµ÷ÊÔˮƽ½«ÔÚÃüÁîÐÐÀﶨÒå,Èç¹ûûÓж¨Òå,µ÷ÊÔˮƽΪÁã.

ʾÀý: log level = 3 passdb:5 auth:10 winbind:2

logon drive (G)
Õâ¸öÑ¡ÏîÉèÖÃÒ»¸ö±¾µØ·¾¶£¨¿ÉÒÔÀí½âΪÍøÂçÓ³ÉäÅÌ£©,µ±µÇ¼ʱ,Óû§µÄÖ÷Ŀ¼¾ÍÁ¬½Óµ½Õâ¸ö±¾µØ·¾¶(²Î¼ûlogon home).

×¢Òâ:Õâ¸öÑ¡ÏîÖ»ÓÐÔÚSambaÊǵǼ·þÎñÆ÷ʱ²ÅÓÐÓÃ.

ȱʡÉèÖÃ: logon drive = z:

ʾÀý: logon drive = h:

logon home (G)
µ±Win95/98»òWin NT¹¤×÷Õ¾µÇ¼µ½Samba PDCʱ,ËüÃǵÄÖ÷Ŀ¼µÄλÖÃ.ÉèÖÃÁËÕâ¸öÑ¡Ïî,¾ÍÔÊÐíÔÚ(DOS)Ìáʾ·ûÏÂʹÓÃÐÎÈç:

C:\> NET USE H: /HOME

ÕâÑùµÄÃüÁî¡£

Õâ¸öÑ¡ÏîÖ§³Ö±ê×¼µÄÃüÁîÑ¡ÏîÌæ»»,·½±ãΪÿ¸öÓû§»òÕß»úÆ÷ÌṩµÇ¼½Å±¾.

This parameter can be used with Win9X workstations to ensure that roaming profiles are stored in a subdirectory of the user's home directory. This is done in the following way:

logon home = \%NU
rofile

This tells Samba to return the above string, with substitutions made when a client requests the info, generally in a NetUserGetInfo request. Win9X clients truncate the info to \\server\share when a user does net use /home but use the whole string when dealing with profiles.

Note that in prior versions of Samba, the logon path was returned rather than logon home. This broke net use /home but allowed profiles outside the home directory. The current implementation is correct, and can be used for profiles if you use the above trick.

×¢Òâ,Õâ¸öÑ¡ÏîÖ»ÔÚSamba±»ÉèÖóÉΪµÇ¼·þÎñÆ÷logon serverʱ²ÅÆð×÷ÓÃ.

ȱʡÉèÖÃ: logon home = "\%NU"

ʾÀý: logon home = "\remote_smb_serverU"

logon path (G)
Õâ¸öÑ¡ÏîÖ¸¶¨ÁË´æ·Åroaming profile(WindowsNTµÄNTuser.dat µÈÎļþ)µÄÓû§Ä¿Â¼.Contrary to previous versions of these manual pages, it has nothing to do with Win 9X roaming profiles. To find out how to handle roaming profiles for Win 9X system, see the logon home parameter.

Õâ¸öÑ¡ÏîÖ§³Ö±ê×¼Ìæ»»,ÔÊÐíÄãΪÿһ¸öÓû§»ò»úÆ÷ÉèÖò»Í¬µÄµÇ¼½Å±¾.ËüÒ²¿ÉÒÔÖ¸¶¨ÄÇЩÏÔʾÔÚWindows NT¿Í»§¶ËÉϵÄ"Ó¦ÓóÌÐòÊý¾Ý"(×ÀÃæ,¿ªÊ¼²Ëµ¥,ÍøÉÏÁھӺͳÌÐòµÈÎļþ¼ÐºÍËûÃǵÄÄÚÈÝ).

Ö¸¶¨µÄ¹²Ïí×ÊÔ´ºÍ·¾¶±ØÐëÊÇÓû§¿É¶ÁµÄ,ÕâÑù,É趨µÄÑ¡ÏîºÍĿ¼²ÅÄܱ»Windows NT¿Í»§¶Ë×°ÔØʹÓÃ.Õâ¸ö¹²Ïí×ÊÔ´ÔÚÓû§µÚÒ»´ÎµÇ¼ʱ±ØÐëÊÇ¿ÉдµÄ,ÕâÑùWindows NT¿Í»§¶Ë²ÅÄܽ¨Á¢NTuser.datÎļþ¼°ÆäËûĿ¼.

È»ºó,ÕâЩĿ¼ÒÔ¼°ÆäÖеÄÈκÎÄÚÈݶ¼¿ÉÒÔ¸ù¾ÝÐèÒªÉèÖÃΪֻ¶ÁµÄ.°ÑNTuser.datÎļþÉèÖóÉÖ»¶ÁÊDz»Ã÷ÖǵÄ,ÄãÓ¦¸Ã°ÑËü¸ÄÃû³ÉNTuser.man(Ò»¸öÇ¿ÖÆʹÓÃ(MANdatory)µÄuser.dat)À´´ïµ½Í¬ÑùµÄÄ¿µÄ.

WindowsÖÕ¶ËÓÐʱºò¼´Ê¹Ã»ÓÐÓû§µÇ¼Ҳ»á±£³Ö¶Ô[homes]¹²Ïí×ÊÔ´µÄÁ¬½Ó.Òò´Ë,logon path²»ÄÜ°üº¬¶Ôhomes¹²Ïí×ÊÔ´µÄÈκβÎÕÕ(Ò²¾ÍÊÇ˵,°ÑÕâ¸öÑ¡ÏîÉèÖóÉÀàËÆ\\%N\HOMES\profile_path»áÒýÆðÎÊÌâ).

Õâ¸öÑ¡ÏîÖ§³Ö±ê×¼Ìæ»»,ÔÊÐíÄãΪ²»Í¬µÄ»úÆ÷»òÓû§ÉèÖò»Í¬µÄµÇ¼½Å±¾.

×¢Òâ,Õâ¸öÑ¡ÏîÖ»ÓÐÔÚSamba±»ÉèÖóÉΪµÇ¼·þÎñÆ÷logon serverµÄʱºò²ÅÆð×÷ÓÃ.

ȱʡÉèÖÃ: logon path = \\%N\%U\profile

ʾÀý: logon path = \\PROFILESERVER\PROFILE\%U

logon script (G)
Õâ¸öÑ¡ÏîÖ¸Ã÷,µ±Ò»¸öÓû§³É¹¦µÄµÇ¼ºó,½«»á×Ô¶¯ÏÂÔص½±¾µØÖ´ÐеĽű¾Îļþ,Õâ¸ö½Å±¾Îļþ¿ÉÄÜÊÇÒ»¸öÅú´¦ÀíÎļþ£¨.bat£©»òÕßÒ»¸öNTÃüÁîÎļþ£¨.cmd£©.Õâ¸ö½Å±¾Îļþ±ØÐëʹÓÃDOS·ç¸ñµÄ»Ø³µ/»»ÐУ¨CR/LF£©À´½áÊøÿһÐÐ,Òò´Ë,ÎÒÃÇÍƼöʹÓÃDOS·ç¸ñµÄÎı¾±à¼­Æ÷À´½¨Á¢Õâ¸öÎļþ.

½Å±¾ÎļþµÄ´æ·ÅλÖñØÐëÊÇÏà¶ÔÓÚ[netlogon]·þÎñÖÐÖ¸Ã÷µÄĿ¼·¾¶,¾ÙÀýÀ´Ëµ,Èç¹û[netlogon]·þÎñÖ¸¶¨ÁËÁËÒ»¸öpathÊÇ/usr/local/samba/netlogon,¶ølogon script = STARTUP.BAT, ÄÇô½«ÒªÏÂÔص½¿Í»§¶ËÖ´ÐеÄÎļþµÄʵ¼Ê´æ·ÅλÖÃÊÇ:

/usr/local/samba/netlogon/STARTUP.BAT

µÇ¼½Å±¾µÄÄÚÈÝ°üº¬Ê²Ã´,ÍêÈ«ÓÉÄã¾ö¶¨.ÎÒÃǽ¨Òé°üº¬Õâ¸öÖ¸Áî:NET TIME \SERVER /SET /YES,ËüÇ¿ÆÈÿһ̨»úÆ÷µÄʱ¼äºÍ·þÎñÆ÷µÄʱ¼äͬ²½£¨ÒÔ·þÎñÆ÷µÄʱ¼äΪ׼£©£»ÁíÒ»¸ö½¨ÒéÊÇÓ³É乫¹²¹¤¾ßÅÌ:NET USE U:\\SERVER\"¹«¹²¹¤¾ßĿ¼" ÀýÈç:

NET USE Q:\SERVERISO9001_QA

×¢Òâ:ÔÚÒ»¸öÓа²È«ÒªÇóµÄϵͳ»·¾³ÖÐ,ÌرðÖØÒªµÄÊÇÒª¼Çס²»ÒªÔÊÐí¿Í»§ÔÚ[netlogon]ÉÏÓÐдµÄȨÏÞ,Ò²²»Òª¸øÒÔ¿Í»§¸ÄдµÇ¼½Å±¾ÎļþµÄȨÀû.Èç¹ûÔÊÐí¿Í»§ËæÒâµÄÐÞ¸Ä,°²È«¹æÔò¾Í¸ø˺ÁÑÁËÒ»¸ö¿Ú×Ó.

Õâ¸öÑ¡ÏîÖ§³Ö±ê×¼µÄÖû»¹æÔò,ÔÊÐíÄãΪÿ¸ö²»Í¬µÄÓû§»ò»úÆ÷¶¨ÖƲ»Í¬µÄµÇ¼½Å±¾.

×¢Òâ,Õâ¸öÑ¡ÏîÖ»ÓÐÔÚSambaÉèÖÃΪµÇ¼·þÎñÆ÷ʱ²ÅÆð×÷ÓÃ.

ȱʡÉèÖÃ: no logon script defined

ʾÀý: logon script = scriptsU.bat

lppause command (S)
Õâ¸öÑ¡ÏîÖ¸¶¨ÔÚ·þÎñÆ÷ÉÏÖжÏÖ¸¶¨µÄ´òÓ¡×÷ÒµµÄ´òÓ¡»ò¼ÙÍÑ»ú´òÓ¡²Ù×÷ËùʹÓõÄÖ¸Áî.

Õâ¸öÖ¸ÁîÓ¦¸ÃÊÇÒ»¸ö¿ÉÒÔ¸ù¾Ý´òÓ¡»úÃûºÍ×÷ÒµºÅÖжϴòÓ¡×÷ÒµµÄ³ÌÐò»ò½Å±¾.ʵÏÖÕâ¸ö²Ù×÷µÄÒ»¸ö°ì·¨ÊÇʹÓÃ×÷ÒµÓÅÏȼ¶,ÓÅÏȼ¶±ðÌ«µÍµÄ×÷Òµ²»»á±»·¢Ë͵½´òÓ¡»úÉÏ.

ÓÃ%pÖû»¿ÉÒÔÈ¡µÃ´òÓ¡»úÃû,¶ø%j»á±»´òÓ¡×÷ÒµºÅ(Ò»¸öÕûÊý)Öû».ÔÚHPUXϵͳÖÐ(²Î¼ûprinting=hpux ),Èç¹û¸ølpqÃüÁî¼ÓÉÏ-p%pÑ¡Ïî,´òÓ¡×÷Òµ»áÏÔʾÆäÖ´ÐÐ״̬,¾ßÌåµÄ˵,Èç¹û×÷ÒµµÄÓÅÏȼ¶µÍÓÚ×èÈû¼¶±ð,Ëü»áÏÔʾ'PAUSED'״̬,·´Ö®,Èç¹û×÷ÒµµÄÓÅÏȼ¶µÈÓÚ»ò¸ßÓÚ×èÈû¼¶±ð,Ëü»áÏÔʾ'SPOOLED'»ò'PRINTING'״̬.

×¢Òâ,ÔÚÕâ¸öÉèÖÃÖÐʹÓþø¶Ô·¾¶ÊÇÒ»¸öºÃÏ°¹ß,ÒòΪÕâ¸ö·¾¶ÓпÉÄܲ»ÔÚ·þÎñÆ÷µÄPATH»·¾³±äÁ¿ÖÐ.

²Î¼û printing parameterÑ¡Ïî.

ȱʡÉèÖÃ: Ä¿Ç°Õâ¸öÑ¡ÏîûÓÐȱʡÉèÖÃ,³ý·ÇprintingÑ¡ÏîÉèÖÃSYSV,ÔÚÕâÖÖÇé¿öÏÂ,ȱʡ²Î ÊýÊÇ:

lp -i %p-%j -H hold

»òÕßÔÚprintingÑ¡ÏîÉèÖÃΪsoftqʱ,ȱʡѡÏîÊÇ:

qstat -s -j%j -h

ÔÚHPUXϵͳÖеÄÀý×Ó: lppause command = /usr/bin/lpalt %p-%j -p0

lpq cache time (G)
´ËÑ¡Ïî¿ØÖÆÁËlpqÐÅÏ¢¶à³¤Ê±¼ä±»»º³åÒ»´Î,ÒÔ·ÀֹƵ·±µ÷ÓÃlpqÃüÁî.ÿһ´ÎϵͳʹÓÃlpqÃüÁî»á±£ÁôÒ»¸öµ¥¶ÀµÄ»º³å,ËùÒÔÈç¹û²»Í¬µÄÓû§·Ö±ðʹÓÃÁ˲»Í¬µÄlpqÃüÁîµÄ»°,ËûÃDz»¿ÉÄܹ²Ïí»º³åÐÅÏ¢.

»º³åÎļþ±»´æ·ÅÔÚ/tmp/lpq.xxxxÎļþÖÐ,ÆäÖеÄxxxxÊÇÕýÔÚʹÓõÄlpqÃüÁî¹þÏ£±í.

Õâ¸öÑ¡ÏîµÄȱʡֵÊÇ10Ãë,Õâ¾ÍÊÇ˵ÒÔÇ°ÏàͬµÄlpqÃüÁîµÄ»º³åÄÚÈݽ«ÔÚÖÜÆÚΪ10ÃëÄÚ±»Ê¹ÓÃ.Èç¹ûlpqÃüÁî·Ç³£ÂýµÄ»°,¿ÉÒÔÈ¡ÉÔ´óµÄÖµ.

°ÑÕâ¸öÖµÉèΪ0¾ÍÍêÈ«½ûÖ¹ÁË»º³å¼¼ÊõµÄʹÓÃ.

²Î¼û printing Ñ¡Ïî.

ȱʡÉèÖÃ: lpq cache time = 10

ʾÀý: lpq cache time = 30

lpq command (S)
Õâ¸öÑ¡ÏîÖ¸¶¨ÎªÁË»ñµÃlpq·ç¸ñµÄ´òÓ¡»ú״̬ÐÅÏ¢¶øÒªÔÚ·þÎñÆ÷ÉÏÒªÖ´ÐеÄÃüÁî.

Õâ¸öÃüÁîÓ¦¸ÃÊÇÒ»¸öÖ»ÒÔ´òÓ¡»úÃû×÷ΪѡÏî²¢¿ÉÒÔÊä³ö´òÓ¡»ú״̬ÐÅÏ¢µÄ³ÌÐò»ò½Å±¾.

ͨ³£Ö§³Ö¾ÅÖÖ´òÓ¡»ú״̬ÐÅÏ¢:CUPS, BSD,AIX,LPRNG,PLP,SYSV,HPUX,QNXºÍSOFTQ.¶øÕâЩÕýºÃ¸²¸ÇÁË´ó¶àÊýµÄUNIXϵͳ.Äã¿ÉÒÔÓÃprinting =Ñ¡ÏîÀ´¿ØÖƵ½µ×ÒªÓÃÄÄÖÖÀàÐÍ.

ÓÐЩ¿Í»§¶Ë(ÌرðÊÇWindows for Workgroups)¿ÉÄܲ»ÄÜÕýÈ·µØÏò´òÓ¡»ú·¢ËÍÁª½ÓºÅÒÔ»ñµÃ״̬ÐÅÏ¢.¶Ô´Ë,·þÎñÆ÷»áÏò¿Í»§±¨¸æËüËùÁª½ÓµÄÊ׸ö´òÓ¡·þÎñ.ÕâÑùµÄÇé¿öÖ»µ±Áª½ÓºÅ·¢ËÍ·Ç·¨Ê±²Å»á·¢Éú.

Èç¹ûʹÓÃ%p±äÁ¿µÄ»°,ϵͳ»áÔÚ´Ë´¦·ÅÖôòÓ¡»úÃû.·ñÔòÔÚÃüÁîºó·ÅÖôòÓ¡»úÃû.

×¢Òâ,µ±·þÎñÆ÷²»ÄÜ»ñµÃPATH±äÁ¿µÄ»°,ÒÔ¾ø¶Ô·¾¶À´ÃèÊölpq commandÊǸöºÃÏ°¹ß. µ±ÓëCUPS¿â±àÒëÁ¬½Óʱ£¬²»ÐèÒªlpq command£¬ÒòΪsmbd½«Ê¹Óÿâµ÷ÓÃÀ´»ñµÃ´òÓ¡¶ÓÁÐÁÐ±í¡£

²Î¼û printing Ñ¡Ïî.

ȱʡÉèÖÃ: ÒÀÀµÓÚ printing µÄÉèÖÃÇé¿ö

ʾÀý: lpq command = /usr/bin/lpq -P%p

lpresume command (S)
´ËÑ¡ÏîÖ¸¶¨ÎªÁ˼ÌÐøÁ¬Ðø´òÓ¡»ò¼ÙÍÑ»úÒ»¸öÖ¸¶¨µÄ´òÓ¡ÈÎÎñʱҪÔÚ·þÎñÆ÷ÉÏÖ´ÐеÄÃüÁî.

´ËÃüÁîÓ¦¸ÃÊÇÒ»¸öÒÔ´òÓ¡»úÃûºÍÒª»Ö¸´µÄ´òÓ¡ÈÎÎñºÅ×÷ΪѡÏîµÄ³ÌÐò»ò½Å±¾.²Î¼ûlppause command ²ÎÊý¡£

Èç¹ûʹÓÃ%p±äÁ¿µÄ»°,ϵͳ»áÔÚ´Ë´¦·ÅÖôòÓ¡»úÃû.ÓÃ%jÀ´´úÌæ´òÓ¡ÈÎÎñºÅ,µ±È»ÊÇÓÃÕûÊýÐΠʽÂÞ.

×¢Òâ,µ±·þÎñÆ÷²»ÄÜ»ñµÃPATH±äÁ¿µÄ»°,ÒÔ¾ø¶Ô·¾¶À´ÃèÊölpresume commandÊǸöºÃÏ°¹ß

²Î¼û printing Ñ¡Ïî.

ȱʡÉèÖÃ: µ±Ç°Ã»ÓÐȱʡÉèÖ㬳ý·Ç printing Ñ¡ÏîÊÇ SYSV, ´ËʱĬÈÏÊÇ

lp -i %p-%j -H resume

»òÕßÈç¹ûprinting Ñ¡ÏîÊÇ SOFTQ, ÄÇôĬÈÏÊÇ:

qstat -s -j%j -r

HPUXµÄʾÀý: lpresume command = /usr/bin/lpalt %p-%j -p2

lprm command (S)
´ËÑ¡ÏîÖ¸¶¨ÎªÁËҪɾ³ýÒ»¸ö´òÓ¡ÈÎÎñ¶øÐèÒªÔÚ·þÎñÆ÷ÉÏÖ´ÐеÄÃüÁî.

´ËÃüÁîÓ¦¸ÃÊÇÒ»¸öʹÓôòÓ¡»úÃûºÍ´òÓ¡ÈÎÎñºÅµÄ³ÌÐò»ò½Å±¾,²¢ÇÒÖ´ÐÐËüÃÇ¿ÉÒÔɾµô´òÓ¡ÈÎÎñ.

Èç¹ûʹÓÃ%p±äÁ¿µÄ»°,ϵͳ»áÔÚ´Ë´¦·ÅÖôòÓ¡»úÃû.ÓÃ%jÀ´´úÌæ´òÓ¡ÈÎÎñºÅ,µ±È»ÊÇÒ²ÓÃÕûÊýÐÎʽÂÞ.

×¢Òâ,µ±²»ÄÜ´Ó·þÎñÆ÷»ñµÃPATH±äÁ¿µÄ»°,ÒÔ¾ø¶Ô·¾¶À´ÃèÊölprm commandÊǸöºÃÏ°¹ß.

²Î¼ûprinting Ñ¡Ïî.

ȱʡÉèÖÃ: ÒÀÀµÓÚ printing Ñ¡ÏîÉèÖÃ

ʾÀý 1: lprm command = /usr/bin/lprm -P%p %j

ʾÀý 2: lprm command = /usr/bin/cancel %p-%j

machine password timeout (G)
Èç¹ûsamba·þÎñÆ÷ÊÇWindows NTÓò³ÉÔ±µÄ»°(²Î¼ûsecurity=domainÑ¡Ïî),ÄÇôÔËÐÐÖеÄsmbd½ø³Ì»áÖÜÆÚÐÔµØÊÔןı䴢´æÔÚ½Ð×öprivate/secrets.tdbµÄTDBÖеÄMACHINE ACCOUNT PASSWORD.Õâ¸ö²ÎÊýÖ¸¶¨ÁËÃÜÂ뽫¶à¾Ã¸ü»»Ò»´Î£¬ÒÔÃëΪµ¥Î»¡£È±Ê¡ÖµÊÇÒ»¸öÐÇÆÚ(µ±È»ÒªÒÔÃëÀ´±íʾ),ÕâÓëNTÓò³ÉÔ±·þÎñÆ÷ÊÇÒ»ÑùµÄ.

²Î¼û smbpasswd(8), ºÍ security = domain Ñ¡Ïî.

ȱʡÉèÖÃ: machine password timeout = 604800

magic output (S)
´ËÑ¡ÏîÖ¸¶¨ÁËÒ»¸öÓÃmagic½Å±¾Êä³öÄÚÈݶø½¨Á¢µÄÎļþµÄÃû³Æ,²Î¼ûÏÂÃæ¶Ômagic scriptÑ¡ÏîµÄÃèÊö.

¾¯¸æ:Èç¹ûÁ½¸ö¿Í»§ÔÚͬÑùµÄĿ¼ÏÂÓÃÏàͬµÄmagic script,Êä³öÎļþÄÚÈÝÊÇÎÞ·¨È·¶¨µÄ.

ȱʡÉèÖÃ: magic output = <magic script name>.out

ʾÀý: magic output = myfile.txt

magic script (S)
Õâ¸öÑ¡ÏîÓÃÀ´Ö¸¶¨½«±»·þÎñÆ÷Ö´ÐеÄÎļþµÄÃû×Ö,Õâ¸öÎļþÈç¹ûÒѾ­´ò¿ª,ÄÇô,µ±Õâ¸öÎļþ¹Ø±Õºó·þÎñÆ÷ͬÑùÒ²¿ÉÒÔÔËÐÐ.ÕâÑù¾ÍÔÊÐíÁËÒ»¸öUNIX½Å±¾¿ÉÒÔ´«Ë͵½sambaÖ÷»ú,²¢ÎªËùÁ¬½ÓµÄÓû§ÔËÐÐ.

ÒÔÕâÖÖ·½Ê½ÔËÐеĽű¾½«»áÔÚÍê³ÉÒÔºó±»É¾³ý,ֻҪȨÏÞÔÊÐíµÄ»°.

Èç¹û½Å±¾²úÉúÁËÊä³öµÄ»°,ÕâЩÐÅÏ¢¾Í±»Ë͵½magic outputÑ¡ÏîÖ¸¶¨µÄÎļþÖÐ(¼ûÒÔÉÏÃèÊö).

×¢Òâ,һЩÃüÁî½âÊÍÆ÷²»ÄܽâÊÍ°üº¬CR/LF¶ø²»ÊÇCR»Ø³µ»»ÐзûµÄ½Å±¾.magic½Å±¾±ØÐëÊÇ¿ÉÒÔ±»ÔËÐеģ¨¾ÍÏóÔÚ±¾µØÖ÷»úÔËÐÐÒ»Ñù£©,¶øÓÐЩ½Å±¾ÔÚijЩÖ÷»úÉÏ»òijЩshellÏ¿ÉÄÜ»áÔÚdos¿Í»§¶Ë½øÐйýÂË´¦Àí.

magic½Å±¾ÈÔ´¦ÓÚʵÑé½×¶Î,ËùÒÔ²»ÄܶԴËÍêÈ«ÒÀÀµ.

ȱʡÉèÖÃ: ÎÞ¡£½ûֹʹÓÃmagic script.

ʾÀý: magic script = user.csh

mangle case (S)
²Î¼ûNAME MANGLING²¿·Ö.

ȱʡÉèÖÃ: mangle case = no

mangled map (S)
Õâ¸öÑ¡ÏîÊÇÓÃÀ´Ö±½ÓÓ³ÉäÄÇЩ²»ÄÜÔÚWindows/DOSÉÏÃèÊöµÄunixÎļþÃû.²»¹ý²¢²»¾­³£³öÏÖÕâÑùµÄÇé¿ö,Ö»ÓÐһЩÌØÊâµÄÀ©Õ¹ÃûÔÚDOSºÍUNIXÖ®¼ä²Å»á²»Í¬,ÀýÈç,HTMLÎļþÔÚUNIXÏÂͨ³£¶¼ÊÇ.html,¶øÔÚWindows/DOSÏÂͨ³£È´ÊÇ.htm.

ËùÒÔÈç¹ûÒª½« html Ó³ÉäΪ htm ÄãÓ¦µ±ÕâÑù:

mangled map = (*.html *.htm)

ÓÐÒ»¸ö·Ç³£ÓÐÓõľ­ÑéÊÇɾµôÔÚCDROM¹âÅÌÉÏһЩÎļþÃûºóÃæÌÖÈËÑáµÄ;1(Ö»ÓÐÔÚһЩUNIX¿ÉÒÔ¿´µ½ËüÃÇ).Ϊ´Ë¿ÉÒÔÕâÑùÓ³É䣺(*;1 *;).

ȱʡÉèÖÃ: ûÓÐ mangled map

ʾÀý: mangled map = (*;1 *;)

mangled names (S)
Õâ¸öÑ¡Ïî¿ØÖÆÊÇ·ñÒª°ÑUNIXϵķÇDOSÎļþÃûÓ³ÉäΪDOS¼æÈݵÄÐÎʽ("mangled")²¢Ê¹µÃËüÃÇ¿ÉÒÔ²éÔÄ,»òÕß¼òµ¥µØºöÂÔµôÕâЩ·ÇDOSÎļþÃû.

NAME MANGLING²¿·ÖÓиü¶à¹ØÓÚÈçºÎ¿ØÖÆÕâÀà´¦ÀíµÄÏêϸÐÅÏ¢.

Èç¹ûʹÓÃÁËÕâÖÖÓ³Éä,ÄÇôÆäËã·¨¾ÍÏóÏÂÃæÕâÑù£º

°ÑÎļþÃû×îºóÒ»¸öµã·ûºÅÇ°ÃæÊ×Îå¸ö×ÖĸÊý×Ö×Ö·ûÇ¿ÖÆת»»³É´óд,×÷ΪҪӳÉäÃû×ÖµÄÊ×Îå¸ö×Ö·û.

ÔÚÒªÓ³ÉäÃû×ÖµÄÆðʼ²¿·Ö¼ÓÉÏ"~"·ûºÅ,ºóÃæ¸úÁ½¸ö×Ö·ûµÄÌØÊâÐòÁÐ×Ö´®,¶øÕâ¸öÐòÁÐ×Ö´®ÊÇÓÉԭʼµÄÎļþÃû¶øÀ´£¨Ò²¾ÍÊÇ£ºÔ­ÎļþÃûÈ¥µô×îºóµÄÎļþÀ©Õ¹Ãû£©.Ö»Óе±ÎļþµÄÀ©Õ¹Ãûº¬Óдóд×Öĸ»ò³¤ÓÚÈý¸ö×Ö·ûʱ,ÎļþµÄ×îºóÀ©Õ¹Ãû²Å±»°üº¬ÔÚÉ¢ÁмÆËãÖÐ.

×¢Òâ,Èç¹ûÄ㲻ϲ»¶'~'µÄ»°,¿ÉÒÔÓÃmangling charÑ¡ÏîÀ´Ö¸¶¨ÄãÏëÒªµÄ×Ö·û.

×îºó,À©Õ¹Ãû²¿·ÖµÄÇ°Èý¸ö×Ö·û»á±»±£Áô,Ç¿ÖÆת»»µ½´óд²¢×÷ΪӳÉäºóÃû×ÖµÄÀ©Õ¹Ãû.×îºóµÄÀ©Õ¹Ãû¾ÍÊÇԭʼÎļþÃûÖÐ×îºóÒ»¸ö'.'ÓÒÃæµÄÄDz¿·Ö.Èç¹ûÎļþÃûÖÐûÓÐ'.',ÄÇôӳÉäºóµÄÎļþÃûҲûÓÐÀ©Õ¹Ãû²¿·Ö(³ý·ÇÓÃÁË"hidden files" - ²Î¼ûºóÃæµÄ½éÉÜ).

unixµÄÎļþÃûÈç¹ûÒԵ㿪ʼ,ÄÇôºÃ±ÈDOSÖеÄÒþ²ØÎļþ.ÕâЩÎļþÓ³ÉäºóµÄÎļþÃû¾Í»áÄõôµã·ûºÅ²¢ÓÃ"___"À´×÷ΪËüµÄÀ©Õ¹Ãû,¶ø²»¹ÜÔ­À´µÄÀ©Õ¹ÃûÊÇʲô("___"ÊÇÈý¸öÏ»®Ïß).

´óд×ÖĸÊý×Ö×Ö·û×é³ÉÁËÁ½Î»É¢ÁÐÖµ.

Èç¹ûĿ¼ÖеÄÎļþÓëÒªÓ³ÉäµÄÎļþÃûʹÓÃÁËÏàͬµÄÇ°Îåλ×Ö·û,ÕâÑùµÄËã·¨»áµ¼ÖÂÃû³Æ³åÍ»,²»¹ý·¢Éú³åÍ»µÄ¿ÉÄÜÐÔÊÇ1/1300.

Ãû³ÆÓ³ÉäÔÊÐíµ±ÐèÒª±£Áôunix³¤ÎļþÃûʱÔÚunixĿ¼ÓëWindows/DOSÖ®¼ä¿½±´Îļþ.´ÓWindows/DOSÖп½¹ýÀ´µÄunixÎļþ¿ÉÒÔ¸ü»»ÐµÄÀ©Õ¹Ãû²¢±£ÁôͬÑùµÄÖ÷ÎļþÃû.Ãû³ÆÓ³Éä²¢²»»áÔÚת»»Ê±¸ü¸Äʲô¶«Î÷.

ȱʡÉèÖÃ: mangled names = yes

mangled stack (G)
Õâ¸öÑ¡Ïî¿ØÖÆÁËÓ³ÉäÎļþÃûµÄÊýÁ¿,ÒÔ±ãÈÃSamba·þÎñÆ÷smbd(8)¶ÔÆä½øÐлº´æ.

Õ»Àï±£´æÁË×î½üÓ³ÉäµÄ»ù±¾ÎļþÃû(À©Õ¹ÃûÖ»ÓÐÔÚ³¬¹ý3¸ö×Ö·û»òÕß°üº¬´óд×Ö·ûʱ²Å»á±£Áô).

Õ»ÖµÉèµÃÉÔ´óһЩ,¶ÔÓÚÓ³ÉäunixµÄ³¤ÎļþÃû²Ù×÷»á¸ü˳ÀûһЩ.µ«ÊÇ,Ëü»áʹĿ¼·ÃÎʱäµÃ¸üÂý£»Ð¡Ò»Ð©µÄÕ»¿ÉÒÔ±£´æÔÚ·þÎñÆ÷µÄÄÚ´æÖÐ(ÿ¸öÕ»ÔªËØÕ¼256¸ö×Ö½Ú).

²¢²»±£Ö¤ÔÚת»»³¤ÎļþÃûʱ¾ø¶ÔÕýÈ·ÎÞÎó,×¼±¸ºÃÃæ¶Ô¿ÉÄܳöÏֵľªÆæ.

ȱʡÉèÖÃ: mangled stack = 50

ʾÀý: mangled stack = 100

mangle prefix (G)
controls the number of prefix characters from the original name used when generating the mangled names. A larger value will give a weaker hash and therefore more name collisions. The minimum value is 1 and the maximum value is 6.

mangle prefix is effective only when mangling method is hash2.

ȱʡÉèÖÃ: mangle prefix = 1

ʾÀý: mangle prefix = 4

mangling char (S)
Õâ¸öÑ¡ÏîÖ¸¶¨ÔÚname mangling²Ù×÷ÖÐʹÓÃʲôÑùµÄ×Ö·û×÷Ϊmagic×Ö·û.ȱʡÊÇÓÃÁË'~',²»¹ýÓÐЩÈí¼þ¿ÉÄÜ»áÔÚʹÓÃÉÏÊܵ½Ä³Ð©·Á°­.¿ÉÒÔÉ趨ΪÄãÏëÒªµÄ×Ö·û.

ȱʡÉèÖÃ: mangling char = ~

ʾÀý: mangling char = ^

mangling method (G)
controls the algorithm used for the generating the mangled names. Can take two different values, "hash" and "hash2". "hash" is the default and is the algorithm that has been used in Samba for many years. "hash2" is a newer and considered a better algorithm (generates less collisions) in the names. However, many Win32 applications store the mangled names and so changing to the new algorithm must not be done lightly as these applications may break unless reinstalled.

ȱʡÉèÖÃ: mangling method = hash2

ʾÀý: mangling method = hash

map acl inherit (S)
This boolean parameter controls whether smbd(8) will attempt to map the 'inherit' and 'protected' access control entry flags stored in Windows ACLs into an extended attribute called user.SAMBA_PAI. This parameter only takes effect if Samba is being run on a platform that supports extended attributes (Linux and IRIX so far) and allows the Windows 2000 ACL editor to correctly use inheritance with the Samba POSIX ACL mapping code.

ȱʡÉèÖÃ: map acl inherit = no

map archive (S)
Õâ¸öÑ¡Ïî¾ö¶¨ÁËÊÇ·ñ°ÑDOSµÄ¹éµµÊôÐÔÓ³ÉäΪUNIX¿ÉÖ´ÐÐλ.ÔÚÎļþÐ޸ĺóDOSµÄ¹éµµÎ»»á±»É趨µ½ÎļþÉÏ.±£³Ö¹éµµÎ»µÄÒ»¸öÀíÓÉÊÇʹµÃSamba»òÕßÄãµÄPCÔÚн¨ÈκÎÎļþµÄʱºò£¬²»»áΪËüÃÇÉèÖÃUNIX¿ÉÖ´ÐÐÊôÐÔ¡£ÄÇÑù¶ÔÓÚ¹²ÏíÔ´´úÂë¡¢ÎĵµµÈµÈ·Ç³£ÈÃÈËÑá·³¡£

×¢ÒâÕâ¸öÑ¡ÏîÐèÒªÔÚcreate maskÐûÓÐÅųýÎļþÊôÖ÷µÄÖ´ÐÐȨÏÞλ(Ò²¾ÍÊÇ˵Ëü±ØÐë°üº¬100).²Î¼ûcreate maskÑ¡ÏîÖеÄÃèÊö.

ȱʡÉèÖÃ: map archive = yes

map hidden (S)
Õâ¸öÑ¡Ïî¾ö¶¨DOSϵÄÒþ²ØÎļþÊÇ·ñÒªÓ³ÉäΪUNIXÈ«¾Ö¿ÉÖ´ÐÐλ.

×¢ÒâÕâ¸öÑ¡ÏîÐèÒªÔÚcreate maskÖÐûÓÐÅųýËùÓÐÓû§µÄÖ´ÐÐȨÏÞλ(Ò²¾ÍÊÇ˵Ëü±ØÐë°üº¬001).²Î¼ûcreate maskÑ¡ÏîÖеÄÃèÊö.

ȱʡÉèÖÃ: map hidden = no

map system (S)
Õâ¸öÑ¡Ïî¾ö¶¨DOSϵÄϵͳÎļþÊÇ·ñÒªÓ³ÉäΪUNIX×é¿ÉÖ´ÐÐλ.

×¢ÒâÕâ¸öÑ¡ÏîÐèÒªÔÚcreate maskÖÐûÓÐÅųý×éÓû§µÄÖ´ÐÐȨÏÞλ(Ò²¾ÍÊÇ˵Ëü±ØÐë°üº¬010).²Î¼ûcreate maskÑ¡ÏîÖеÄÃèÊö.

ȱʡÉèÖÃ: map system = no

map to guest (G)
Õâ¸öÑ¡ÏîÖ»ÔÚ°²È«Ä£Ê½²»Êǹ²Ïí¼¶(security=share)ʱ²ÅÓÐÓÃ,Ò²¾ÍÊÇÑ¡ÓÃÁËÓû§°²È«¼¶,·þÎñÆ÷°²È«¼¶»òÕßÓò°²È«¼¶(user, server, ºÍdomain).

Õâʱ,Ñ¡Ïî»áÓÐÈýÖÖ²»Í¬µÄÖµ,·Ö±ð֪ͨsmbd(8)ÔÚÓû§ÒÔ·Ç·¨Éí·ÝµÇ¼ʱ×÷ºÎÏàÓ¦´¦Àí.

ÕâÈýÖÖÉ趨ÊÇ:

Never - Òâ˼ÊÇÓû§µÇ¼ʱÓÃÁ˸ö·Ç·¨¿ÚÁî²¢ÇÒ±»·þÎñÆ÷Ëù¾Ü.ÕâÊǸöȱʡֵ.

Bad User - Òâ˼ÊÇÓû§µÇ¼ʱÓÃÁË·Ç·¨¿ÚÁî²¢ÇÒ±»·þÎñÆ÷Ëù¾Ü,³ý·ÇÓû§Ãû²»´æÔÚ,·ñÔòÒ²¿ÉÒÔÒÔÀ´±öÉí·ÝµÇ¼²¢Ó³Éäµ½¶ÔÓ¦µÄguest accountÕ˺Å.

Bad Password - Òâ˼ÊÇÓû§µÇ¼ʱ¼´Ê¹ÓÃÁË·Ç·¨¿ÚÁî,µ«ÊÇ»¹»áÒÔÀ´±öÉí·ÝµÇ¼²¢Ó³Éäµ½¶ÔÓ¦µÄguestÕ˺Å.¿ÉÄܳöÏÖÕâÑùµÄÎÊÌâ,¾ÍÊÇÓû§ËäÈ»Êä´íÁË¿ÚÁî,È´·Ç³£Æ½¾²µØÒÔ¡°À´±ö¡±Éí·ÝµÇ¼µ½ÏµÍ³ÉÏ¡£ËûÃDz»Ã÷°×ΪʲôËûÃDz»ÄÜ·ÃÎÊÄÇЩËûÃÇÈÏΪ¿ÉÒÔ·ÃÎʵÄ×ÊÔ´,ÒòΪÔڵǼʱûÓÐÈκÎÐÅÏ¢ÌáʾËûÃÇÊä´íÁË¿ÚÁî¡£ËùÒÔÓ¦¸ÃСÐÄʹÓÃËü,ÒÔ±ÜÃâ²»±ØÒªµÄÂé·³. Helpdesk services will hate you if you set the map to guest parameter this way :-).

×¢Ò⵱ʹÓù²Ïí¼¶ÒÔÍâµÄÆäËü°²È«Ä£Ê½Ê±,ÒªÉ趨Õâ¸öÑ¡ÏÒÔʹ"Guest"¹²Ïí×ÊÔ´·þÎñ·¢»Ó×÷ÓÃ.ÒòΪÔÚÕâЩ°²È«¼¶Ä£Ê½ÖÐ,Óû§ÇëÇóµÄ¹²Ïí×ÊÔ´ÃûÔÚ·þÎñÆ÷³É¹¦ÑéÖ¤Óû§µÇ¼ǰ²»»á·¢Ë͵½·þÎñÆ÷×÷´¦Àí,ËùÒÔ·þÎñÆ÷¾ÍÔÚ²»ÄÜ´¦ÀíÁª½ÓÑéÖ¤½á¹ûʱΪÁª½ÓÌṩ"Guest"¹²Ïí.

¶ÔÓÚÄÇЩÒÔÇ°µÄ°æ±¾,Õâ¸öÑ¡Ïî»áÓ³Éäµ½±àÒëʱËùÓõÄlocal.hÎļþÀﶨÒåµÄGUEST_SESSSETUP±äÁ¿µÄÖµ.

ȱʡÉèÖÃ: map to guest = Never

ʾÀý: map to guest = Bad User

max connections (S)
×î´óÁª½ÓÊý¾ÍÊÇÔÊÐíͬʱÁª½Óµ½Ò»¸ö×ÊÔ´·þÎñµÄ×î´óÊýÁ¿ÏÞÖÆ.ÔÚmax connections´óÓÚ0µÄÇé¿öÏÂ,Èç¹ûÁª½ÓÊý³¬¹ýÁË×î´óÁª½ÓÊýÉ趨ʱ,³¬³öµÄÁª½Ó½«±»¾Ü¾ø.Èç¹ûÉèΪ0µÄ»°¾ÍûÓÐÕâÑùµÄÁª½ÓÏÞÖÆÁË.

ΪÁËʵÏÖÕâÑùµÄ¹¦ÄÜ,ϵͳ»áʹÓüǼËø¶¨Îļþ.Ëø¶¨Îļþ´æ·ÅÔÚlock directoryÑ¡ÏîÖ¸¶¨µÄĿ¼ÖÐ.

ȱʡÉèÖÃ: max connections = 0

ʾÀý: max connections = 10

max disk size (G)
¿ØÖÆ´ÅÅÌʹÓõÄÉÏÏÞ.Èç¹û°ÑËüÉèΪ100µÄ»°,ËùÓеĹ²Ïí×ÊÔ´ÈÝÁ¿¶¼²»»á³¬¹ý100M.

×¢ÒâÕâ¸öÑ¡Ïî²¢²»ÊÇÏÞÖƹÜÀíÔ±Íù´ÅÅÌÉÏ´æ·ÅÊý¾ÝµÄÈÝÁ¿.ÔÚÉÏÃæËù˵µÄÇé¿öÖÐ,¹ÜÀíÔ±ÈÔÈ»¿ÉÒÔ´æ·Å³¬¹ý100MµÄÊý¾Ýµ½´ÅÅÌÉÏ,µ«Èç¹û¿Í»§²éѯʣÓà´ÅÅÌ¿Õ¼ä»ò´ÅÅÌ×Ü¿Õ¼äµÄ»°,ËùµÃµ½µÄ½á¹û¾ÍÖ»ÔÚÕâ¸ö max disk sizeÖ¸¶¨µÄÈÝÁ¿·¶Î§Ö®ÄÚ.

ʹÓÃÕâ¸öÑ¡ÏîÖ÷ÒªÊÇΪÁ˶ÔһЩ·è¿ñʹÓôÅÅÌ¿Õ¼äµÄÈí¼þ½øÐÐÒ»¶¨µÄÏÞÖÆ,ÌرðÊÇËüÃÇ¿ÉÄÜ»áʹÓó¬¹ý1GÉÏÒԵĴÅÅÌ¿Õ¼ä.

°ÑÕâ¸öÑ¡ÏîÉèΪ0˵Ã÷ûÓÐÏÞÖÆ.

ȱʡÉèÖÃ: max disk size = 0

ʾÀý: max disk size = 1000

max log size (G)
Õâ¸öÑ¡Ïî(Ò»¸ökBΪµ¥Î»µÄÕûÊý)ÓÃÀ´Ö¸¶¨Ê¹ÓõļǼÎļþ×î´óµ½¶àÉÙÈÝÁ¿.samba»áÖÜÆÚÐԵؼì²éÕâ¸öÈÝÁ¿,Èç¹û³¬¹ýÕâ¸öÑ¡ÏîÖµ¾Í°ÑÀϵÄÎļþ»»Ãû³ÉÀ©Õ¹ÃûΪ.oldµÄÎļþ.

°ÑÕâ¸öÑ¡ÏîÉèΪ0˵Ã÷ûÓÐÏÞÖÆ.

ȱʡÉèÖÃ: max log size = 5000

ʾÀý: max log size = 1000

max mux (G)
Õâ¸öÑ¡Ïî¿ØÖÆÁ˶ÔÓû§ÔÊÐíµÄ×î´óSMB²¢·¢²Ù×÷Êý.ÄãÓ¦¸Ã²»ÐèÒªÉ趨Õâ¸öÑ¡ÏîµÄ.

ȱʡÉèÖÃ: max mux = 50

max open files (G)
Õâ¸öÑ¡ÏîÏÞ¶¨ÁËÔÚÈÎÒâʱ¼ä¿Í»§¶ËÓÃÒ»¸ö smbd(8)Îļþ·þÎñ½ø³Ì¿ÉÒÔ´ò¿ªµÄ×î´óÎļþÊý.ȱʡµÄÖµ·Ç³£¸ß(10,000),ÒòΪ¶ÔÓÚÿ¸öδ´ò¿ªµÄÎļþֻʹÓÃÆäÖеÄһλ.

´ò¿ªÎļþ¼«ÏÞͨ³£ÓÃUNIXÿ½ø³Ì×î´óÎļþÃèÊö·ûÊýÀ´ÏÞÖƸüºÃ,ËùÒÔÄã²»ÐèҪȥÅöÕâ¸öÑ¡ÏîµÄ.

ȱʡÉèÖÃ: max open files = 10000

max print jobs (S)
This parameter limits the maximum number of jobs allowable in a Samba printer queue at any given moment. If this number is exceeded, smbd(8) will remote "Out of Space" to the client. See all total print jobs.

ȱʡÉèÖÃ: max print jobs = 1000

ʾÀý: max print jobs = 5000

max protocol (G)
´ËÏîµÄÖµÊÇÒ»¸ö×Ö·û´®,¶¨ÒåÁË·þÎñÆ÷Ö§³ÖµÄ×î¸ßЭÒéµÈ¼¶.

¿ÉÄܵÄÖµÊÇ:

CORE: ÔçÆÚ°æ±¾,²»½ÓÊÜÓû§Ãû.

COREPLUS: ÔÚCOREµÄ»ù´¡ÉϸĽøÁËһЩÐÔÄÜ.

LANMAN1: µÚÒ»¸ö±È½ÏÁ÷ÐеÄЭÒé,Ö§³Ö³¤ÎļþÃû.

LANMAN2: ¶ÔLANMAN1½øÐÐÁ˸üÐÂ.

NT1: Ä¿Ç°ÓÃÓÚWindows NT,Ò»°ã³ÆΪCIFS.

ͨ³£,´ËÑ¡Ïî²»±ØÉ趨,ÒòΪÔÚSMBЭÒéÖлá×Ô¶¯Ð­É̲¢Ñ¡ÔñºÏÊʵÄЭÒé.

²Î¼û min protocol

ȱʡÉèÖÃ: max protocol = NT1

ʾÀý: max protocol = LANMAN1

max reported print jobs (S)
This parameter limits the maximum number of jobs displayed in a port monitor for Samba printer queue at any given moment. If this number is exceeded, the excess jobs will not be shown. A value of zero means there is no limit on the number of print jobs reported. See all total print jobs and max print jobs parameters.

ȱʡÉèÖÃ: max reported print jobs = 0

ʾÀý: max reported print jobs = 1000

max smbd processes (G)
This parameter limits the maximum number of smbd(8) processes concurrently running on a system and is intended as a stopgap to prevent degrading service to clients in the event that the server has insufficient resources to handle more than this number of connections. Remember that under normal operating conditions, each user will have an smbd(8) associated with him or her to handle connections to all shares from a given host.

ȱʡÉèÖÃ: max smbd processes = 0 ## no limit

ʾÀý: max smbd processes = 1000

max ttl (G)
Õâ¸öÑ¡Ïî֪ͨnmbd(8) µ±ËüÓù㲥»ò´ÓWINS·þÎñÆ÷ÇëÇóÒ»¸öÃû×Öʱ,Õâ¸öNetBIOSÃû×ÖµÄÓÐЧʱ¼ä('time to live', ÒÔÃë¼Æ)ÊǶ೤.Äã²»ÐèҪȥÅöÕâ¸öÑ¡Ïî,ȱʡֵÊÇ3Ìì.

ȱʡÉèÖÃ: max ttl = 259200

max wins ttl (G)
Õâ¸öÑ¡Ïî֪ͨsmbd(8)³ÌÐòµ±Ëü×÷Ϊһ¸öWINS·þÎñÆ÷ʱ(wins support =true),nmbd³ÐÈϵÄ×NetBIOSÃû×ÖÉú´æʱ¼ä('time to live',ÒÔÃë¼Æ).Äã²»ÐèҪȥ¸Ä±äÕâ¸öÑ¡ÏîµÄ,ȱʡֵÊÇ6Ìì(518400Ãë).

²Î¼û min wins ttl Ñ¡Ïî.

ȱʡÉèÖÃ: max wins ttl = 518400

max xmit (G)
Õâ¸öÑ¡Ïî¿ØÖÆͨ¹ýsambaµÄ×î´ó°üÈÝÁ¿.ȱʡֵÊÇ65535,ͬʱÕâÒ²ÊÇ×î´óÖµ.ÓÐʱÄã¿ÉÄÜÓÃÒ»¸ö½ÏСµÄÖµ¿ÉÒԵõ½¸üºÃµÄÐÔÄÜ.²»¹ýµÍÓÚ2048ͨ³£»áÓÐһЩÎÊÌâ.

ȱʡÉèÖÃ: max xmit = 65535

ʾÀý: max xmit = 8192

message command (G)
µ±·þÎñÆ÷½ÓÊÕµ½Ò»¸öWinPopupÀàËƵÄÐÅϢʱÔËÐÐÒ»¸öÖ¸¶¨µÄÃüÁî.

ͨ³£Õâ¸öÃüÁîËù×ö֮ʶ¼È¡¾öÓÚÄãµÄÏëÏó.

ÀýÈç:

message command = csh -c 'xedit %s;rm %s' &

Õâ¸öÃüÁîÓÃxedit·¢³öÒ»ÌõÐÅÏ¢,È»ºóÔÙɾ³ýËü.×¢ÒâºÜÖØÒªµÄÒ»µãÊÇÕâ¸öÃüÁîÓ¦¸ÃÁ¢¼´·µ»Ø.Õâ¾ÍÊÇΪʲôÔÚÐÐÄ©ÓÃ'&'µÄÔ­Òò.Èç¹ûËüûÓÐÁ¢¼´·µ»ØµÄ»°,¼ÆËã»ú¿ÉÄÜ»áÔÚ·¢ËÍÐÅϢʱµ±µôµÄ(²»¹ýÒ»°ã¶¼»áÔÚ30Ãëºó»Ö¸´).

ËùÓÐÐÅÏ¢¶¼±»ÒÔÈ«¾Ö·Ã¿ÍÓû§Éí·Ý·¢ËÍ.ÃüÁî¿ÉÒÔʹÓñê×¼µÄÌæ»»·û,²»¹ý%u½«²»»áÓÐЧ(ÔÚÕâÀïÓÃ%U¿ÉÄܸüºÃ).

³ýÁ˱ê×¼Ìæ»»µÄ²¿·Ö,»¹¿ÉÒÔÓ¦ÓÃһЩ¸½¼ÓµÄÌæ»»,±ÈÈç:

%s =°üº¬ÏûÏ¢µÄÎļþÃû

%t = ·¢ËÍÐÅÏ¢µÄÄ¿±ê(ºÜ¿ÉÄÜÊÇ·þÎñÆ÷Ãû).

%f = ÐÅÏ¢µÄÀ´Ô´.

Äã¿ÉÒÔÓÃÕâ¸öÃüÁîÀ´·¢ËÍÓʼþ»òÕßÄãÏëÒªµÄÄÚÈÝ.Èç¹ûÄãÓйØÓÚ·¢ËÍÄÚÈݵĺÃÖ÷ÒâÇë֪ͨ¿ª·¢ÈËÔ±.

ÓиöÀý×Ó¿ÉÒÔÒÔÓʼþÐÎʽ·¢ËÍÐÅÏ¢¸øroot£º

message command = /bin/mail -s 'message from %f on %m' root < %s; rm %s

Èç¹ûûÓÐÖ¸¶¨·¢ËÍÐÅÏ¢ËùÓõÄÃüÁî,ÄÇôÕâ¸öÐÅÏ¢²¢²»»á±»·¢³ö,ͬʱSambaÏò·¢ËÍÕß±¨¸æ³ö´í.²»ÐÒµÄÊÇWfWg(Windows for Workgrups)ÍêÈ«ºöÂÔ³ö´í´úÂë,ÌáʾÐÅÏ¢Òѱ»·¢³ö.

Èç¹ûÄãÏëÒªÇÄÇĵØɾµôËüµÄ»°ÇëÓãº

message command = rm %s

ȱʡÉèÖÃ: ûÓÐ message command

ʾÀý: message command = csh -c 'xedit %s; rm %s' &

min passwd length (G)
Óë min password length ͬÒå.

min password length (G)
´ËÏîÉ趨µ±Ö´Ðбä¸üUNIX¿ÚÁîʱsmbd½ÓÊܵÄÃ÷ÎÄ¿ÚÁîµÄ×îС×Ö·û³¤¶È.

²Î¼û unix password sync, passwd programºÍ passwd chat debug Ñ¡Ïî.

ȱʡÉèÖÃ: min password length = 5

min print space (S)
´ËÏîÉ趨һ¸öÓû§¼ÙÍÑ»ú´òÓ¡×÷Òµ±ØÐëµÄ×îСʣÓà´ÅÅÌ¿Õ¼ä.µ±È»ÊÇÓÃkB Ϊµ¥Î».ȱʡÉèΪ0,¾ÍÊÇ˵Óû§×ÜÊÇ¿ÉÒÔ¼ÙÍÑ»ú´òÓ¡×÷Òµ.

²Î¼û printing Ñ¡Ïî¡£

ȱʡÉèÖÃ: min print space = 0

ʾÀý: min print space = 2000

min protocol (G)
The value of the parameter (a string) is the lowest SMB protocol dialect than Samba will support. Please refer to the max protocol parameter for a list of valid protocol names and a brief description of each. You may also wish to refer to the C source code in source/smbd/negprot.c for a listing of known protocol dialects supported by clients.

If you are viewing this parameter as a security measure, you should also refer to the lanman auth Ñ¡Ïî¡£ Otherwise, you should never need to change this Ñ¡Ïî¡£

Default : min protocol = CORE

Example : min protocol = NT1 # disable DOS clients

min wins ttl (G)
´ËÏî֪ͨnmbd(8)µ±ÒÔWINS·þÎñÆ÷µÄÐÎʽ(wins support = yes)Ö´ÐÐʱ,ËüËù³ÐÈϵÄNetBIOSÃû×ÖµÄ×îСÓÐЧʱ¼ä(ÒÔÃëΪµ¥Î»).Õâ¸öÑ¡ÏîÎÞÐè¸ü¸Ä,ȱʡÊÇ6Сʱ(21600Ãë)

ȱʡÉèÖÃ: min wins ttl = 21600

msdfs proxy (S)
This parameter indicates that the share is a stand-in for another CIFS share whose location is specified by the value of the Ñ¡Ïî¡£ When clients attempt to connect to this share, they are redirected to the proxied share using the SMB-Dfs protocol.

Only Dfs roots can act as proxy shares. Take a look at the msdfs root and host msdfs options to find out how to set up a Dfs root share.

ʾÀý: msdfs proxy = \\otherserver\someshare

msdfs root (S)
If set to yes, Samba treats the share as a Dfs root and allows clients to browse the distributed file system tree rooted at the share directory. Dfs links are specified in the share directory by symbolic links of the form msdfs:serverA\\shareA,serverB\\shareB and so on. For more information on setting up a Dfs tree on Samba, refer to ???.

²Î¼û host msdfs

ȱʡÉèÖÃ: msdfs root = no

name cache timeout (G)
Specifies the number of seconds it takes before entries in samba's hostname resolve cache time out. If the timeout is set to 0. the caching is disabled.

ȱʡÉèÖÃ: name cache timeout = 660

ʾÀý: name cache timeout = 0

name resolve order (G)
sambaÌ×¼þÖеÄһЩ³ÌÐòʹÓôËÏîÀ´¾ö¶¨Ê¹ÓõÄÃû×Ö·þÎñÒÔ¼°½âÎöÖ÷»úÃûµ½IPµØÖ·µÄ´ÎÐò.Ö÷ҪĿµÄÊÇ¿ØÖÆnetbiosÃû³ÆÔõÑù½âÎö¡£´ËÑ¡ÏîÁгö²»Í¬µÄÃû×Ö½âÎöÑ¡ÏÒÔ¿Õ¸ñΪ·Ö¸ô·û.

ÕâЩÃû×Ö½âÎöÑ¡ÏîÊÇ£º"lmhosts","host","wins"ºÍ"bcast".ËüÃǾö¶¨ÁËÃû×Ö½âÎöÊÇÒÔÈçÏ·½Ê½µÄ£º

lmhosts : ÔÚsambaµÄlmhostsÎļþÖвéÕÒIPµØÖ·.Èç¹ûlmhostsÎļþµÄÄÚÈÝÐÐÖÐûÓÐÃû×ÖÀàÐ͸½¼ÓÔÚNetBIOSÃûÉÏʱ(²Î¼ûlmhosts (5)ÖеÄÏêϸÃèÊö),ÈκÎÀàÐ͵ÄÃû×Ö¶¼¿ÉÒÔÆ¥ÅäÕâ¸ö²éѯ.

host : Ö´Ðбê×¼µÄÖ÷»úÃûµ½IPµØÖ·µÄ½âÎö²Ù×÷,´Ë²Ù×÷»áʹÓÃϵͳµÄ/etc/hosts,NIS»òÕßÊÇDNSÀ´²éѯ.¾ßÌå·½·¨È¡¾öÓÚ²Ù×÷ϵͳ,ÔÚIRIXºÍSolarisÖнâÎöÃû×ֵķ½·¨¿ÉÄÜÊÇÓÉ/etc/nsswitch.confÎļþÀ´¿ØÖƵÄ.×¢Òâ´Ë·½·¨Ö»ÊÊÓÃÓÚ¶Ô±»²éѯµÄNetBIOSÃû×ÖÀàÐÍΪ0x20(·þÎñÆ÷)»òÕßÊÇ0x1c(Óò¿ØÖÆÆ÷)ʱ²ÅÓÐÓÃ,ÆäËüÀàÐͶ¼»á±»ºöÂÔ.ºóÒ»ÖÖÇé¿öÖ»ÔڻĿ¼ÓòÖÐÓÐÓ㬷µ»ØÒ»¸öÆ¥Åä_ldap._tcp.domain µÄSRV RRÌõÄ¿µÄDNS ²éѯ¡£

wins : ÏòÁÐÔÚwins serverÑ¡ÏîÖеķþÎñÆ÷²éѯһ¸öÃû×Ö¶ÔÓ¦µÄIPµØÖ·.Èç¹ûûÓÐÖ¸¶¨WINS·þÎñÆ÷,ÄÇô´Ë·½·¨¾Í±»ÂÔ¹ýÁË.

bcast : ÏòÔÚinterfacesÑ¡ÏîÖÐÁгöµÄÿһ¸öÒÑÖª±¾µØÍøÂç½Ó¿Ú½øÐй㲥À´×÷²éѯ.ÕâÊÇ×î²»¿ÉÐŵÄÃû×Ö½âÎö·½·¨,³ý·ÇÄ¿±êÖ÷»ú¾ÍÔÚ±¾µØ×ÓÍøÖÐ.

ȱʡÉèÖÃ: name resolve order = lmhosts host wins bcast

ʾÀý: name resolve order = lmhosts bcast host

ÔÚÉÏÀýÖÐÊ×Ïȼì²é±¾µØlmhostsÎļþ,È»ºó³¢ÊԹ㲥,½ÓÏÂÀ´¾ÍÊÇÓÃͨ³£µÄϵͳÖ÷»úÃû²éѯ·½Ê½ÁË.

When Samba is functioning in ADS security mode (security = ads) it is advised to use following settings for name resolve order:

name resolve order = wins bcast

DC lookups will still be done via DNS, but fallbacks to netbios names will not inundate your DNS servers with needless querys for DOMAIN<0x1c> lookups.

netbios aliases (G)
´ËÏîÖ¸¶¨Ò»´®NetBIOSÃû×ÖÈÃnmbd×÷Ϊ¸½¼ÓµÄÃû×Ö½øÐÐÐû²¼.ÕâÑù¾Íʹһ¸ö»úÆ÷ÔÚ¿Éä¯ÀÀÁбíÖпÉÒÔ³öÏÖ¶à¸öÃû×ÖÐÎʽ.Èç¹ûÖ÷»úÊÇä¯ÀÀ·þÎñÆ÷»òµÇ¼·þÎñÆ÷, ¾Í²»»á³öÏÖÕâЩ¸½¼ÓµÄ±ðÃû,¶øÖ»»áʹÓÃËüµÄ³õʼÃû×Ö.

²Î¼û netbios name Ñ¡Ïî¡£

ȱʡÉèÖÃ: ¿Õ×Ö·û´® (ûÓи½¼ÓµÄÃû×Ö)

ʾÀý: netbios aliases = TEST TEST1 TEST2

netbios name (G)
´ËÏî¶ÔÒ»ÒÑÖªµÄsamba·þÎñÆ÷ÉèÖÃËüµÄNetBIOSÃû.ȱʡÇé¿öÏ»áʹÓôËÖ÷»úDNSÃû×ÖµÄÖ÷»úÃû²¿·Ö.Èç¹ûÕâ¸ö·þÎñÆ÷ÊÇ×÷ä¯ÀÀ·þÎñÆ÷»òµÇ¼·þÎñÆ÷ʱ(»òÊÇÖ÷»úDNSÃûµÄµÚÒ»¸ö³É·Öʱ),Õâ¸ö·þÎñÆ÷Ãû½«³ÉΪÕâЩ·þÎñ¶ÔÍâÐû²¼Ê±ËùÓõÄÃû×Ö.

²Î¼û netbios aliases Ñ¡Ïî

ȱʡÉèÖÃ: machine DNS name

ʾÀý: netbios name = MYNAME

netbios scope (G)
This sets the NetBIOS scope that Samba will operate under. This should not be set unless every machine on your LAN also sets this value.

nis homedir (G)
´ËÏî´ÓNISÓ³Éä±íÖÐÈ¡µÃÓÐЧ¹²Ïí·þÎñÆ÷.¶ÔÓÚÓÃ×Ô¶¯×°ÔسÌÐòµÄUNIXϵͳÀ´Ëµ,Óû§µÄÖ÷Ŀ¼¾­³£¸ù¾ÝÐèÒª´ÓÔ¶³Ì·þÎñÆ÷×°Ôص½Ò»¸öÐèÒªµÄ¹¤×÷Õ¾ÉÏ.

Èç¹ûsambaµÇ¼·þÎñÆ÷²»ÊÇ×÷ΪÕæÕýÖ÷Ŀ¼·þÎñÆ÷¶øÊÇͨ¹ýNFSÀ´ÊµÏÖ,ȴ֪ͨÓû§ÒÔSMB·þÎñÆ÷À´Ê¹ÓÃÖ÷Ŀ¼ʱ,Óû§×°ÔØÖ÷Ŀ¼À´½øÐзÃÎÊÐèÒªÁ½¸öÍøÂçÌø²½(Ò»¸öÒÔSMB·½Ê½,ÁíÒ»¸öÒÔNFS·½Ê½×°ÔØ).ÕâÑùµÄʹÓ÷½Ê½ÊǷdz£ÂýµÄ.

´ËÑ¡ÏîÔÊÐíµ±SambaÔÚÖ÷Ŀ¼·þÎñÆ÷·½Ê½ÔËÐÐʱÈÃsamba·´À¡Ä¿Â¼·þÎñÆ÷¶ø·ÇµÇ¼·þÎñÆ÷ÉϵÄÖ÷¹²Ïí×ÊÔ´,ÕâÑùsambaÓû§¿ÉÒÔÖ±½Ó´ÓĿ¼·þÎñÆ÷ÉÏ×°ÔØĿ¼.µ±samba°ÑĿ¼¹²Ïí×ÊÔ´·´À¡¸øÓû§,ÕâʱËü»á²Î¿¼homedir mapÑ¡ÏîÖ¸¶¨µÄNISÓ³Éä±íÈ»ºóÔÙ·´À¡±íÖÐÁгöµÄ·þÎñ.

×¢ÒâҪʹ´ËÏîÆð×÷ÓñØÐëÓÐÒ»¸öÔË×÷ÖеÄNISϵͳ,²¢ÇÒsamba·þÎñÆ÷±ØÐëÊÇÒ»¸öµÇ¼·þÎñÆ÷¡£

ȱʡÉèÖÃ: nis homedir = no

nt acl support (S)
´Ë²¼¶ûÁ¿Ñ¡Ïî¿ØÖÆÊÇ·ñÈÃsmbd(8)³¢ÊÔ°ÑUNIXȨÏÞÓ³Éäµ½NTµÄ·ÃÎÊ¿ØÖÆÁбí.Õâ¸ö²ÎÊýÔÚ2.2.2֮ǰÊÇÒ»¸öÈ«¾ÖÑ¡Ïî¡£

ȱʡÉèÖÃ: nt acl support = yes

ntlm auth (G)
This parameter determines whether or not smbd(8) will attempt to authenticate users using the NTLM encrypted password response. If disabled, either the lanman password hash or an NTLMv2 response will need to be sent by the client.

If this option, and lanman auth are both disabled, then only NTLMv2 logins will be permited. Not all clients support NTLMv2, and most will require special configuration to us it.

Default : ntlm auth = yes

nt pipe support (G)
´Ë²¼¶ûÁ¿Ñ¡Ïî¿ØÖÆÊÇ·ñÈÃsmbd(8)ÔÊÐíWindows NTÓû§Áª½Óµ½NTµÄÌØÊâSMB¹ÜµÀIPC$.Õâͨ³£ÊÇ¿ª·¢ÕßËùÓõĵ÷ÊÔÏî,ÆäËüÓû§¿ÉÒÔ²»¹Ü.

ȱʡÉèÖÃ: nt pipe support = yes

nt status support (G)
This boolean parameter controls whether smbd(8) will negotiate NT specific status support with Windows NT/2k/XP clients. This is a developer debugging option and should be left alone. If this option is set to no then Samba offers exactly the same DOS error codes that versions prior to Samba 2.2.3 reported.

You should not need to ever disable this Ñ¡Ïî¡£

ȱʡÉèÖÃ: nt status support = yes

null passwords (G)
Allow or disallow client access to accounts that have null passwords. ÔÊÐí»ò½ûÖ¹Óû§ÒÔ¿Õ¿ÚÁîʹÓÃÕ˺Å.

²Î¼ûsmbpasswd(5).

ȱʡÉèÖÃ: null passwords = no

obey pam restrictions (G)
When Samba 3.0 is configured to enable PAM support (i.e. --with-pam), this parameter will control whether or not Samba should obey PAM's account and session management directives. The default behavior is to use PAM for clear text authentication only and to ignore any account or session management. Note that Samba always ignores PAM for authentication in the case of encrypt passwords = yes. The reason is that PAM modules cannot support the challenge/response authentication mechanism needed in the presence of SMB password encryption.

ȱʡÉèÖÃ: obey pam restrictions = no

only guest (S)
Óë guest onlyͬÒå.

only user (S)
´Ë²¼¶ûÁ¿Ñ¡Ïî¿ØÖÆÊÇ·ñÔÊÐíµ±Ç°½øÐÐÁª½ÓËùÓõÄÓû§ÃûûÓÐÁÐÔÚuserÁбíÖÐ.ȱʡÇé¿öÏ´ËÏîÊDZ»½ûÖ¹ÁË,ÕâÑùÓû§Ö»ÒªÌṩ·þÎñÐèÒªµÄÓû§Ãû¾Í¿ÉÒÔÁË.ÉèÖÃÕâ¸öÑ¡ÏǿÖÆ·þÎñÆ÷ʹÓÃuserÁбíÖеĵǼÓû§Ãû£¬ÕâÖ»ÔÚ¹²Ïí¼¶°²È«ÖÐÓÐЧ¡£

ҪעÒâµÄÊÇÉÏÃæµÄ˵·¨Ò²±íÃ÷ÁËsamba²¢²»»á´Ó·þÎñÃû¶øÍÆÑݳöÏàÓ¦µÄÓû§Ãû.ÕâÑùµÄ»°¶ÔÓÚ[homes]¶Î¾Í±È½ÏÂé·³ÁË.Òª±ÜÃâÂé·³µÄ»°ÐèÒªÓÃuser = %S,Õâ¾ä¾Í±íÃ÷ÄãµÄÓû§ÁбíuserÕýºÃ¾ÍÊÇÕâ¸ö·þÎñ×ÊÔ´Ãû,ÕâʱµÄÖ÷Ŀ¼Ãû¾ÍÊÇÓû§Ãû.

²Î¼û user Ñ¡Ïî¡£

ȱʡÉèÖÃ: only user = no

oplock break wait time (G)
´ËÏîµ÷ÕûÐÔµÄÑ¡ÏîÒÔÊÊÓ¦ÔÚWindows 9xºÍWinNTÖпÉÄܳöÏֵĴíÎó.µ±Óû§·¢ÆðÒ»¸ö»áµ¼ÖÂoplockÔÝÍ£ÇëÇó(oplock break request)µÄSMB¶Ô»°Ê±,Èç¹ûsamba¶ÔÆäÏìӦ̫¿ìµÄ»°,¿Í»§¶Ë½«»áʧ°Ü²¢ÇÒ²»ÄÜÏìÓ¦´ËÇëÇó.Õâ¸ö¿Éµ÷ÕûµÄÑ¡Ïî(ÒÔºÁÃëΪµ¥Î»)ÊÇÒ»¸ösambaÔÚÏòÕâÑùµÄ¿Í»§·¢ËÍoplockÔÝÍ£ÇëÇóÇ°µÈ´ýµÄʱ¼äÁ¿.

³ý·ÇÄãÀí½âÁËsambaµÄoplock´úÂë,·ñÔò²»Òª¸Ä±äÕâ¸öÑ¡Ï

ȱʡÉèÖÃ: oplock break wait time = 0

oplock contention limit (S)
ÕâÊǸö·Ç³£¸ß¼¶µÄsmbd(8)µ÷ÕûÑ¡Ïî,ÓÃÒԸĽøÔÚ¶à¸öÓû§Õù¶áÏàͬÎļþʱoplocksÈϿɲÙ×÷µÄЧÂÊ.

¼òµ¥µØ˵£¬Õâ¸öÑ¡ÏîÖ¸¶¨ÁËÒ»¸öÊý×Ö,Èç¹ûÕù¶áÏàͬÎļþµÄÓû§ÊýÁ¿³¬¹ýÁË´ËÉ趨¼«Ï޵Ļ°£¬¼´Ê¹ÓÐÇëÇó£¬smbd(8)Ò²²»ÔÙÈÏ¿ÉoplockµÄ²Ù×÷ÁË.ÕâÑùµÄ»°smbd¾ÍÏóWindows NTÒ»ÑùµÄÔËÐÐ.

³ý·ÇÄãÀí½âÁËsambaµÄoplock´úÂë,·ñÔò²»Òª¸Ä±äÕâ¸öÑ¡Ïî!

ȱʡÉèÖÃ: oplock contention limit = 2

oplocks (S)
´Ë²¼¶ûÁ¿Í¨ÖªsmbdÊÇ·ñ¶Ôµ±Ç°ÇëÇóµÄ¹²Ïí×ÊÔ´ÉϵÄÎļþ´ò¿ª²Ù×÷ÆôÓÃoplocks(»ú»áÐÔµÄËø¶¨²Ù×÷).oplock´úÂë¿ÉÒÔÃ÷ÏÔ¸ÄÉÆ·ÃÎÊsamba·þÎñÆ÷ÎļþµÄËÙ¶È(approx.30% ÉõÖÁ¸ü¶à).ËüÔÊÐí±¾µØ»º´æÎļþ,¶ÔÓÚ²»¿ÉÐÅÀµµÄÍøÂç»·¾³À´Ëµ¿ÉÄÜÐèÒª½ûÖ¹µôÕâ¸öÑ¡Ïî(ÔÚWindows NT·þÎñÆ÷ÉÏËüÊÇȱʡ´ò¿ªµÄ).Çë²Î¿¼samba docs/Ŀ¼ÏµÄSpeed.txtÎļþ.

oplocks»áÓÐÑ¡ÔñÐԵعرÕÿһ¸ö»ù±¾¹²Ïí×ÊÔ´ÉϵÄÌض¨Îļþ.²Î¼û veto oplock files Ñ¡Ïî.ÔÚÓÐЩϵͳÉÏ»áͨ¹ý×îµ×²ãµÄ²Ù×÷ϵͳȷÈÏoplocks.ÕâÑù¾Í¿ÉÒÔÔÚËùÓеķÃÎÊÓëoplockedÎļþÖнøÐÐÊý¾Ýͬ²½,¶ø²»¹Ü´Ë·ÃÎÊÊÇͨ¹ýsamba»òNFS»òÕßÊDZ¾µØµÄUNIX½ø³Ì.²Î¼ûkernel oplocksÑ¡Ïî²é¿´Ï¸½Ú.

²Î¼û kernel oplocks ÒÔ¼° level2 oplocks parameters.

ȱʡÉèÖÃ: oplocks = yes

os2 driver map (G)
The parameter is used to define the absolute path to a file containing a mapping of Windows NT printer driver names to OS/2 printer driver names. The format is:

<nt driver name> = <os2 driver name>.<device name>

For example, a valid entry using the HP LaserJet 5 printer driver would appear as HP LaserJet 5L = LASERJET.HP LaserJet 5L.

The need for the file is due to the printer driver namespace problem described in ???. For more details on OS/2 clients, please refer to ???.

ȱʡÉèÖÃ: os2 driver map = <¿Õ×Ö·û´®>

os level (G)
Õâ¸öÕûÊýÖµ¿ØÖÆÔÚä¯ÀÀÆ÷Ñ¡¾ÙÖÐSambaÐû²¼Ëü±¾ÉíÊÇʲôϵͳ¼¶±ð. ´ËÑ¡ÏîµÄÖµ¾ö¶¨ÁËnmbd(8ÊÇ·ñÓлú»á³ÉΪ±¾µØ¹ã²¥ÇøÓòÄÚ¹¤×÷×é WORKGROUPÖеÄÖ÷¿Øä¯ÀÀÆ÷.

×¢Òâ: ĬÈÏÇé¿öÏ£¬Samba½«ÔÚ±¾µØÖ÷¿Øä¯ÀÀÆ÷Ñ¡¾ÙÖг¬Ô½ËùÓÐM$²Ù×÷ϵͳ²¢ÇÒ»ñʤ£¬³ý·Ç»¹ÓÐWindows NT4.0/2000 Óò¿ØÖÆÆ÷¡£ÕâÒâζ×ÅSambaÖ÷»úµÄ´íÎóÅäÖý«Ê¹Ò»¸ö×ÓÍøµÄä¯ÀÀÎÞЧ¡£²Î¼ûSamba docs/ Ŀ¼ÖеÄBROWSING.txt À´»ñÈ¡ÏêϸÐÅÏ¢¡£

ȱʡÉèÖÃ: os level = 20

ʾÀý: os level = 65

pam password change (G)
With the addition of better PAM support in Samba 2.2, this parameter, it is possible to use PAM's password change control flag for Samba. If enabled, then PAM will be used for password changes when requested by an SMB client instead of the program listed in passwd program. It should be possible to enable this without changing your passwd chat parameter for most setups.

ȱʡÉèÖÃ: pam password change = no

panic action (G)
´ËÏîÊÇÒ»¸ösamba¿ª·¢ÕßʹÓõÄÑ¡ÏîÒÔÔÊÐíµ±smbd(8)»òsmbd(8)³ÌÐò±ÀÀ£Ê±¿ÉÒÔµ÷ÓÃÒ»¸öϵͳÃüÁî.ͨ³£ÕâÖÖ¹¦Äܱ»ÓÃÓÚ·¢³ö¶ÔÎÊÌâµÄ¾¯¸æ.

ȱʡÉèÖÃ: panic action = <¿Õ×Ö·û´®>

ʾÀý: panic action = "/bin/sleep 90000"

paranoid server security (G)
Some version of NT 4.x allow non-guest users with a bad passowrd. When this option is enabled, samba will not use a broken NT 4.x server as password server, but instead complain to the logs and exit.

Disabling this option prevents Samba from making this check, which involves deliberatly attempting a bad logon to the remote server.

ȱʡÉèÖÃ: paranoid server security = yes

passdb backend (G)
This option allows the administrator to chose which backends to retrieve and store passwords with. This allows (for example) both smbpasswd and tdbsam to be used without a recompile. Multiple backends can be specified, separated by spaces. The backends will be searched in the order they are specified. New users are always added to the first backend specified.

This parameter is in two parts, the backend's name, and a 'location' string that has meaning only to that particular backed. These are separated by a : character.

Available backends can include: .TP 3 * smbpasswd - The default smbpasswd backend. Takes a path to the smbpasswd file as an optional argument. .TP * tdbsam - The TDB based password storage backend. Takes a path to the TDB as an optional argument (defaults to passdb.tdb in the private dir directory. .TP * ldapsam - The LDAP based passdb backend. Takes an LDAP URL as an optional argument (defaults to ldap://localhost) LDAP connections should be secured where possible. This may be done using either Start-TLS (see ldap ssl) or by specifying ldaps:// in the URL argument. .TP * nisplussam - The NIS+ based passdb backend. Takes name NIS domain as an optional argument. Only works with sun NIS+ servers. .TP * mysql - The MySQL based passdb backend. Takes an identifier as argument. Read the Samba HOWTO Collection for configuration details. .LP

ȱʡÉèÖÃ: passdb backend = smbpasswd

ʾÀý: passdb backend = tdbsam:/etc/samba/private/passdb.tdb smbpasswd:/etc/samba/smbpasswd

ʾÀý: passdb backend = ldapsam:ldaps://ldap.example.com

ʾÀý: passdb backend = mysql:my_plugin_args tdbsam

passwd chat (G)
Õâ¸ö×Ö´®¿ØÖÆÔÚsmbd(8)ºÍ±¾µØ¿ÚÁî¸ü¸Ä³ÌÐò¼ä¸üÓû§¿ÚÁîʱ·¢ÉúµÄ"chat"¶Ô»°.×Ö·û´®ÃèÊöÒ»¸öÓ¦´ð½ÓÊÕ¶ÔµÄÐòÁÐ,ÈÃsmbd(8)ÓÃÓÚ¾ö¶¨¶Ôpasswd program·¢ËͲ¢µÈ´ý½ÓÊÕÄÄЩ¾ßÌåµÄÄÚÈÝ.Èç¹ûûÓÐÊÕµ½Ô¤¼ÆµÄÊä³öʱ²»»á¸ü¸Ä¿ÚÁî.

Õâ¸öchatÐòÁÐÒ»°ã·¢ÉúÔÚÌض¨µÄÖ÷»úÉÏ£¬È¡¾öÓÚ±¾µØ¿ÚÁî¿ØÖƵķ½·¨(¾ÍÏóNIS»òÕß±ðµÄ).

×¢ÒâÕâ¸öÑ¡Ïî½ö½öÔÚunix password syncÑ¡ÏîÉèÖÃΪyesµÄʱºòÓÐÓᣵ±smbpasswdÎļþÖеÄSMB¿ÚÁî±»¸ü¸ÄʱÊÇÒÔrootÉí·ÝÔËÐеģ¬²»±ØÊäÈë¾ÉÃÜÂëÎı¾. ÕâÒâζ×Åroot±ØÐë¿ÉÒÔÔÚ²»ÖªµÀÓû§ÃÜÂëʱÖØÖÃËûµÄÃÜÂë¡£ÔÚNIS/YP ÖÐÕâÒâζ×Åpasswd³ÌÐò±ØÐëÔÚNISÖ÷¿Ø·þÎñÆ÷ÉÏÔËÐС£

Õâ¸ö×Ö·û´®¿ÉÒÔ°üº¬%nºê£¬ÓÃÓÚÌæ»»ÐÂÃÜÂë¡£chatÐòÁл¹¿ÉÒÔ°üº¬±ê×¼ºê\\n, \\r, \\t ºÍ\\s À´¸ø³ö»»ÐУ¬»Ø³µ£¬tabºÍ¿Õ¸ñ¡£chatÐòÁÐ×Ö·û´®»¹¿ÉÒÔ°üº¬'*' À´Æ¥ÅäÈκÎ×Ö·ûÐòÁС£Ë«ÒýºÅÓÃÀ´½«´ø¿Õ¸ñµÄ×Ö·û´®ÉèΪһ¸öµ¥¶ÀµÄ×Ö·û´®¡£

Èç¹ûÔÚ¶Ô»°ÐòÁеÄÈκβ¿·Ö·¢Ë͵Ä×Ö·û´®ÎªÒ»¸ö¾äºÅ".",ÄÇô²»»á·¢ËÍÈκÎÄÚÈÝ.ͬÑù,Èç¹ûµÈ´ý½ÓÊÕ²¿·ÖÓÐ×Ö·û´®ÊÇÒ»¸ö".",ÄÇô²»µÈ´ýÈκεÄÄÚÈÝ.

Èç¹ûpam password change²ÎÊýÉèÖÃΪyes£¬chat¿ÉÒÔÒÔÈκÎ˳Ðò½øÐУ¬Ã»ÓÐÌض¨µÄÊä³ö£¬ÊÇ·ñ³É¹¦¿ÉÒÔÓÉPAM½á¹ûµÃµ½¡£ÔÚPAM»á»°Öкê\n±»ºöÂÔ¡£

²Î¼û unix password sync, passwd program , passwd chat debug ºÍ pam password change.

ȱʡÉèÖÃ: passwd chat = *new*password* %n\n *new*password* %n\n *changed*

ʾÀý: passwd chat = "*Enter OLD password*" %o\n "*Enter NEW password*" %n\n "*Reenter NEW password*" %n\n "*Password changed*"

passwd chat debug (G)
´Ë²¼¶ûÁ¿Ö¸¶¨¿ÚÁî¶Ô»°½Å±¾Ñ¡ÏîÊÇ·ñÒÔ debugģʽÔËÐÐ.ÔÚµ÷ÊÔģʽÏÂ,·¢ËͺͽÓÊյĿÚÁî¶Ô»°×Ö·û´®»á´òÓ¡µ½debug levelΪ100ʱµÄsmbd(8)¼Ç¼ÎļþÖÐ.ÓÉÓÚÔÚsmbd ¼Ç¼ÖÐÔÊÐíʹÓÃÃ÷ÎÄ¿ÚÁî,ËùÒÔÕâÊǸöΣÏÕµÄÑ¡Ïî.²»¹ýÕâ¸öÑ¡Ïî¿ÉÒÔ°ïÖúSamba¹ÜÀíÔ±ÔÚµ÷ÓÃpasswd programÉèºÃµÄ¿ÚÁî³ÌÐòʱµ÷ÊÔÆäpasswd chat ¶Ô»°½Å±¾,²¢ÇÒÓ¦¸ÃÔÚÍê³ÉÒÔºó°ÑËü¹Ø±Õ.Õâ¸öÑ¡ÏîÔÚÉèÖÃÁËpam password changeÑ¡ÏîʱÎÞЧ¡£È±Ê¡Çé¿öÏÂÕâ¸öÑ¡ÏîÊǹرյÄ.

²Î¼û passwd chat , pam password change , passwd program .

ȱʡÉèÖÃ: passwd chat debug = no

passwd program (G)
Ö¸¶¨ÓÃÓÚÉ趨UNIXÓû§¿ÚÁîµÄ³ÌÐòÃû.³öÏÖ%uµÄµØ·½±íʾÒÔÓû§ÃûÌæ»».ÔÚµ÷ÓÿÚÁî¸ü¸Ä³ÌÐòÇ°»áÏȼì²éÓû§ÃûÊÇ·ñ´æÔÚ.

ÐèҪעÒâµÄÊǺܶà¿ÚÁî³ÌÐòÇ¿µ÷¿ÚÁîÒªºÏ·¨,ÀýÈçÓ¦¸ÃÓÐ×îС³¤¶È»òÕßÊÇ×ÖĸÓëÊý×ֵĻìºÏ.Õâ¿ÉÄÜÔÚһЩ¿Í»§¶Ë(ÈçWfWg)×ܽ«¿ÚÁîתΪ´óд·¢ËÍʱ,ÒýÆðһЩÎÊÌâ.

×¢ÒâÈç¹û°Ñunix password syncÑ¡ÏîÉèΪyesµÄ»°,ÔڸıäsmbpasswdÎļþÖеÄSMB¿ÚÁîʱÊÇÒÔrootÉí·Ýµ÷ÓøĿÚÁî³ÌÐòµÄ.Èç¹û¿ÚÁî¸ü¸Äʧ°ÜµÄ»°,smbd¶ÔSMB¿ÚÁîµÄ¸ü¸ÄÒ²»áʧ°Ü,ÕâÊÇÉè¼ÆʱµÄ»úÖÆ.

Èç¹ûÉ趨ÁËunix password syncÑ¡ÏîµÄ»°,Ö¸¶¨¿ÚÁî³ÌÐòʱ±ØÐëʹÓÃËùÓгÌÐòµÄ¾ø¶Ô·¾¶,±ØÐë¼ì²é°²È«ÎÊÌâ.ȱʡµÄunix password syncÑ¡ÏîÖµÊÇ no.

²Î¼û unix password sync.

ȱʡÉèÖÃ: passwd program = /bin/passwd

ʾÀý: passwd program = /sbin/npasswd %u

password level (G)
ÔÚһЩ¿Í»§¶Ë/·þÎñÆ÷ȺÌåÖÐʹÓôóСд»ìºÏ¿ÚÁî´æÔÚ×ÅÀ§ÄÑ.ÆäÖбȽÏÂé·³µÄÒ»Àà¿Í»§ÊÇWfWg,ÒòΪËüÔÚʹÓÃLANMAN1ЭÒéʱ³öÓÚijЩÀíÓɶøÇ¿µ÷ҪʹÓôóд¿ÚÁî.²»¹ýµ±Ê¹ÓÃCOREPLUSʱ²»ÒªÐÞ¸ÄËü! ÁíÍâÔÚWindows95/98 ²Ù×÷ϵͳÖлá³öÎÊÌâ: ¼´Ê¹Ñ¡ÔñÁ˻ỰÖеÄNTLM0.12ЭÒ飬ÕâЩ¿Í»§¶ËÒ²»á½«Ã÷ÎÄ¿ÚÁîתΪ´óд¡£

´ËÑ¡ÏÒåÁË¿ÚÁî×ÖÖдóд×ÖĸµÄ×î´óÊýÁ¿.

ÀýÈç,¼Ù¶¨¸ø³öµÄ¿ÚÁîÊÇ"FRED".Èç¹û password levelÉèΪ1µÄ»°,ÔÚ"FRED"Ñé֤ʧ°Üʱ»á³¢ÊÔÒÔϵĿÚÁî×éºÏ£º

"Fred", "fred", "fRed", "frEd","freD"

Èç¹ûpassword levelÉèΪ2µÄ»°,¾Í»á³¢ÊÔÏÂÃæµÄ×éºÏ£º

"FRed", "FrEd", "FreD", "fREd", "fReD", "frED", ..

µÈµÈ¡£

°Ñ´ËÑ¡ÏîÉè³ÉµÄÖµÔ½¸ß£¬Ïà¶Ôµ¥Ò»´óСд¿ÚÁîÀ´Ëµ´óСд»ìºÏµÄ¿ÚÁîÔ½ÈÝÒ×Æ¥Åä¡£.²»¹ý,ҪСÐÄʹÓÃÕâ¸öÑ¡Ïî»á½µµÍ°²È«ÐÔ,ͬʱÔö¼Ó´¦ÀíÐÂÁª½ÓËù»¨µÄʱ¼äÁ¿.

Èç¹û°ÑÑ¡ÏîÉèΪ0ʱ»áʹ´¦Àí¿ÚÁîʱֻ×÷Á½ÖÖ³¢ÊÔ - ÏÈÓë¸ø³öµÄ¿ÚÁî±È½Ï,ÔٱȽÏËüµÄÈ«²¿Ð¡Ð´ÐÎʽ.

ȱʡÉèÖÃ: password level = 0

ʾÀý: password level = 4

password server (G)
ͨ¹ýÔÚÕâÀïÖ¸¶¨ÆäËüµÄSMB·þÎñÆ÷»òÕ߻Ŀ¼Óò¿ØÖÆÆ÷,ͬʱʹÓÃsecurity = [ads|domain|server],ÄÜ°ÑÁª½ÓsambaµÄÓû§Ãû/¿ÚÁîºÏ·¨ÐÔÑéÖ¤½»¸øÖ¸¶¨µÄÔ¶³Ì·þÎñÆ÷È¥¸É.

´ËÑ¡ÏîÉ趨ÉÏÃæËù˵µÄÆäËü¿ÚÁî·þÎñÆ÷µÄÃû×Ö»òÕßIPµØÖ·. еÄÓï·¨ÔÊÐíÔÚÁ¬½Óµ½ADS realm·þÎñÆ÷ʱָ¶¨¶Ë¿ÚºÅ¡£ÒªÖ¸¶¨Ä¬ÈϵÄLDAP 389¶Ë¿ÚÖ®ÍâµÄºÅÂ룬¿ÉÒÔ½«¶Ë¿ÚºÅ·ÅÔÚÃû×Ö»òipºóÃ棬ÖмäÓÃÒ»¸öðºÅÁ¬½Ó(±ÈÈç˵£¬192.168.1.100:389)¡£Èç¹ûÄã²»Ö¸¶¨Ò»¸ö¶Ë¿Ú£¬Samba½«Ê¹Óñê×¼µÄLDAP¶Ë¿Útcp/389. ×¢Òâ¶Ë¿ÚºÅÔÚWindowsNT4.0 Óò»òÕßnetbiosÁ¬½ÓµÄ·þÎñÆ÷ÉÏÎÞЧ

Èç¹û²ÎÊýÊÇÒ»¸öÃû³Æ£¬Ëü½«Ê¹Óà name resolve order ÖÐÖ¸¶¨µÄ·½Ê½À´½âÎö¡£

¿ÚÁî·þÎñÆ÷Ó¦¸ÃÊÇʹÓÃ"LM1.2X002"»ò"LM NT 0.12"ЭÒéµÄÖ÷»ú,¶øÇÒËü±¾Éí±ØÐëʹÓÃÓû§¼¶°²È«Ä£Ê½.

×¢Ò⣺ʹÓÿÚÁî·þÎñÆ÷±íÃ÷ÄãµÄUNIXÖ÷»ú(¾ÍÊÇÔËÐÐSambaµÄÄÇ̨)¾ÍÖ»ÓëÄãÖ¸¶¨µÄ¿ÚÁî·þÎñÆ÷¾ßÓÐÏàͬµÄ°²È«µÈ¼¶ÁË.ÔÚûÓÐÍêÈ«ÐÅÈεÄÇé¿öϲ»ÒªÑ¡ÔñʹÓÃÆäËüµÄ¿ÚÁî·þÎñÆ÷.

²»Òª°Ñ¿ÚÁî·þÎñÖ¸ÏòSamba·þÎñÆ÷±¾Éí,Õâ²úÉúÒ»¸öÑ­»·¶øÈ¥²éÕÒÄãµÄSamba·þÎñÆ÷,µ¼ÖÂËÀËø.

ÔÚÖ¸¶¨¿ÚÁî·þÎñÆ÷Ãûʱ¿ÉÒÔʹÓñê×¼µÄÌæ»»·û,¶øʵ¼ÊÄÜÓõĿÉÄÜÖ»ÊÇ%mÕâÒ»¸ö,Õâ¸öÌæ»»·û˵Ã÷Samba·þÎñÆ÷»áÓÃÁªÈëµÄ¿Í»§×÷Ϊ¿ÚÁî·þÎñÆ÷.Èç¹ûÕâÑùÓõĻ°ËµÃ÷Äã·Ç³£ÐÅÈÎÄãµÄ¿Í»§,ͬʱ×îºÃÒÔÖ÷»úÔÊÐí²ßÂÔ¶ÔËûÃǽøÐÐÏÞÖÆ£¡

Èç¹û°Ñ°²È«¼¶securityÑ¡ÏîÉèΪdomain»òÕßadsµÄ»°,Ö¸¶¨µÄÆäËü¿ÚÁî·þÎñÆ÷±ØÐëÊÇÔÚÕâ¸öDomainÖеÄÒ»¸öÖ÷Óò¿ØÖÆÆ÷»ò±¸·ÝÓò¿ØÖÆÆ÷»òÕß'*'.ÁíÍâÖ¸¶¨×Ö·û'*'µÄ»°¾ÍÒÔsamba·þÎñÆ÷»áÔÚÕû¸öÓòÖÐʹÓüÓÃÜÑéÖ¤RPCµ÷ÓÃÀ´ÑéÖ¤Óû§µÇ¼.ʹÓà security = domainµÄºÃ´¦ÊÇ,Èç¹ûÖ¸¶¨Á˼¸¸öpassword serverʱ,smbd »á¶Ôÿһ¸ö½øÐг¢ÊÔÖ±µ½ËüÊÕµ½»ØÓ¦,¶ÔÓÚ³õʼ·þÎñÆ÷µ±»úʱÕâ¾ÍºÜÓÐÓÃÁË.

Èç¹ûpassword serverÑ¡ÏîÉèΪ×Ö·û'*'µÄ»°,samba½«³¢ÊÔͨ¹ý²éѯWORKGROUP<1C>Ãû×ÖÀ´×Ô¶¯²éÕÒÖ÷»òÕß±¸·ÝÓò¿ØÖÆÆ÷²¢ÁªÏµ¾­¹ýÃû×Ö½âÎöµÃµ½µÄIPµØÖ·ÁбíÖеÄÿ¸ö·þÎñÆ÷À´½øÐÐÓû§ÑéÖ¤.

Èç¹û·þÎñÆ÷Áбí°üº¬Ãû×Ö»òIPͬʱҲ°üº¬'*'ʱ£¬ÁÐ±í½«ÊÓΪÊ×Ñ¡Óò¿ØÖÆÆ÷µÄÁÐ±í£¬µ«ÊÇÒ²»áÌí¼ÓÒ»¸ö×Ô¶¯µÄ¶ÔËùÓÐÆäÓàDCµÄ²éÕÒ¡£Samba²»»áͨ¹ý¶¨Î»×î½üµÄDCÀ´ÓÅ»¯ÕâÕÅÁÐ±í¡£

Èç¹ûsecurityÊÇserverµÄ»°,»áÓÐһЩ°²È«¼¶Îªsecurity = domainʱËùûÓеÄÏÞÖÆ£º

Èç¹ûÔÚpassword serverÑ¡ÏîÖÐÖ¸¶¨Á˼¸¸ö¿ÚÁî·þÎñÆ÷µÄ»°,smbdÔÚÁª½Ó¾ßÌåµÄ·þÎñÆ÷ʱ»áʧ°Ü,Ò²²»ÄÜÑéÖ¤ÈκεÄÓû§Õ˺Å.ÕâÊÇ°²È«¼¶Îªsecurity = server ģʽʱSMB/CIFSЭÒéµÄÒ»¸öÏÞÖÆ,²¢ÇÒSambaÎÞ·¨ÐÞ¸Ä.

Èç¹û°ÑWindows NT·þÎñÆ÷×÷Ϊ¿ÚÁî·þÎñÆ÷,Äã±ØÐëÈ·±£Óû§¿ÉÒÔ´ÓSamba·þÎñÆ÷ÉϽøÐеǼ.µ±Ê¹Óà security = serverģʽʱ,ÍøÂçµÇ¼¿´ÆðÀ´ÊÇ´ÓÄÇÀï´¦ÀíµÄ,¶ø²»ÊÇ´ÓÓû§¹¤×÷Õ¾.

²Î¼û security Ñ¡Ïî¡£

ȱʡÉèÖÃ: password server = <¿Õ×Ö·û´®>

ʾÀý: password server = NT-PDC, NT-BDC1, NT-BDC2, *

ʾÀý: password server = windc.mydomain.com:389 192.168.1.101 *

ʾÀý: password server = *

path (S)
´ËÏîÖ¸¶¨¸ø³öµÄ·þÎñÏîËùÓõÄϵͳ·¾¶.ÔÚ·þÎñÏî¾ßÓпɴòÓ¡ÊôÐÔʱ,´òÓ¡¼ÙÍÑ»úÊý¾Ý»áÏÈ´æ·ÅÔÚÕâ¸ö·¾¶ËùÖ¸µÄλÖÃÖÐ. This parameter specifies a directory to which the user of the service is to be given access. In the case of printable services, this is where print data will spool prior to being submitted to the host for printing.

¶ÔÓÚÄÇЩҪ¶Ô·Ã¿ÍÌṩµÄ¿É´òÓ¡·þÎñÀ´Ëµ,·þÎñÏîÓ¦¸ÃÉèΪֻ¶Á,¶øÇÒ·¾¶Ó¦¸ÃÉèΪȫ¾Ö¿ÉдÊôÐÔ²¢¾ßÓÐÕ³ÐÔ(s)λ.Õ⵱Ȼ²»ÊÇÇ¿ÖÆÐÔµÄ,²»¹ý²»ÕâÑù×öµÄ»°¿ÉÄÜ»áÎÞ·¨µÃµ½ÄãËùÏ£ÍûµÄ½á¹û.

·¾¶³öÏÖ%uµÄµØ·½½«ÒÔÕý´¦ÓÚÁª½Ó״̬µÄUNIXÓû§ÃûÀ´Ìæ»»£»Í¬Ñù³öÏÖ%mµÄµØ·½½«ÒÔÇëÇóÁª½ÓµÄÖ÷»úNetBIOSÃûÌæ»».ÔÚÉ趨αÖ÷Ŀ¼ʱ,ÕâÖÖÌæ»»ÏîºÜÓÐÓõÄ.

ËùÖ¸¶¨µÄ·¾¶¶¼ÊÇ»ùÓÚ¸ùĿ¼root dir(Èç¹ûÓеĻ°)µÄ.

ȱʡÉèÖÃ: ÎÞ

ʾÀý: path = /home/fred

pid directory (G)
This option specifies the directory where pid files will be placed.

ȱʡÉèÖÃ: pid directory = ${prefix}/var/locks

ʾÀý: pid directory = /var/run/

posix locking (S)
The smbd(8) daemon maintains an database of file locks obtained by SMB clients. The default behavior is to map this internal database to POSIX locks. This means that file locks obtained by SMB clients are consistent with those seen by POSIX compliant applications accessing the files via a non-SMB method (e.g. NFS or local file access). You should never need to disable this Ñ¡Ïî¡£

ȱʡÉèÖÃ: posix locking = yes

postexec (S)
´ËÏîÖ¸¶¨ÔڶϿª·þÎñʱÔËÐеÄÒ»¸öÃüÁî.ËüʹÓÃͨ³£µÄÌæ»»Ïî.´ËÃüÁîÔÚһЩϵͳÖпÉÄÜÊÇÒÔrootÉí·ÝÀ´ÔËÐеÄ.

Ò»¸öÓÐȤµÄʾÀý£¬ÓÃÓÚжÔØ·þÎñÆ÷×ÊÔ´£º

postexec = /etc/umount /cdrom

²Î¼û preexec.

ȱʡÉèÖÃ: ÎÞ (²»Ö´ÐÐÃüÁî)

ʾÀý: postexec = echo

preexec (S)
´ËÏîÖ¸¶¨ÔÚÁª½Óµ½·þÎñʱÔËÐÐÒ»¸öÃüÁî.ͨ³£ÕâÒ²¿ÉÒÔÓÃһЩÌæ»»Ïî.

Ò»¸öÓÐȤµÄʾÀý£¬ÔÚÓû§Ã¿Ò»´ÎµÇ¼ʱÏò¶Ô·½·¢ËÍÒ»¸ö»¶Ó­ÐÅÏ¢£º(Ò»Ìõ¸ñÑÔ£¿)

preexec = csh -c 'echo

µ±È»,Ò»¶Îʱ¼äÒÔºóÕâÀàÐÅÏ¢¿ÉÄܾͱȽÏÌÖÑáÁË:-)

²Î¼û preexec close ºÍ postexec .

ȱʡÉèÖÃ: ÎÞ (²»Ö´ÐÐÃüÁî)

ʾÀý: preexec = echo

preexec close (S)
´Ë²¼¶ûÁ¿Ñ¡Ïî¿ØÖÆÊÇ·ñ´Ópreexec ·µ»ØµÄ·ÇÁã´úÂë»á¹Ø±ÕËùÁª½ÓµÄ·þÎñ.

ȱʡÉèÖÃ: preexec close = no

prefered master (G)
ÕâÊÇΪƴд´íÎó×¼±¸µÄ¡£Çë²é¿´ preferred master :-)

preferred master (G)
´Ë²¼¶ûÁ¿Ñ¡Ïî¿ØÖÆnmbd(8)ÊÇ·ñ×÷Ϊ¹¤×÷×éÀïµÄÊ×Ñ¡Ö÷ä¯ÀÀÆ÷.

Èç¹ûÉè´ËÑ¡ÏîΪyesʱ,nmbd»áÔÚÆô¶¯Ê±Ç¿ÖƽøÐÐÒ»´ÎÑ¡¾Ù,ËüÓÐһЩÓÐÀûÌõ¼þÀ´Ó®µÃÑ¡¾Ù.ÍƼö°Ñ´ËÑ¡ÏîÓë domain master = yesÁªºÏʹÓÃ,ÕâÑùnmbd¿ÉÒÔ±£Ö¤³ÉΪһ¸öÓòä¯ÀÀÆ÷.

СÐÄʹÓôËÏî,ÒòΪÈç¹ûÔÚÏàͬµÄ×ÓÍøÄÚÓжà¸öÖ÷»ú(²»¹ÜÊÇSamba·þÎñÆ÷£¬Windows95»¹ÊÇNT)²Î¼ÓÑ¡¾ÙµÄ»°,ËûÃÇÿ¸ö¶¼»áÖÜÆÚÐÔ²»¶ÏµØ³¢ÊÔ³ÉΪ±¾µØÖ÷ä¯ÀÀÆ÷,Õâʱ»áÔì³É²»±ØÐëµÄ¹ã²¥½»Í¨Á÷Á¿²¢½µµÍä¯ÀÀÐÔÄÜ.

²Î¼û os level.

ȱʡÉèÖÃ: preferred master = auto

preload (G)
´ËÑ¡ÏÒåÁËÒª×Ô¶¯¼ÓÈëµ½ä¯ÀÀÁбíµÄ·þÎñÏîÇåµ¥.Õâ¶ÔÓÚhomesºÍprinters·þÎñÏî·Ç³£ÓÐÓÃ,·ñÔòÕâЩ·þÎñ½«ÊDz»¿É¼ûµÄ.

×¢Òâ,Èç¹ûÄãÏë¼ÓÔØprintcapÀïËùÓеĴòÓ¡»ú,ÄÇôÓÃload printers»á¸üÈÝÒ×.

ȱʡÉèÖÃ: no preloaded services

ʾÀý: preload = fred lp colorlp

preload modules (G)
This is a list of paths to modules that should be loaded into smbd before a client connects. This improves the speed of smbd when reacting to new connections somewhat.

ȱʡÉèÖÃ: preload modules =

ʾÀý: preload modules = /usr/lib/samba/passdb/mysql.so+++

preserve case (S)
´ËÏî¿ØÖƽ¨Á¢ÐµÄÎļþʱȡÃûÊÇ·ñʹÓÃÓû§´«µÝµÄ´óСд,»¹ÊÇÇ¿ÖÆʹÓÃdefault case .

ȱʡÉèÖÃ: preserve case = yes

²Î¼ûNAME MANGLING¶ÎÖеÄÍêÕûÌÖÂÛ.

printable (S)
Èç¹û´ËÏîÉèΪyes,ÄÇôÓû§¿ÉÒÔ¶Áд²¢·¢ËÍ´òÓ¡»º´æÎļþµ½·þÎñÏîÖ¸¶¨µÄĿ¼ÖÐ.

×¢ÒâÒ»¸ö¿É´òÓ¡µÄ·þÎñ×ÜÊÇÔÊÐíͨ¹ý»º´æ´òÓ¡Êý¾ÝµÄ·½·¨Ïò·þÎñÏî·¾¶ÖÐÖ´ÐÐд²Ù×÷(ÐèÒªÓû§ÓпÉдȨÏÞ).read onlyÑ¡Ïî¿ØÖÆÖ»ÔÊÐí²»¿É´òÓ¡µØ·ÃÎÊ×ÊÔ´.

ȱʡÉèÖÃ: printable = no

printcap (G)
Óë printcap name ͬÒå.

printcap name (S)
´ËÏîÓÃÓÚ¸²¸Çµô±àÒëʱ²úÉúµÄȱʡprintcapÃû(ͨ³£ÊÇ/etc/printcap).²Î¼û[printers]¶ÎµÄÌÖÂÛ,Ëü˵Ã÷ÁËΪʲôҪÕâÑù×öµÄÀíÓÉ.

To use the CUPS printing interface set printcap name = cups . This should be supplemented by an addtional setting printing = cups in the [global] section. printcap name = cups will use the "dummy" printcap created by CUPS, as specified in your CUPS configuration file.

ÔÚ¿ÉÒÔÓÃlpstatÃüÁîÁгö¿ÉÓôòÓ¡»úµÄÁбíµÄSystem VϵͳÉÏ,¿ÉÒÔÓÃprintcap name = lpstat À´×Ô¶¯»ñµÃ¿ÉÓôòÓ¡»úÁбí.Õâ¶ÔÓÚÅäÖÃsambaʱ¶¨Òå³ÉSYSVµÄϵͳ(Õâ¾Í°üÀ¨Á˺ܶà»ùÓÚSystem VµÄϵͳ)À´ËµÊÇȱʡÇé¿ö.Èç¹ûÔÚÕâЩϵͳÉÏÉèºÃprintcap nameΪlpstatµÄ»°,samba¾Í»áÖ´ÐÐlpstat -v²¢³¢ÊÔ·ÖÎöÊä³öÐÅÏ¢ÒÔ»ñµÃÒ»·Ý´òÓ¡»úÁбí.

ͨ³£×îСµÄprintcapÎļþ¿´ÆðÀ´¾ÍÏóÏÂÃæÕâÑù£º

print1|My Printer 1
print2|My Printer 2
print3|My Printer 3
print4|My Printer 4
print5|My Printer 5

ÎÒÃÇ¿´µ½'|'·ûºÅÓÃÀ´¶¨Òå´òÓ¡»úµÄ±ðÃû.µÚ¶þ¸ö´øÓпոñµÄ±ðÃûÆäʵÊÇÌáʾSambaËüÊÇ×¢ÊÍ.

ÔÚAIXÖÐĬÈϵÄprintcapÎļþÃûÊÇ/etc/qconfig. Èç¹ûÔÚÎļþÃûÖÐÕÒµ½qconfig×ÖÑù£¬Samba½«¼Ù¶¨ÎļþÊÇAIX µÄqconfig¸ñʽ¡£

ȱʡÉèÖÃ: printcap name = /etc/printcap

ʾÀý: printcap name = /etc/myprintcap

print command (S)
µ±Ò»¸ö´òÓ¡×÷ÒµÍêÈ«»º³åµ½ÁË·þÎñÏîʱ,´ËÏîÖ¸¶¨µÄÃüÁî¾ÍÄܹýµ÷ÓÃsystem()À´´¦ÀíÄÇЩ»º´æÎļþ.ͨ³£ÎÒÃÇÖ¸¶¨µäÐ͵ÄÃüÁîÀ´·¢ËÍ»º´æÎļþµ½Ö÷»úµÄ´òÓ¡×Óϵͳ,²»¹ýÒ²²»Ò»¶¨ÒªÕâÑù.·þÎñÆ÷²»»áɾ³ýÄÇЩ»º´æÎļþ,ËùÒÔÄãÖ¸¶¨µÄÈκÎÃüÁӦµ±ÔÚ´¦ÀíÍêÒÔºóɾ³ýÎļþ,·ñÔòµÄ»°¾ÍÐèÒªÊÖ¹¤À´É¾³ý¾ÉµÄ»º´æÎļþÁË.

´òÓ¡ÃüÁîÊÇÒ»¸ö¼òµ¥µÄÎı¾×Ö·û´®¡£Ëü¿ÉÒÔÔÚºêÌæ»»Ö®ºóÖð×Ö´«µÝ¸øϵͳ¡£

%s, %f - »º³åÎļþÃû·¾¶

%p - Êʵ±µÄ´òÓ¡»úÃû

%J - ¿Í»§Ìá½»µÄ×÷ÒµÃû

%c - »º³åµÄ×÷ÒµÐèÒª´òÓ¡µÄÒ³Êý

%z -»º³åµÄ´òÓ¡×÷ÒµµÄ´óС(ÒÔ×Ö½Ú¼Æ)

´òÓ¡ÃüÁîÖÁÉÙ±ØÐë°üº¬%s»ò%fÌæ»»·ûÖеÄÒ»¸ö,¶ø%pÊǸö¿ÉÑ¡Ïî.ÔÚÌá½»´òÓ¡×÷ҵʱ,Èç¹û²»Ìṩ´òÓ¡»úÃûµÄ»°,%pÌæ»»·û»á´Ó´òÓ¡ÃüÁîÖÐɾµô.

Èç¹ûÔÚ[global]¶ÎÖÐÖ¸¶¨ÁË´òÓ¡ÃüÁî,Ëü½«±»ÓÃÓÚÈκοɴòÓ¡ÐԵķþÎñÏî,¶ø²»ÔÙÐèÒªÔÚËüÃÇÖ®Öе¥¶ÀÖ¸¶¨ÁË.

Èç¹û¼ÈûÓжԿɴòÓ¡ÐÔ·þÎñÏîµ¥¶ÀÖ¸¶¨´òÓ¡ÃüÁîÓÖûÓÐÖ¸¶¨Ò»¸öÈ«¾ÖµÄ´òÓ¡ÃüÁîʱ,¼ÙÍÑ»úÎļþËäÈ»»á½¨Á¢È´²»»á±»´¦ÀíÒ²²»»á±»É¾³ý(ÕâºÜÖØҪŶ).

×¢ÒâÔÚijЩUNIXÉÏÒÔnobodyÕ˺ÅÉí·Ý½øÐдòÓ¡»áµ¼ÖÂʧ°Ü.Èç¹û·¢ÉúÁËÕâÑùµÄÇé¿öÇ뽨Á¢Ò»¸öµ¥¶ÀµÄÓдòӡȨµÄ·Ã¿ÍÕ˺Ų¢ÔÚ[global]¶ÎÀïÉèÖÃguest accountÑ¡Ïî.

Èç¹ûÄãÃ÷°×ÃüÁîÊÇÖ±½Ó´«µÝ¸øshellµÄ»°£¬Äã¿ÉÒÔ×éÖ¯·Ç³£¸´ÔӵĴòÓ¡ÃüÁî.¾ÙÀýÀ´Ëµ,ÏÂÃæµÄÃüÁî»á¼Ç¼һ¸ö´òÓ¡×÷Òµ,´òÓ¡Õâ¸öÎļþÈ»ºóɾµôËü.×¢ÒâÕâÀïµÄ';'ÊÇshell½Å±¾ÃüÁî³£Óõķָô·û.

print command = echo Printing %s >> /tmp/print.log; lpr -P %p %s; rm %s

Äã¿ÉÄܱØÐë¸ù¾ÝƽʱÔÚϵͳÉÏ´òÓ¡ÎļþµÄ·½Ê½À´¸Ä±äÕâ¸öÃüÁî.ȱʡÇé¿öÏÂ,´ËÑ¡Ïî»á¸ù¾ÝprintingÑ¡ÏîµÄÉ趨¶ø±ä»¯.

ȱʡÉèÖÃ: ¶ÔÓÚ printing = BSD, AIX, QNX, LPRNG »òÕß PLP :

print command = lpr -r -P%p %s

¶ÔÓÚ printing = SYSV »òÕß HPUX :

print command = lp -c -d%p %s; rm %s

¶ÔÓÚ printing = SOFTQ :

print command = lp -d%p -s %s; rm %s

¶ÔÓÚ printing = CUPS :

Èç¹ûSamba ±àÒëʱ¼ÓÈëÁËlibcups, ÄÇôprintcap=cups½«Ê¹ÓÃCUPS APIÀ´Ìá½»×÷ÒµµÈµÈ¡£·ñÔòËüÓÃ-orawÑ¡ÏʹÓÃSystemVÃüÁîÀ´´òÓ¡£¬Ò²¾ÍÊÇ˵Ëü»áÓÃlp -c -d%p -o raw; rm %s.µ±printing = cups, ²¢ÇÒSamba±àÒëʱ¼ÓÈëÁËlibcupsʱ£¬ÈκÎÊÖ¹¤ÉèÖõĴòÓ¡ÃüÁ±»ºöÂÔ¡£

ʾÀý: print command = /usr/local/samba/bin/myprintscript %p %s

printer (S)
Óë printer name ͬÒå¡£

printer admin (S)
This is a list of users that can do anything to printers via the remote administration interfaces offered by MS-RPC (usually using a NT workstation). Note that the root user always has admin rights.

ȱʡÉèÖÃ: printer admin = <¿Õ×Ö·û´®>

ʾÀý: printer admin = admin, @staff

printer name (S)
´ËÑ¡ÏîÖ¸¶¨¿É´òÓ¡ÐÔ·þÎñÏîÓÃÀ´´òÓ¡»º´æ×÷ÒµÊý¾ÝµÄ´òÓ¡»ú.

Èç¹ûÔÚ[global]¶ÎÀïÖ¸¶¨ÁË´òÓ¡»úÃû³Æ,ÄÇô¸ø³öµÄ´òÓ¡»ú¾ÍÓÃÓÚÈκοɴòÓ¡ÐÔ·þÎñÏî¶ø²»Ðè¸ö±ðµÄÖ¸¶¨´òÓ¡»úÃû³ÆÁË.

ȱʡÉèÖÃ: ¿Õ (ÔںܶàϵͳÖпÉÄÜÊÇ lp )

ʾÀý: printer name = laserwriter

printing (S)
´ËÑ¡Ïî¿ØÖÆϵͳÉÏÈçºÎ½âÊÍ´òÓ¡»ú״̬ÐÅÏ¢,¶øÈç¹ûÔÚ[global]¶ÎÖж¨Ò壬ËüÒ²»áÓ°Ïìprint command,lpq command,lppause command,lpresume commandºÍlprm commandÕâЩѡÏîµÄȱʡֵ

ͨ³£ÏµÍ³Ö§³Ö¾ÅÖÖ´òÓ¡»ú·ç¸ñ,ËüÃÇÊÇBSD, AIX, LPRNG, PLP, SYSV, HPUX, QNX, SOFTQ,»¹ÓÐ CUPS

ÒªÔÚϵͳÉϲ鿴ʹÓÃÁ˲»Í¬µÄÑ¡ÏîºóÆäËü´òÓ¡ÃüÁîµÄȱʡֵ,¿ÉÒÔÓÃtestparm(1)³ÌÐò.

´ËÏî¿ÉÒÔÔÚÿһ̨´òÓ¡»úÉÏ·Ö±ðÉèÖÃ.

²Î¼û[printers]¶ÎµÄÌÖÂÛ¡£

print ok (S)
Óë printable ͬÒå¡£

private dir (G)
This parameters defines the directory smbd will use for storing such files as smbpasswd and secrets.tdb.

Default :private dir = ${prefix}/private

profile acls (S)
This boolean parameter controls whether smbd(8) This boolean parameter was added to fix the problems that people have been having with storing user profiles on Samba shares from Windows 2000 or Windows XP clients. New versions of Windows 2000 or Windows XP service packs do security ACL checking on the owner and ability to write of the profile directory stored on a local workstation when copied from a Samba share.

When not in domain mode with winbindd then the security info copied onto the local workstation has no meaning to the logged in user (SID) on that workstation so the profile storing fails. Adding this parameter onto a share used for profile storage changes two things about the returned Windows ACL. Firstly it changes the owner and group owner of all reported files and directories to be BUILTIN\\Administrators, BUILTIN\\Users respectively (SIDs S-1-5-32-544, S-1-5-32-545). Secondly it adds an ACE entry of "Full Control" to the SID BUILTIN\\Users to every returned ACL. This will allow any Windows 2000 or XP workstation user to access the profile.

Note that if you have multiple users logging on to a workstation then in order to prevent them from being able to access each others profiles you must remove the "Bypass traverse checking" advanced user right. This will prevent access to other users profile directories as the top level profile directory (named after the user) is created by the workstation profile code and has an ACL restricting entry to the directory tree to the owning user.

ȱʡÉèÖÃ: profile acls = no

protocol (G)
Óë max protocol ͬÒå

public (S)
Óë guest ok ͬÒå

queuepause command (S)
¶¨Òå·þÎñÆ÷ÔÝÍ£´òÓ¡¶ÓÁÐʱҪִÐеÄÃüÁî.

´ËÃüÁîÓ¦¸ÃÊǸöÖ»ÓôòÓ¡»úÃû×÷ΪѡÏîµÄ³ÌÐò»ò½Å±¾,ÒÔ±ãÓÃÀ´Í£Ö¹´òÓ¡¶ÓÁÐ,ʹ´òÓ¡×÷Òµ²»ÔÙÏò´òÓ¡»ú·¢ËÍ.

´ËÃüÁî²»Ö§³ÖWindows for Workgroups,µ«¿ÉÒÔÔÚWindows 95ºÍNTµÄ´òÓ¡»ú´°¿ÚÖз¢ËÍ.

´Ë´¦ÓÃÌæ»»·û%p¿ÉÒÔÌæ´ú´òÓ¡»úÃû³Æ.·ñÔòÕâ¸öÃû³Æ½«±»·ÅÖÃÔÚÃüÁîºóÃæ.

×¢Òâ,ÔÚÃüÁîÖÐʹÓþø¶Ô·¾¶ÊǸöºÃÏ°¹ß,ÒòΪ²»Ò»¶¨¿ÉÒÔ»ñµÃ·þÎñÆ÷µÄPATH±äÁ¿.

ȱʡÉèÖÃ: ÒÀÀµÓÚ printing Ñ¡ÏîµÄÉèÖÃ

ʾÀý: queuepause command = disable %p

queueresume command (S)
¶¨Òå·þÎñÆ÷»Ö¸´ÔÝÍ£Á˵ĴòÓ¡¶ÓÁÐʱҪִÐеÄÃüÁî.¾ÍÊÇÓÃÓÚ»Ö¸´ÒòΪÉÏÃæµÄÑ¡Ïî( queuepause command)¶øµ¼ÖµĽá¹ûµÄ.

´ËÃüÁîÓ¦¸ÃÊǸöÖ»ÓôòÓ¡»úÃû×÷ΪѡÏîµÄ³ÌÐò»ò½Å±¾,ÒÔ±ãÓÃÀ´»Ö¸´´òÓ¡¶ÓÁÐ,ʹ´òÓ¡×÷Òµ¼ÌÐøÏò´òÓ¡»ú·¢ËÍ.

´ËÃüÁî²»Ö§³ÖWindows for Workgroups,µ«¿ÉÒÔÔÚWindows 95ºÍNTµÄ´òÓ¡»ú´°¿ÚÖз¢ËÍ.

´Ë´¦ÓÃÌæ»»·û%p¿ÉÒÔÌæ´ú´òÓ¡»úÃû³Æ.·ñÔòÕâ¸öÃû³Æ½«±»·ÅÖÃÔÚÃüÁîºóÃæ.

×¢Òâ,ÔÚÃüÁîÖÐʹÓþø¶Ô·¾¶ÊǸöºÃÏ°¹ß,ÒòΪ²»Ò»¶¨¿ÉÒÔ»ñµÃ·þÎñÆ÷µÄPATH±äÁ¿.

ȱʡÉèÖÃ: ÒÀÀµÓÚ printing Ñ¡ÏîµÄÉèÖÃ

ʾÀý: queuepause command = enable %p

read bmpx (G)
´Ë²¼¶ûÁ¿Ñ¡Ïî¿ØÖÆÊÇ·ñÈÃsmbd(8)Ö§³Ö"¶à¹¤¶Á¿é"(Read Block Multiplex)µÄSMB.ÏÖÔÚÕâÖÖ·½Ê½ÒѾ­ºÜÉÙÓÃÁË,ËùÒÔȱʡÊÇno.Ò»°ãÄã²»ÐèÒªÉ趨´ËÑ¡Ïî.

ȱʡÉèÖÃ: read bmpx = no

read list (S)
´Ë´¦¸ø³ö¶Ô·þÎñÏîÓÐÖ»¶ÁȨÏÞµÄÓû§Çåµ¥.Èç¹ûÕýÔÚÁª½ÓµÄÓû§ÊôÓÚ´ËÁбí,ÄÇôËûÃǽ«Ã»ÓÐдȨÏÞ,´ËʱÊDz»¹Üread onlyÑ¡ÏîÊÇ·ñÉèÖõÄ.´ËÁбí¿ÉÒÔ°üÀ¨ÓÃÔÚ invalid users Ñ¡ÏîÖÐÃèÊöµÄÓï·¨¶¨ÒåµÄ×éÃû³Æ.

²Î¼û write list ºÍ invalid users Ñ¡Ïî¡£

ȱʡÉèÖÃ: read list = <¿Õ×Ö·û´®>

ʾÀý: read list = mary, @students

read only (S)
×¢ÒâËüÓë writeable ·´Òå.

Èç¹ûÕâ¸ö²ÎÊýÊÇyes, ÄÇô·þÎñµÄÓû§²»Äܽ¨Á¢»òÐ޸ķþÎñĿ¼ÖеÄÎļþ¡£

×¢ÒâÒ»¸ö¿É´òÓ¡µÄ·þÎñ(printable = yes) µÄĿ¼ ×ÜÊÇ ¿ÉдµÄ(ÐèÒªÓû§¿ÉдȨÏÞ)µ«ÊÇÖ»ÄÜͨ¹ý»º³å²Ù×÷À´Ð´.

ȱʡÉèÖÃ: read only = yes

read raw (G)
´ËÑ¡Ïî¿ØÖÆ×ÅÊÇ·ñÈ÷þÎñÆ÷ÔÚ´«ËÍÊý¾Ýµ½¿Í»§¶Ëʱ֧³Ö¶ÁȡԭʼµÄSMBÇëÇó.

Èç¹ûÔÊÐí,ÄÇôËü»áÒÔ65535 ×Ö½ÚΪµ¥Î»À´¶ÁÈ¡Ò»¸öÊý¾Ý°üµÄ65535×Ö½Ú.Õâ»á´øÀ´½Ï¶àµÄÐÔÄÜ·½ÃæµÄºÃ´¦.

µ«ÊÇ,ÓÐЩ¿Í»§¶ËʹÓò»ÕýÈ·µÄ°üÈÝÁ¿(ËäÈ»ÊÇ¿ÉÔÊÐíµÄ),»òÕßËüÃDz»Ö§³Ö´óÈÝÁ¿°ü,ËùÒÔ¶ÔÕâЩ¿Í»§¶ËÄãÓ¦¸Ã½ûÖ¹ÕâһѡÏî.

ͨ³£½«´ËÑ¡Ïî×÷ΪһÖÖϵͳµ÷ÊÔ¹¤¾ß,¶øÇÒÑϸñÀ´Ëµ²»Ó¦ÐÞ¸Ä.²Î¼ûwrite rawÑ¡Ïî.

ȱʡÉèÖÃ: read raw = yes

read size (G)
´ËÏîÓ°Ïì×Å´ÅÅ̶Á/дÓëÍøÂç¶Á/дµÄÂÖÁ÷½»Ìæ.Èç¹ûÔÚÈô¸É¸öSMBÃüÁî(ͨ³£ÊÇSMBwrite,SMBwriteXºÍSMBreadbraw)Öд«Ë͵ÄÊý¾ÝÁ¿³¬¹ý´ËÏîÉ趨µÄֵʱ,·þÎñÆ÷¿ªÊ¼¾Í»áÔÚ´ÓÍøÂç½ÓÊÕÕû¸öÊý¾Ý°ü֮ǰ½øÐÐд²Ù×÷£»ÔÚÖ´ÐÐSMBreadbrawµÄÇé¿öÏÂ,·þÎñÆ÷ÔÚ´Ó´ÅÅÌÉ϶Á³öËùÓÐÊý¾Ý֮ǰ¾Í¿ªÊ¼ÏòÍøÂçÖÐдÊý¾Ý.

ÔÚ´ÅÅÌÓëÍøÂçµÄ·ÃÎÊËÙ¶ÈÏà½üʱ,ÕâÖÖ½»µüʽµÄ¹¤×÷¾Í»á×öµÃ·Ç³£ºÃ,²»¹ýµ±ÆäÖÐÒ»ÀàÉ豸µÄËٶȴó´ó¸ßÓÚÁíÒ»Ààʱ,ËüÖ»»áÓÐÄÇôһµãµãЧ¹û.

ȱʡµÄÖµÊÇ16384,µ«Ã»ÓÐ×ö¹ý²âÊÔ×îÓÅÖµµÄʵÑé¡£¸ù¾ÝÒѾ­Á˽âµÄÇé¿öÀ´¿´,ÔÚʹÓò»Í¬µÄϵͳʱ,×îÓÅ»¯ÖµµÄ²î±ðºÜ´ó.Ò»¸ö´óÓÚ65536µÄÖµÊÇûÓÐÈκÎÒâÒåµÄ,ËüÖ»»áÔì³É²»±ØÒªµÄÄÚ´æ·ÖÅä.

ȱʡÉèÖÃ: read size = 16384

ʾÀý: read size = 8192

realm (G)
This option specifies the kerberos realm to use. The realm is used as the ADS equivalent of the NT4 domain. It is usually set to the DNS name of the kerberos server.

ȱʡÉèÖÃ: realm =

ʾÀý: realm = mysambabox.mycompany.com

remote announce (G)
´ËÏîÔÊÐíÄãÉèÖÃnmbd(8)ÖÜÆÚÐÔµØÏòÈÎÒ⹤×÷×éµÄÈÎÒâIPµØÖ·ÉêÃ÷×Ô¼ºµÄ´æÔÚ.

Èç¹ûÄãÒªsamba·þÎñÆ÷´¦ÔÚÒ»¸öͨ³£ä¯ÀÀ´«²¥¹æÔòûÓÐÕý³£¹¤×÷µÄÔ¶³Ì¹¤×÷×éÀïʱ,ÓôËÏî¾ÍºÜÓÐÓÃÁË.´ËÔ¶³Ì¹¤×÷×é¿ÉÒÔλÓÚIP°üµ½µÃµ½µÄÈκεط½.

ÀýÈç:

remote announce = 192.168.2.255/SERVERS 192.168.4.255/STAFF

ÒÔÉÏÕâÐÐ˵Ã÷nmbd ¶ÔÁ½¸ö¸ø³öµÄʹÓù¤×÷×éÃûµÄIPµØÖ·½øÐÐÉêÃ÷.Èç¹ûÄãÖ»ÓÃÁËIPµØÖ·µÄ»°,ÄÇô»áÓÃworkgroupÑ¡ÏîÀï¸ø³öµÄ¹¤×÷×éÃûÀ´Ìæ´ú.

ÄãÑ¡ÓõÄIPµØַͨ³£Ó¦¸ÃÊÇÔ¶³ÌÍøÂçµÄ¹ã²¥µØÖ·,²»¹ýÒ²¿ÉÒÔÓÃÅäÖÃÎȶ¨µÄÍøÂçÖеÄÒÑÖªÖ÷ä¯ÀÀÆ÷IPµØÖ·.

ȱʡÉèÖÃ: remote announce = <¿Õ×Ö·û´®>

remote browse sync (G)
´ËÏîÔÊÐíÄãÉ趨nmbd(8)ÖÜÆÚÐÔµØͬ²½Î»ÓÚÔ¶³Ì(remote segment)µÄSambaÖ÷ä¯ÀÀÆ÷ÉϵÄä¯ÀÀÁбí.ͬʱҲÔÊÐíÄãÊÕ¼¯Î»ÓÚ¾ßÓн»²æ·ÓÉ×ÓÍøÖÐÖ÷ä¯ÀÀÆ÷ÉϵÄä¯ÀÀÁбí.ÕâÊÇÒÔÒ»ÖÖºÍÆäËû·ÇSambaµÄ·þÎñÆ÷²»¼æÈݵķ½Ê½½øÐеġ£

This is useful if you want your Samba server and all local clients to appear in a remote workgroup for which the normal browse propagation rules don't work. The remote workgroup can be anywhere that you can send IP packets to.

ÀýÈç:

remote browse sync = 192.168.2.255 192.168.4.255

ÒÔÉÏÐлáʹnmbdÏòλÓÚÖ¸¶¨×ÓÍø»òµØÖ·ÖеÄÖ÷ä¯ÀÀÆ÷ÇëÇóͬ²½ËûÃDZ¾µØ·þÎñÆ÷ÖеÄä¯ÀÀÁбí

ÄãÑ¡ÓõÄIPµØַͨ³£Ó¦¸ÃÊÇÔ¶³ÌÍøÂçµÄ¹ã²¥µØÖ·,²»¹ýÒ²¿ÉÒÔÓÃÅäÖ÷dz£Îȶ¨µÄÍøÂçÖеÄÒÑÖªÖ÷ä¯ÀÀÆ÷IPµØÖ·.Èç¹û¸ø³öÒ»¸öÖ÷»úµÄIPµØÖ·,»òÕßÖ÷¿Øä¯ÀÀÆ÷ÊÂʵÉÏÔÚ×Ô¼ºµÄÍø¶ÎÖÐ, samba¾Í²»ÑéÖ¤Ô¶³ÌÖ÷»úÊÇ·ñÓÐЧ¡¢ÊÇ·ñÕýÔÚÕìÌýÁË¡£

ȱʡÉèÖÃ: remote browse sync = <¿Õ×Ö·û´®>

restrict anonymous (G)
Õâ¸öÑ¡ÏîÏÞÖÆÁËÊÇ·ñÔÚÄäÃûÁ¬½ÓÖзµ»ØÓû§ºÍ×éÁбíÐÅÏ¢£¬·ÂÕÕÁËWindows2000 ºÍNTÔÚ×¢²á±í¼üÖµHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\RestrictAnonymous ÖеÄ×ö·¨¡£ÉèÖÃΪ0µÄʱºò£¬ÈκÎÇëÇ󶼷µ»ØÓû§ºÍ×éÁÐ±í¡£ÉèÖÃΪ1µÄʱºò£¬Ö»ÓÐÈÏÖ¤µÄÓû§¿ÉÒÔ»ñµÃÓû§ºÍ×éÁÐ±í¡£ÉèÖÃΪ2µÄʱºò£¬Ö»ÓÐWindows2000/XPºÍSambaÖ§³Ö£¬²»ÔÊÐíÄäÃûÁ¬½Ó¡£ÕâÑù×ö»á×èÖ¹ÐèÒªÄäÃû²Ù×÷µÄM$»òµÚÈý·½³ÌÐòÔËÐС£

The security advantage of using restrict anonymous = 1 is dubious, as user and group list information can be obtained using other means.

The security advantage of using restrict anonymous = 2 is removed by setting guest ok = yes on any share.

ȱʡÉèÖÃ: restrict anonymous = 0

root (G)
Óë root directory" ͬÒå

root dir (G)
Óë root directory" ͬÒå.

root directory (G)
·þÎñÆ÷½«ÔÚÆô¶¯Ê±¶Ô´ËÏîËùÉè֮Ŀ¼½øÐÐchroot()(Ò²¾ÍÊǸıä¸ùĿ¼) ²Ù×÷.¶ÔÓÚ°²È«²Ù×÷À´Ëµ,Õâ²¢²»ÊÇÊ®·Ö±ØÒªµÄ.Èç¹ûûÓÐÕâ²½²Ù×÷,·þÎñÆ÷»á¾Ü¾ø¶Ô·þÎñÏîÒÔÍâµÄÎļþ½øÐзÃÎÊ.ͬʱҲ¼ì²é²¢¾Ü¾øÄÇЩÎļþϵͳÆäËü²¿·ÖµÄÈíÁ´½Ó»òÕß³¢ÊÔÔÚÆäËüĿ¼(È¡¾öÓÚÑ¡Ïîwide linksµÄÉèÖÃÇé¿ö)ÖÐʹÓÃ".."ÕâЩ²Ù×÷.

¼ÓÈëÒ»¸öroot directory,×¢Òâ²»ÊÇʵ¼ÊµÄ"/"Ŀ¼,¿ÉÒÔÔö¼Ó¶îÍâµÄ°²È«¼¶±ð,µ«ÊÇ´ú¼Û¾Í¸ßÁË.ÕâÑùÍêÈ«È·±£ÁËËùÖ¸¶¨µÄroot directory¼°ËùÊô×ÓĿ¼ÍâµÄÎļþ¶¼ÊDz»ÄÜ·ÃÎʵÄ,°üÀ¨·þÎñÆ÷Õý³£ÔËÐÐʱËùÐèµÄһЩÎļþÒ²ÊÇÈç´Ë.Òò´ËÒªÏëά»¤·þÎñÆ÷ÕûÌåµÄ¿É²Ù×÷ÐÔ,ÄãÐèÒª¾µÏñһЩϵͳÎļþµ½ËùÖ¸¶¨µÄroot directoryÏÂ.ÌرðÊÇÒª¾µÏñ /etc/passwdÎļþ»ò´ËÎļþµÄ×Ó¼¯,Èç¹ûÐèÒªµÄ»°,ÈκδòÓ¡²Ù×÷ÒªÓõ½µÄ¶þ½øÖÆÎļþ»òÅäÖÃÎļþÒ²Òª¾µÏñ.µ±È»,Ó¦¸ÃÓɲÙ×÷ϵͳ¾ö¶¨±ØÐë±»¾µÏñµÄÎļþ¼¯ºÏ.

ȱʡÉèÖÃ: root directory = /

ʾÀý: root directory = /homes/smb

root postexec (S)
´ËÏîÓë postexecÑ¡ÏÒåÏàͬ,Ö»ÊÇÒÔrootÉí·ÝÀ´ÔËÐÐÃüÁî¶øÒÑ.ÔÚÒ»´ÎÁª½Ó¹Ø±ÕÖ®ºó¶ÔÎļþϵͳ,ÌرðÊǹâÅÌÇý¶¯Æ÷½øÐÐжÔØÊǷdz£ÓÐÓõÄ.

²Î¼û postexec.

ȱʡÉèÖÃ: root postexec = <¿Õ×Ö·û´®>

root preexec (S)
´ËÏîÓë preexecÑ¡ÏÒåÏàͬ,Ö»ÊÇÒÔrootÉí·ÝÀ´ÔËÐÐÃüÁî¶øÒÑ.ÔÚÒ»´ÎÁª½ÓÎȶ¨½¨Á¢Ö®ºó×°ÔØÎļþϵͳ,ÌرðÊǹâÅÌÇý¶¯Æ÷ÊǷdz£ÓÐÓõÄ.

²Î¼û preexec ºÍ preexec close Ñ¡Ïî.

ȱʡÉèÖÃ: root preexec = <¿Õ×Ö·û´®>

root preexec close (S)
´ËÏîÓëpreexec close Ñ¡ÏÒåÏàͬ,Ö»ÊÇÒÔrootÉí·ÝÀ´ÔËÐÐÃüÁî¶øÒÑ.

²Î¼û preexec ºÍpreexec close.

ȱʡÉèÖÃ: root preexec close = no

security (G)
´ËÏîÊÇsmb.confÎļþÖÐ×îÖØÒªµÄÒ»¸öÉ趨֮һ,ËüÓ°ÏìÁË¿Í»§ÊÇÈçºÎÓ¦´ðSamba·þÎñÆ÷µÄ.

Õâ¸öÑ¡ÏîÉèÖÃÁË¡°°²È«Ä£Ê½Î»¡±ÓÃÓÚ´ð¸´Ð­ÒéЭÉÌÒÔʹsmbd(8) µ÷Õû¹²Ïí°²È«¼¶ÊÇ¿ª»òÕß¹Ø.¿Í»§¶Ë¸ù¾Ý´Ëλ¾ö¶¨ÊÇ·ñ(ÒÔ¼°ÈçºÎ)Ïò·þÎñÆ÷´«ËÍÓû§ºÍ¿ÚÁîÐÅÏ¢.

ȱʡֵÊÇsecurity = user,ÕâÒ²ÊÇÔÚWindows 98ºÍWindows NT»·¾³ÖÐ×î³£ÓõÄÉ趨.

¿ÉÑ¡µÄÖµ security = share, security = server »òÕßsecurity = domain .


 2.0.0°æ±¾Ö®Ç°µÄSambaÖÐ,ȱʡֵÊÇ security = share Ö÷ÒªÒòΪµ±Ê±Ö»ÓÐÕâÒ»¸öÖµ¿ÉÑ¡¡£

ÔÚWfWgÀïÓÐÒ»¸ö´íÎó,µ±ÔÚʹÓÃÓû§ºÍ·þÎñÆ÷°²È«¼¶Ê±,WfWg¿Í»§½«»áÍêÈ«ºöÂÔÄãÔÚ"connect drive"¶Ô»°¿òÀï¼üÈëµÄ¿ÚÁî.Õâ¾Íʹ³ýÁËÔÚWfWgÀïÒѵǼµÄÓû§ÒÔÍâµÄÈκÎÈËÒªÁª½ÓSamba·þÎñÏî±äµÃ·Ç³£À§ÄÑ.

Èç¹ûÄãµÄÖ÷»úʹÓÃÓëUNIXÖ÷»úÉÏÏàͬµÄÓû§Ãûʱ,¾ÍÓ¦µ±Ê¹ÓÃsecurity = user.Èç¹ûÄãÓõÄÓû§Ãûͨ³£ÔÚUNIXÉϲ»´æÔÚʱ¾ÍÓ¦¸ÃÓÃsecurity = share.

Èç¹ûÄãÏëÉèÖù²Ïí¶ø²»ÓÿÚÁîµÄ»°(·Ã¿Í¼¶¹²Ïí)Ò²Ó¦¸ÃÓÃsecurity=share.Õâͨ³£ÓÃÓÚÌṩ¹²Ïí´òÓ¡µÄ·þÎñÆ÷.ÔÚsecurity=userÀïÉ趨guestÕÊ»§·Ç³£À§ÄÑ,ÏêϸµÄÇé¿öÇë²Î¼ûmap to guestÑ¡Ïî.

smbd¿ÉÄÜ»áʹÓÃÒ»ÖÖ»ìÔÓģʽ(hybrid),ÕâÑù¾Í¿ÉÒÔÔÚ²»Í¬µÄNetBIOS aliasesÏÂÌṩÓû§ºÍ¹²Ïí¼¶µÄ°²È«ÌØÐÔ.

ÏÖÔÚ½âÊ͸÷¸ö²»Í¬µÄÉ趨.

SECURITY = SHARE

µ±¿Í»§Áª½Óµ½Ò»¸ö¹²Ïí°²È«¼¶µÄ·þÎñÆ÷,ÔÚÁª½Ó¹²Ïí×ÊԴ֮ǰÎÞÐèÓÃÒ»¸öºÏ·¨µÄÓû§ÃûºÍ¿ÚÁîµÇ¼µ½·þÎñÆ÷(ËäÈ»ÏÖÔڵĿͻ§¶ËÏóWIN95/95¼°NTÔÚÓësecurity = share µÄ·þÎñÆ÷½»Ì¸Ê±¶¼»áÒÔÓû§Ãû·¢ËÍÒ»¸öµÇ¼ÇëÇó,µ«È´Ã»Óдø¿ÚÁî).Ïà·´,¿Í»§¶Ë»áÔÚÿһ¸ö¹²ÏíÉÏ·¢ËÍÈÏÖ¤ÐÅÏ¢(¿ÚÁî)ÒÔ³¢ÊÔÁª½Óµ½Õâ¸ö¹²ÏíÏî.

×¢Òâ smbd ×ÜÊÇ ÓúϷ¨µÄUNIXÓû§´ú±í¿Í»§½øÐвÙ×÷, ¼´Ê¹ÊÇÔÚ security = share µÄʱºò.

ÒòΪÔÚ¹²Ïí°²È«¼¶ÖÐ,¿Í»§ÎÞÐèÏò·þÎñÆ÷·¢ËÍÓû§Ãû,ËùÒÔsmbdÓÃһЩ¼¼ÊõÀ´Îª¿Í»§¾ö¶¨ÕýÈ·µÄUNIXÓû§Õ˺Å.

ÓÃÓÚÆ¥Åä¸ø³ö¿Í»§¿ÚÁîµÄ¿ÉÄܵÄUNIXÓû§ÃûÁбí¿ÉÒÔÓÃÒÔÏ·½·¨½¨Á¢£º

Èç¹ûÉèÖÃÁËguest onlyÑ¡Ïî,ÔòÌø¹ýËùÓÐÆäËü²½ÖèÖ»¼ì²éguest accountÓû§Ãû.

Èç¹ûͨ¹ý¹²ÏíÁ¬½ÓÇëÇó·¢ËÍÒ»¸öÓû§Ãû,Ôò´ËÓû§Ãû(Ó³Éäºó - ²Î¼ûusername map)±»×÷ΪDZÔÚÓû§Ãû¼ÓÈë.

Èç¹û¿Í»§Ê¹ÓÃÒ»¸öÏÈÇ°µÄ logon ÇëÇó(SessionSetup SMBµ÷ÓÃ)ÔòÔÚSMBÖз¢Ë͵ÄÓû§Ãû½«×÷ΪDZÔÚÓû§Ãû¼ÓÈë.

¿Í»§ÇëÇóµÄ·þÎñÏîÃû±»×÷ΪDZÔÚÓû§Ãû¼ÓÈë.

¿Í»§µÄNetBIOSÃû±»×÷ΪDZÔÚÓû§Ãû¼ÓÈëµ½ÁбíÖÐ.

ÔÚuserÁбíÖеÄÈκÎÓû§¶¼±»×÷ΪDZÔÚÓû§Ãû¼ÓÈë.

Èç¹ûδÉèguest onlyÑ¡Ïî,ÔòʹÓÃÌṩµÄ¿ÚÁîÀ´³¢ÊÔ´ËÁбí.¶ÔÓÚÆ¥Åäµ½¿ÚÁîµÄµÚÒ»¸öÓû§½«×÷ΪUNIXÓû§Éí·ÝʹÓÃ.

Èç¹ûÉèÖÃÁËguest onlyÑ¡Ïî»òδ¼ì²âµ½Óû§Ãû,ÔòÈç¹û¹²ÏíÏîÖбê־Ϊ¿ÉÒÔʹÓÃguest account,ÄÇôʹÓô˷ÿÍÓû§Õ˺Å,·ñÔò¾Ü¾ø·ÃÎÊ.

×¢Òâ,ÔÚ¹²Ïí°²È«¼¶ÖйØÓÚÄĸöUNIXÓû§Ãû×îºó½«ÔÚÔÊÐí·ÃÎÊÖÐʹÓ÷dz£»ìÏý.

²Î¼ûNOTE ABOUT USERNAME/PASSWORD VALIDATION¶Î.

SECURITY = USER ÕâÊÇsamba2.0/3.0ȱʡ°²È«¼¶ÉèÖÃ.¶ÔÓÚÓû§°²È«¼¶,Ò»¸ö¿Í»§±ØÐëÏÈÒԺϷ¨µÄÓû§ÃûºÍ¿ÚÁî(Ò²¿ÉÒÔÓÃusername mapÑ¡Ïî½ø³ÌÓ³Éä)¡°µÇ¼¡±.ÔÚ´Ë°²È«Ä£Ê½ÖÐÒ²¿ÉʹÓüÓÃÜ¿ÚÁî(²Î¼ûencrypted passwordsÑ¡Ïî).Èç¹ûÉèÖÃÁËÈçuserºÍguest onlyÕâÑùµÄÑ¡Ïî,ÔòËüÃǻᱻӦÓò¢ÇÒÔÚ´ËÁ¬½ÓÉϸü¸ÄUNIXÓû§Õ˺Å,µ«Ö»ÄÜÔÚÓû§Õ˺ű»³É¹¦ÑéÖ¤Ö®ºó²ÅÐÐ.

×¢Òâ,µ±·þÎñÆ÷³É¹¦ÑéÖ¤¿Í»§Éí·Ý֮ǰ,ÇëÇóµÄ×ÊÔ´Ãû³ÆÊDz»·¢Ë͵½·þÎñÆ÷ÉϵÄ.Õâ¾ÍÊÇΪʲôÓû§°²È«¼¶ÖÐÔÚûÓÐÔÊÐí·þÎñÆ÷×Ô¶¯°Ñδ֪Óû§Ó³ÉäΪguest accountµÄÇé¿öÏÂ,·Ã¿Í¹²ÏíÎÞ·¨¹¤×÷.²Î¼ûmap to guestÑ¡Ïî»ñµÃÍê³ÉÓ³ÉäµÄϸ½Ú.

²Î¼ûNOTE ABOUT USERNAME/PASSWORD VALIDATION¶Î.

SECURITY = DOMAIN

Ö»ÓÐÒѾ­Óà net(8)°Ñ·þÎñÆ÷Ìí¼Ó½øÒ»¸öWindows NTµÄÓòÖÐ,´Ë°²È«Ä£Ê½²ÅÄÜÕý³£¹¤×÷.ËüÒªÇóencrypted passwordsÑ¡ÏîÉèΪyes.ÔÚ´ËģʽÖÐSamba½«ÊÔͼ°ÑÓû§Ãû/¿ÚÁî´«Ë͵½Ò»¸öWindowsNTÖ÷Óò»ò±¸·ÝÓò¿ØÖÆÆ÷½øÐÐÑéÖ¤Ïñһ̨ÕæÕýµÄWindowsNT·þÎñÆ÷ÄÇÑù¡£

×¢Òâ,ÈÔÈ»ÐèÒª´æÔÚÒ»¸öºÍÓò¿ØÖÆÆ÷ÉϵÄÓû§ÃûÒ»ÖµÄÓÐЧµÄUNIXÓû§£¬À´Ê¹SambaÓµÓÐÒ»¸öÓÐЧµÄUNIXÕÊ»§À´Ó³Éä´æÈ¡Îļþ²Ù×÷¡£

×¢Òâ,¶ÔÓÚ¿Í»§¶ËÀ´Ëµ,security=domainģʽÓësecurity=userÊÇÒ»ÑùµÄ.ËüÖ»Ó°Ïì ·þÎñÆ÷´¦ÀíÑéÖ¤¹¤×÷µÄ·½Ê½.¶ÔÓÚ¿Í»§¶ËÎÞÈκÎÓ°Ïì.

×¢Òâ,µ±·þÎñÆ÷³É¹¦ÑéÖ¤¿Í»§Éí·Ý֮ǰ,ÇëÇóµÄ×ÊÔ´Ãû³ÆÊDz»·¢Ë͵½·þÎñÆ÷ÉϵÄ.Õâ¾ÍÊÇΪʲôÓò°²È«¼¶ÖÐÔÚûÓÐÔÊÐí·þÎñÆ÷×Ô¶¯°Ñδ֪Óû§Ó³ÉäΪguest accountµÄÇé¿öÏÂ,·Ã¿Í¹²ÏíÎÞ·¨¹¤×÷.²Î¼ûmap to guestÑ¡Ïî»ñµÃÍê³ÉÓ³ÉäµÄϸ½Ú

²Î¼û NOTE ABOUT USERNAME/PASSWORD VALIDATION ¶Î.

²Î¼û password server parameter ºÍ encrypted passwords Ñ¡Ïî¡£

SECURITY = SERVER

ÔÚ´ËģʽÖÐSamba½«ÊÔͼ°ÑÓû§Ãû/¿ÚÁî´«Ë͵½ÆäËüSMB·þÎñÆ÷,±ÈÈçһ̨NT·þÎñÆ÷,½øÐÐÑéÖ¤.Èç¹ûÑé֤ʧ°ÜÔò»Øµ½security = userģʽ,ËüÐèÒªencrypted passwords ²ÎÊýÉèÖÃΪyes£¬³ý·ÇÔ¶¶Ëϵͳ²»Ö§³ÖËüÃÇ¡£µ«ÊÇҪעÒ⣬Èç¹ûʹÓÃÁ˼ÓÃÜ¿ÚÁîµÄ»°,samba²»»áÔÙÈ¥¼ì²éUNIXϵͳ¿ÚÁîÎļþµÄ,Ëü±ØÐëÓÐÒ»¸öºÏ·¨µÄsmbpasswdÎļþÒÔÔٴμì²éÓû§Õ˺Å.²Î¼ûSamba HOWTO Collection ÖйØÓÚUser Database µÄÕ½ÚÀ´»ñµÃÈçºÎÉèÖõÄÐÅÏ¢¡£

This mode of operation has significant pitfalls, due to the fact that is activly initiates a man-in-the-middle attack on the remote SMB server. In particular, this mode of operation can cause significant resource consuption on the PDC, as it must maintain an active connection for the duration of the user's session. Furthermore, if this connection is lost, there is no way to reestablish it, and futher authenticaions to the Samba server may fail. (From a single client, till it disconnects).

×¢Òâ,¶ÔÓÚ¿Í»§¶ËÀ´Ëµ,security=serverģʽÓësecurity=userÊÇÒ»ÑùµÄ.ËüÖ»Ó°Ïì·þÎñÆ÷´¦ÀíÑéÖ¤¹¤×÷µÄ·½Ê½.¶ÔÓÚ¿Í»§¶ËÎÞÈκÎÓ°Ïì.

×¢Òâ,µ±·þÎñÆ÷³É¹¦ÑéÖ¤¿Í»§Éí·Ý֮ǰ,ÇëÇóµÄ×ÊÔ´Ãû³ÆÊDz»·¢Ë͵½·þÎñÆ÷ÉϵÄ.Õâ¾ÍÊÇΪʲô·þÎñÆ÷°²È«¼¶ÖÐÔÚûÓÐÔÊÐí·þÎñÆ÷×Ô¶¯°Ñδ֪Óû§Ó³ÉäΪguest accountµÄÇé¿öÏÂ,·Ã¿Í¹²ÏíÎÞ·¨¹¤×÷.²Î¼û map to guestÑ¡Ïî»ñµÃÍê³ÉÓ³ÉäµÄϸ½Ú.

²Î¼û NOTE ABOUT USERNAME/PASSWORD VALIDATION ¶Î.

²Î¼û password server parameter ºÍ encrypted passwords Ñ¡Ïî¡£

SECURITY = ADS

In this mode, Samba will act as a domain member in an ADS realm. To operate in this mode, the machine running Samba will need to have Kerberos installed and configured and Samba will need to be joined to the ADS realm using the net utility.

Note that this mode does NOT make Samba operate as a Active Directory Domain Controller.

Read the chapter about Domain Membership in the HOWTO for details.

²Î¼û ads server parameter, the realm paramter ºÍencrypted passwords Ñ¡Ïî¡£

ȱʡÉèÖÃ: security = USER

ʾÀý: security = DOMAIN

security mask (S)
´ËÑ¡Ïî¿ØÖÆNT¿Í»§Óñ¾µØNT°²È«¶Ô»°¿ò²Ù×÷UNIXȨÏÞʱ¶ÔȨÏÞËù×÷µÄÐÞ¸ÄÇé¿ö. This parameter controls what UNIX permission bits can be modified when a Windows NT client is manipulating the UNIX permission on a file using the native NT security dialog box.

´ËÑ¡ÏîÓÃÑÚÂëÖµ'Óë'ʵÏÖ¶ÔȨÏÞλµÄ¸ü¸Ä,´Ó¶ø·ÀÖ¹ÐÞ¸Äδ³öÏÖÔÚ´ËÑÚÂëÖеÄÈκÎλ.¿ÉÒÔ½«ÑÚÂëÖеÄ0¿´×÷Óû§ÎÞȨ¸ü¸ÄµÄλֵ. This parameter is applied as a mask (AND'ed with) to the changed permission bits, thus preventing any bits not in this mask from being modified. Essentially, zero bits in this mask may be treated as a set of bits the user is not allowed to change.

ÈçδÃ÷È·É趨´ËÑ¡Ïî,Ôò°Ñ´ËÑ¡ÏîÉèΪ0777£¬ÔÊÐíÓû§ÐÞ¸ÄÎļþµÄËùÓÐuser/group/worldÕâЩȨÏÞ.

×¢Òâ,¿Éͨ¹ýÆäËüÊֶηÃÎʵ½Samba·þÎñÆ÷µÄÓû§¿ÉÒÔÇá¶øÒ×¾ÙµØÈƹý´ËÏÞÖÆ,ËùÒÔ´ËÑ¡ÏîÖ»¶Ô¶ÀÁ¢µÄ·þÎñÆ÷ϵͳÓÐÓÃ.¶àÊýÆÕͨϵͳµÄ¹ÜÀíÔ±¿ÉÒÔ½«Ëü±£ÁôΪ0777.

²Î¼û force directory security mode, directory security mask, force security mode Ñ¡Ïî.

ȱʡÉèÖÃ: security mask = 0777

ʾÀý: security mask = 0770

server schannel (G)
This controls whether the server offers or even demands the use of the netlogon schannel. server schannel = no does not offer the schannel, server schannel = auto offers the schannel but does not enforce it, and server schannel = yes denies access if the client is not able to speak netlogon schannel. This is only the case for Windows NT4 before SP4.

Please note that with this set to no you will have to apply the WindowsXP requireSignOrSeal-Registry patch found in the docs/Registry subdirectory.

ȱʡÉèÖÃ: server schannel = auto

ʾÀý: server schannel = yes

server signing (G)
This controls whether the server offers or requires the client it talks to to use SMB signing. Possible values are auto, mandatory and disabled.

When set to auto, SMB signing is offered, but not enforced. When set to mandatory, SMB signing is required and if set to disabled, SMB signing is not offered either.

ȱʡÉèÖÃ: client signing = False

server string (G)
´ËÑ¡ÏîÔÚ´òÓ¡¹ÜÀíÆ÷ÖеĴòÓ¡»úÐÅÏ¢¶Ô»°¿òÒÔ¼°ÔÚnet view(ÍøÉÏÁÚ¾Ó)µÄIPCÁ¬½ÓÖÐÏÔʾµÄ·þÎñÆ÷ÐÅÏ¢.Ëü¿ÉÒÔÊÇÈκÎÄãÏ£ÍûÏòÓû§ÏÔʾµÄ×Ö´®.

Ëü»¹ÉèÖÃÏÔʾÔÚä¯ÀÀÁбíÖÐÖ÷»úÃûºóµÄÄÚÈÝ.

%v ½«Ì滻ΪSamba°æ±¾ºÅ

%h ½«Ì滻ΪÖ÷»úÃû

ȱʡÉèÖÃ: server string = Samba %v

ʾÀý: server string = University of GNUs Samba Server

set directory (S)
Èç¹û set directory = no£¬ÔòʹÓ÷þÎñµÄÓû§²»ÄÜÓÃsetdirÃüÁî¸ü±äĿ¼.

setdirÃüÁîÖ»ÔÚDigital Pathworks¿Í»§¶ËÖÐʵÏÖ.²Î¼ûPathworksÎĵµµÄϸ½Ú.

ȱʡÉèÖÃ: set directory = no

set primary group script (G)
Thanks to the Posix subsystem in NT a Windows User has a primary group in addition to the auxiliary groups. This script sets the primary group in the unix userdatase when an administrator sets the primary group from the windows user manager or when fetching a SAM with net rpc vampire. %u will be replaced with the user whose primary group is to be set. %g will be replaced with the group to set.

ȱʡÉèÖÃ: No default value

ʾÀý: set primary group script = /usr/sbin/usermod -g '%g' '%u'

set quota command (G)
The set quota command should only be used whenever there is no operating system API available from the OS that samba can use.

This parameter should specify the path to a script that can set quota for the specified arguments.

The specified script should take the following arguments:

1 - quota type .TP 3 * 1 - user quotas .TP * 2 - user default quotas (uid = -1) .TP * 3 - group quotas .TP * 4 - group default quotas (gid = -1) .LP

2 - id (uid for user, gid for group, -1 if N/A)

3 - quota state (0 = disable, 1 = enable, 2 = enable and enforce)

4 - block softlimit

5 - block hardlimit

6 - inode softlimit

7 - inode hardlimit

8(optional) - block size, defaults to 1024

The script should output at least one line of data.

²Î¼û get quota command Ñ¡Ïî¡£

ȱʡÉèÖÃ: set quota command =

ʾÀý: set quota command = /usr/local/sbin/set_quota

share modes (S)
´ËÑ¡ÏîÔÚÒ»¸öÎļþ´ò¿ªÊ±ÔÊÐí»ò½ûÖ¹share modes.´Ëģʽ¿ÉÓÃÓÚʹ¿Í»§»ñµÃ¶ÔÒ»¸öÎļþ¶ÀÕ¼µÄ¶Á»òд·ÃÎÊ.

ÕâЩ´ò¿ªÄ£Ê½UNIXÊDz»Ö±½ÓÖ§³ÖµÄ,ËùÒÔÒªÓù²ÏíÄÚ´æ»òÔÚUNIX²»Ö§³Ö¹²ÏíÄÚ´æʱ(Ò»°ã¶¼Ö§³Ö)ÓÃËø¶¨ÎļþÀ´Ä£Äâ.

ÔÊÐí¹²ÏíģʽµÄÑ¡ÏîÊÇDENY_DOS, DENY_ALL, DENY_READ,DENY_WRITE, DENY_NONE ºÍDENY_FCB.

ȱʡÇé¿öÏ´ËÑ¡ÏîÌṩÁËÍêÈ«µÄ¹²Ïí¼æÈݺÍÐí¿É.

Äã ²»Ó¦ °Ñ´ËÑ¡Ïî¹Ø±ÕÒòΪºÜ¶àWindowsÓ¦ÓûáÒò´ËÍ£Ö¹ÔËÐС£

ȱʡÉèÖÃ: share modes = yes

short preserve case (S)
´Ë²¼¶ûֵѡÏî¿ØÖÆ×ÅÈç¹ûÐÂÎļþ·ûºÏ8.3ÎļþÃû¸ñʽ(ËùÓÐ×Öĸ¶¼Îª´óдÇÒ³¤¶ÈÊʵ±),ÔòÒÔ´óд×Öĸ½¨Á¢Îļþ£¬·ñÔò¾Íת»»Îªdefault case .´ËÑ¡Ïî¿ÉÓëpreserve case = yesÑ¡ÏîÁªÓÃ,ÒÔÔÊÐí³¤ÎļþÃû±£Áô´óСд£¬Í¬Ê±¶ÌÎļþÃûת»»ÎªÐ¡Ð´¡£

²Î¼û NAME MANGLING ¶Î.

ȱʡÉèÖÃ: short preserve case = yes

show add printer wizard (G)
With the introduction of MS-RPC based printing support for Windows NT/2000 client in Samba 2.2, a "Printers..." folder will appear on Samba hosts in the share listing. Normally this folder will contain an icon for the MS Add Printer Wizard (APW). However, it is possible to disable this feature regardless of the level of privilege of the connected user.

Under normal circumstances, the Windows NT/2000 client will open a handle on the printer server with OpenPrinterEx() asking for Administrator privileges. If the user does not have administrative access on the print server (i.e is not root or a member of the printer admin group), the OpenPrinterEx() call fails and the client makes another open call with a request for a lower privilege level. This should succeed, however the APW icon will not be displayed.

Disabling the show add printer wizard parameter will always cause the OpenPrinterEx() on the server to fail. Thus the APW icon will never be displayed. Note :This does not prevent the same user from having administrative privilege on an individual printer.

²Î¼û addprinter command, deleteprinter command, printer admin

Default :show add printer wizard = yes

shutdown script (G)
This parameter only exists in the HEAD cvs branch This a full path name to a script called by smbd(8) that should start a shutdown procedure.

This command will be run as the user connected to the server.

%m %t %r %f parameters are expanded:

%m will be substituted with the shutdown message sent to the server.

%t will be substituted with the number of seconds to wait before effectively starting the shutdown procedure.

%r will be substituted with the switch -r. It means reboot after shutdown for NT.

%f will be substituted with the switch -f. It means force the shutdown even if applications do not respond for NT.

ȱʡÉèÖÃ: None.

ʾÀý: shutdown script = /usr/local/samba/sbin/shutdown %m %t %r %f

Shutdown script example:


#!/bin/bash
                
$time=0
let "time/60"
let "time++"

/sbin/shutdown $3 $4 +$time $1 &

Shutdown does not return so we need to launch it in background.

²Î¼û abort shutdown script.

smb passwd file (G)
´ËÑ¡ÏîÉèÖüÓÃÜ¿ÚÁîÎļþsmbpasswdµÄ·¾¶.ȱʡ·¾¶ÔÚ±àÒësambaʱָ¶¨.

ȱʡÉèÖÃ: smb passwd file = ${prefix}/private/smbpasswd

ʾÀý: smb passwd file = /etc/samba/smbpasswd

smb ports (G)
Specifies which ports the server should listen on for SMB traffic.

ȱʡÉèÖÃ: smb ports = 445 139

socket address (G)
´ËÑ¡ÏîÔÊÐíÄã¿ØÖÆsamba¼àÌýÁ¬½ÓËùÓõĵØÖ·.ËüÓÃÓÚÔÚÒ»¸ö·þÎñÆ÷ÉÏÖ§³Ö¶à¸öÅäÖò»Í¬µÄÐéÄâ½Ó¿Ú.ȱʡÇé¿öÏÂsamba»áÔÚÈκεØÖ·É϶¼½ÓÊÜÁ¬½ÓÇëÇó.

By default Samba will accept connections on any address.

ʾÀý: socket address = 192.168.2.20

socket options (G)
´ËÑ¡ÏîÉèÖÃÓÃÓÚÓë¿Í»§¶Ë½»Ì¸µÄÌ×½Ó×ÖÑ¡Ïî.

Ì×½Ó×ÖÑ¡ÏîÊÇʹÓÃÔÚÔÊÐíµ÷ÕûÁ¬½ÓµÄ²Ù×÷ϵͳµÄÍøÂç²ãµÄ¿ØÖÆÃüÁî.

´ËÑ¡Ïîͨ³£ÓÃÓÚÔÚ¾ÖÓòÍøÉÏÓÅ»¯µ÷Õûsamba·þÎñÆ÷µÄÐÔÄÜ.ÒòΪsambaÎÞ·¨ÖªµÀÓëÄãµÄÍøÂçËù¶ÔÓ¦µÄÓÅ»¯Ñ¡Ïî,ËùÒÔÄã±ØÐë×Ô¼º½øÐÐÊÔÑé²¢×÷³öÑ¡Ôñ.ÎÒÃÇÇ¿ÁÒÍƼöÄãÏÈÔĶÁÓëÄãµÄ²Ù×÷ϵͳÓйصÄÏàÓ¦Îļþ(Ò²Ðíman setsockopt»áÓаïÖú).

Äã¿ÉÄܻᷢÏÖÔÚÓÐЩϵͳÉÏsamba»áÔÚÄãʹÓÃÒ»¸öÑ¡Ïîʱ·¢³ö"Unknown socket option"µÄÐÅÏ¢.Õâ¾Í˵Ã÷ÄãûÓÐÕýȷƴд»òÕßÐèҪΪ²Ù×÷ϵͳÌí¼ÓÒ»¸ö°üº¬Îļþµ½includes.hÖÐ.ÈçÓкóÃæÖ¸³öµÄÎÊÌâÇëдÐŵ½samba-bugs@samba.org.

Ö»Òª²Ù×÷ϵͳÔÊÐí,Äã¿ÉÒÔÒÔÈκη½·¨×éºÏÈκÎËùÖ§³ÖµÄÌ×½Ó×ÖÑ¡Ïî.

µ±Ç°¿ÉÓÃÓÚ´ËÑ¡ÏîµÄ¿ÉÉèÖÃÌ×½Ó×ÖÑ¡ÏîÁбíÓУº

SO_KEEPALIVE

SO_REUSEADDR

SO_BROADCAST

TCP_NODELAY

IPTOS_LOWDELAY

IPTOS_THROUGHPUT

SO_SNDBUF *

SO_RCVBUF *

SO_SNDLOWAT *

SO_RCVLOWAT *

±êÓÐ'*'µÄҪʹÓÃÒ»¸öÕûÊý²ÎÊý.ÆäËüµÄÓÐʱʹÓÃ1»ò0´ú±íÔÊÐí»ò½ûÖ¹¸ÃÑ¡Ïî,Èçδָ¶¨1»ò0Ôòȱʡֵ¶¼ÎªÔÊÐí.

ÒªÖ¸¶¨Ò»¸ö±äÁ¿£¬ÓÃ"SOME_OPTION=VALUE"¸ñʽ¡£±ÈÈç¿ÉÒÔÊÇSO_SNDBUF=8192.×¢Òâ,ÔÚ"="Ç°ºó²»ÄÜÓÐÈκοոñ.

ÈçÔÚ¾ÖÓòÍøÉÏ,ÔòʹÓÃÏÂÃæÕâ¸öÊDZȽÏÃ÷Öǵģº

socket options = IPTOS_LOWDELAY

ÈçÓÐÒ»¸ö¾ÖÓòÍøÔò¿ÉÒÔÊÔһϣº

socket options = IPTOS_LOWDELAY TCP_NODELAY

ÈçÓÐÒ»¸ö¹ãÓòÍø,ÔòÊÔÒ»ÏÂIPTOS_THROUGHPU.

×¢ÒâÓÐЩѡÏî¿Éµ¼ÖÂsamba·þÎñÆ÷ÍêȫʧЧ.СÐÄʹÓÃËüÃÇ£¡

ȱʡÉèÖÃ: socket options = TCP_NODELAY

ʾÀý: socket options = IPTOS_LOWDELAY

source environment (G)
This parameter causes Samba to set environment variables as per the content of the file named.

If the value of this parameter starts with a "|" character then Samba will treat that value as a pipe command to open and will set the environment variables from the output of the pipe.

The contents of the file or the output of the pipe should be formatted as the output of the standard Unix env(1) command. This is of the form:

Example environment entry:

SAMBA_NETBIOS_NAME = myhostname

ȱʡÉèÖÃ: No default value

Examples: source environment = |/etc/smb.conf.sh

ʾÀý: source environment = /usr/local/smb_env_vars

stat cache (G)
´ËÑ¡Ïî¼ì²âsmbd(8)ÊÇ·ñʹÓûº´æÒÔÌáÉýÓ³Éä²»·Ö´óСдÃû³ÆµÄËÙ¶È.ÄãÎÞÐë¸ü¸Ä´ËÑ¡Ïî.

ȱʡÉèÖÃ: stat cache = yes

strict allocate (S)
This is a boolean that controls the handling of disk space allocation in the server. When this is set to yes the server will change from UNIX behaviour of not committing real disk storage blocks when a file is extended to the Windows behaviour of actually forcing the disk system to allocate real storage blocks when a file is created or extended to be a given size. In UNIX terminology this means that Samba will stop creating sparse files. This can be slow on some systems.

When strict allocate is no the server does sparse disk block allocation when a file is extended.

Setting this to yes can help Samba return out of quota messages on systems that are restricting the disk quota of users.

ȱʡÉèÖÃ: strict allocate = no

strict locking (S)
´Ë²¼¶ûÁ¿Ñ¡Ïî¿ØÖÆ·þÎñÆ÷¶ÔÎļþËøµÄ´¦Àí.µ±ÉèΪyes,Ôò·þÎñÆ÷¶ÔÎļþËø¼ì²éÿ´Î¶Áд·ÃÎÊ,²¢¾Ü¾øËø´æÔÚʱµÄ·ÃÎÊ.ÔÚÓÐЩϵͳÉÏÕâ¿ÉÄÜ»áºÜÂý.

µ±½ûÓÃstrict lockingʱ,·þÎñÆ÷Ö»ÔÚ¿Í»§Ã÷È·ÒªÇóʱ²ÅΪËûÃǼì²éÎļþËø.

Ñ­¹æµ¸¾ØµÄ¿Í»§×ÜÊÇÔÚÖØÒªµÄʱºòÒªÇó¼ì²éÎļþËø,ËùÒÔÔÚ¶àÊýÇé¿öÏÂstrict locking = noÊÇ¿ÉÈ¡µÄ.

ȱʡÉèÖÃ: strict locking = no

strict sync (S)
ºÜ¶àWindowsÓ¦ÓÃ(°üÀ¨Windows 98ä¯ÀÀÆ÷)¶¼»á¸ÉÈŶÔˢлº³åÇøÄÚÈݵ½´ÅÅ̵IJÙ×÷.ÔÚUNIXÏÂ,Ò»´Îͬ²½µ÷ÓÃÇ¿Öƽø³Ì¹ÒÆð,Ö±µ½ÄÚºËÈ·±£°ÑËùÓдÅÅÌ»º´æÇøÖеÄδÍê³ÉÊý¾Ý°²È«µØ´æµ½¹Ì¶¨´æ´¢É豸ÖÐΪֹ.´Ë²Ù×÷ºÜÂý,¶øÇÒÖ»ÄܺÜÉÙÓõ½.°Ñ´ËÑ¡ÏîÉèΪno (ȱʡֵ)˵Ã÷smbd(8) ºöÂÔWindowsÓ¦ÓÃÇëÇóµÄÒ»´Îͬ²½µ÷ÓÃ.ÕâÑùÖ»ÓÐÔÚSambaÔËÐеIJÙ×÷ϵͳ±ÀÀ£Ê±²Å¿ÉÄܶªÊ§Êý¾Ý,Òò´ËȱʡÉèÖÃΣÏÕÐÔºÜС.ÁíÍâ,ËüÐÞÕýÈËÃDZ¨¸æµÄºÜ¶à¹ØÓÚWindows98ä¯ÀÀÆ÷¿½±´ÎļþµÄÐÔÄÜÎÊÌâ.

²Î¼û sync always Ñ¡Ïî¡£

ȱʡÉèÖÃ: strict sync = no

sync always (S)
´Ë²¼¶ûÁ¿Ñ¡Ïî¿ØÖÆÊÇ·ñÔÚд²Ù×÷½áÊøÇ°°ÑËùдµÄÄÚÈÝдµ½¹Ì¶¨´æ´¢É豸ÉÏ.Èç¹ûΪnoÔò·þÎñÆ÷½«ÔÚÿ´Îдµ÷ÓÃÖÐÈÿͻ§ÇëÇóÀ´²Ù×ÝËü(¿Í»§¿ÉÒÔÉèÖÃÒ»¸öλÂëÀ´Ö¸³öҪͬ²½Ò»´ÎÌØÊâµÄд²Ù×÷).Èç¹ûΪyesÔòÔÚÿ´Îд²Ù×÷ºóµ÷ÓÃÒ»´Îfsync() ÒÔÈ·±£½«Êý¾Ýдµ½´ÅÅÌÉÏ.×¢Òâ±ØÐë°Ñstrict syncÑ¡ÏîÉèΪyesÒÔʹ±¾Ñ¡Ïî²úÉúЧ¹û.

²Î¼û strict sync Ñ¡Ïî¡£

ȱʡÉèÖÃ: sync always = no

syslog (G)
´ËÑ¡Ïî¾ö¶¨sambaµ÷ÊÔÐÅÏ¢ºÅÈçºÎÓ³ÉäΪϵͳsyslogµÄ¼Ç¼µÈ¼¶.µ÷ÊÔ¼¶0Ó³ÉäΪsyslogµÄLOG_ERR,µ÷ÊÔ¼¶1Ó³ÉäΪ LOG_WARNING,µ÷ÊÔ¼¶2Ó³ÉäΪLOG_NOTICE,µ÷ÊÔ¼¶3Ó³ÉäΪLOG_INFO.ËùÓиü¸ßµÄ¼¶±ðºÅÓ³ÉäΪ LOG_DEBUG.

´ËÑ¡ÏîÉèÖÃÁ˶Ôsyslog·¢ËÍÐÅÏ¢µÄãÐÖµ.Ö»ÓÐСÓÚ´ËÖµµÄµ÷ÊÔ¼¶ÐÅÏ¢ºÅ²Å·¢¸øsyslog.

ȱʡÉèÖÃ: syslog = 1

syslog only (G)
´ËÑ¡ÏîʹsambaÖ»°Ñµ÷ÊÔ¼¶±ðºÅ¼Ç¼µ½ÏµÍ³syslog,¶ø²»Êǵ÷ÊԼǼÎļþ.

ȱʡÉèÖÃ: syslog only = no

template homedir (G)
When filling out the user information for a Windows NT user, the winbindd(8) daemon uses this parameter to fill in the home directory for that user. If the string %D is present it is substituted with the user's Windows NT domain name. If the string %U is present it is substituted with the user's Windows NT user name.

ȱʡÉèÖÃ: template homedir = /home/%D/%U

template primary group (G)
This option defines the default primary group for each user created by winbindd(8)'s local account management functions (similar to the 'add user script').

ȱʡÉèÖÃ: template primary group = nobody

template shell (G)
When filling out the user information for a Windows NT user, the winbindd(8) daemon uses this parameter to fill in the login shell for that user.

ȱʡÉèÖÃ: template shell = /bin/false

time offset (G)
´ËÑ¡ÏîÊǸö¼ÓÈ뵽ת»»±ê×¼GMTΪµ±µØʱ¼ä²Ù×÷µÄ·ÖÖÓÊý.Èç¹ûÄãÏòºÜ¶àÓв»ÕýÈ·±£´æʱ¼ä²Ù×÷µÄÖ÷»úÌṩ·þÎñʱÕâ¾ÍºÜÓÐÓÃÁË.

ȱʡÉèÖÃ: time offset = 0

ʾÀý: time offset = 60

time server (G)
´ËÑ¡Ïî¼ì²ânmbd(8) ÊÇ·ñÒÔʱ¼ä·þÎñÆ÷Éí·ÝÏòWindows¿Í»§Í¨¸æ×ÔÉí.

ȱʡÉèÖÃ: time server = no

timestamp logs (G)
Óë debug timestamp ͬÒå.

unicode (G)
Specifies whether Samba should try to use unicode on the wire by default. Note: This does NOT mean that samba will assume that the unix machine uses unicode!

ȱʡÉèÖÃ: unicode = yes

unix charset (G)
Specifies the charset the unix machine Samba runs on uses. Samba needs to know this in order to be able to convert text to the charsets other SMB clients use.

ȱʡÉèÖÃ: unix charset = UTF8

ʾÀý: unix charset = ASCII

unix extensions (G)
This boolean parameter controls whether Samba implments the CIFS UNIX extensions, as defined by HP. These extensions enable Samba to better serve UNIX CIFS clients by supporting features such as symbolic links, hard links, etc... These extensions require a similarly enabled client, and are of no current use to Windows clients.

ȱʡÉèÖÃ: unix extensions = yes

unix password sync (G)
´Ë²¼¶ûÁ¿Ñ¡Ïî¿ØÖÆsambaÊÇ·ñÔÚsmbpasswdÎļþÖеļÓÃÜSMB¿ÚÁî±»¸ü¸Äʱ³¢ÊÔÓÃSMB¿ÚÁîÀ´Í¬²½UNIX¿ÚÁî.ÈçÉèΪyesÔòÒÔrootÉí·Ýµ÷ÓÃpasswd programÑ¡ÏîÖÐÖ¸¶¨µÄ³ÌÐò - ÒÔÔÊÐíÉèÖÃеÄUNIX¿ÚÁî¶øÎÞÐè·ÃÎÊÔ­UNIX¿ÚÁî(ÒòΪ¸ü¸ÄSMB¿ÚÁîʱ´úÂë²»·ÃÎÊÃ÷ÎĵÄÔ­¿ÚÁî¶øÖ»É漰пÚÁî).

²Î¼û passwd program, passwd chat.

ȱʡÉèÖÃ: unix password sync = no

update encrypted (G)
´Ë²¼¶ûÁ¿Ñ¡ÏîʹÒÔÃ÷ÎÄ¿ÚÁîµÇ¼µÄÓû§ÔڵǼʱ×Ô¶¯¸üÐÂsmbpasswdÎļþÖеļÓÃÜ(É¢ÁмÆËã¹ýµÄ)¿ÚÁî.´ËÑ¡ÏîÔÊÐíÒ»¸öÕ¾µã´ÓÃ÷ÎÄ¿ÚÁîÑéÖ¤·½Ê½(ÒÔÃ÷ÎÄ¿ÚÁîÑéÖ¤Óû§Õ˺Ų¢Ôٴμì²éUNIXÕ˺ÅÊý¾Ý¿â)ÒÆÖ²µ½¼ÓÃÜ¿ÚÁîÑéÖ¤·½Ê½(SMBµÄѯÎÊ/ÏìÓ¦ÑéÖ¤»úÖÆ)¶øÎÞÐèÇ¿ÖÆËùÓÐÓû§ÔÚÒÆֲʱͨ¹ýsmbpasswdÖØÐÂÊäÈëËûÃǵĿÚÁî.Õâ¶Ô¸Ä±ä¼ÓÃÜ¿ÚÁîÒƽ»Òª½Ï³¤ÖÜÆÚÕâÖÖ×´¿öÀ´ËµºÜ·½±ã.Ò»µ©ËùÓÐÓû§¶¼ÔÚsmbpasswdÎļþÖÐÓµÓÐËûÃǼÓÃܹýµÄ¿ÚÁî,Ôò´ËÓ¦¸Ã°Ñ´ËÑ¡ÏîÉèΪno.

ΪÁËÈôËÑ¡ÏîÕýÈ·¹¤×÷,µ±ËüÉèΪyesʱ±ØÐë°Ñ encrypt passwordsÑ¡ÏîÉèΪno .

×¢Ò⼴ʹÉèÖÃÁË´ËÑ¡Ïî,smbd»¹ÊDZØÐëÑéÖ¤Óû§Õ˺Å,Ö±µ½ÊäÈëºÏ·¨µÄ¿ÚÁîºó²ÅÄÜÕýÈ·Á¬½Ó²¢¸üÐÂËûÃǵÄÉ¢ÁмÆËã(ÓÉsmbpasswdÍê³É)ºóµÄ¿ÚÁî×Ö.

ȱʡÉèÖÃ: update encrypted = no

use client driver (S)
This parameter applies only to Windows NT/2000 clients. It has no effect on Windows 95/98/ME clients. When serving a printer to Windows NT/2000 clients without first installing a valid printer driver on the Samba host, the client will be required to install a local printer driver. From this point on, the client will treat the print as a local printer and not a network printer connection. This is much the same behavior that will occur when disable spoolss = yes.

The differentiating factor is that under normal circumstances, the NT/2000 client will attempt to open the network printer using MS-RPC. The problem is that because the client considers the printer to be local, it will attempt to issue the OpenPrinterEx() call requesting access rights associated with the logged on user. If the user possesses local administator rights but not root privilegde on the Samba host (often the case), the OpenPrinterEx() call will fail. The result is that the client will now display an "Access Denied; Unable to connect" message in the printer queue window (even though jobs may successfully be printed).

If this parameter is enabled for a printer, then any attempt to open the printer with the PRINTER_ACCESS_ADMINISTER right is mapped to PRINTER_ACCESS_USE instead. Thus allowing the OpenPrinterEx() call to succeed. This parameter MUST not be able enabled on a print share which has valid print driver installed on the Samba server.

²Î¼û disable spoolss

ȱʡÉèÖÃ: use client driver = no

use mmap (G)
This global parameter determines if the tdb internals of Samba can depend on mmap working correctly on the running system. Samba requires a coherent mmap/read-write system memory cache. Currently only HPUX does not have such a coherent cache, and so this parameter is set to no by default on HPUX. On all other systems this parameter should be left alone. This parameter is provided to help the Samba developers track down problems with the tdb internal code.

ȱʡÉèÖÃ: use mmap = yes

user (S)
Óë username ͬÒå

username (S)
ÔÚ¶ººÅ·Ö¸ôµÄÁбíÖÐÖ¸¶¨¶à¸öÓû§ÒÔÓÃÓÚÂÖÁ÷(´Ó×óµ½ÓÒ)²âÊÔËùÌṩµÄ¿ÚÁî.

Ö»Óе±Ö÷»úÎÞ·¨ÌṩËü×Ô¼ºµÄÓû§Ãûʱ²ÅÐèÒªusernameÑ¡Ïî¡£µ±ÓÃCOREPLUSЭÒé»òÄãµÄÓû§ÓµÓÐÓëUNIXÓû§Ãû²»Í¬µÄWfWgÓû§Ãûʱ¾Í»áÓÐÕâÑùµÄÇé¿ö.ÔÚÕâÁ½ÖÖÇé¿öÏÂ,ÓÃ\serverhare%userÓï¾ä´úÌæ»á¸üºÃµÄ.

ÔÚ´ó¶àÊýÇé¿öÏÂusernameÑ¡Ïî²¢²»ÊÇ×îºÃµÄ½â¾ö·½°¸,ÒòΪËüÒâζ×ÅSamba»á³¢ÊÔ¶ÔusernameÑ¡ÏîÐÐÖеÄÿ¸öÓû§ÃûÂÖÁ÷×÷²âÊÔ.ÕâÑù×öÊǺÜÂýµÄ,¶øÇÒÍòÒ»ºÜ¶àÓû§Öظ´¿ÚÁîµÄ»°Õâ¾ÍÊǸö»µÖ÷ÒâÁË.´íÎóʹÓôËÑ¡Ïî¿ÉÄÜ»á´øÀ´³¬Ê±»ò°²È«È±ÏÝ.

sambaÒÀ¿¿µ×²ãµÄUNIX°²È«.´ËÑ¡Ïî²»ÏÞÖƵǼÕß,ËüÖ»¶ÔSamba·þÎñÆ÷ÌṩÏìÓ¦ËùÌṩ¿ÚÁîµÄÓû§ÃûµÄÏßË÷.ÈκÎϲ»¶µÄÈ˶¼¿ÉÒԵǼ,¶øÇÒÈç¹ûËûÃÇÖ»ÊÇÆô¶¯Ò»´Îtelnet¶Ô»°µÄ»°²»»áÔì³ÉÆÆ»µ.½ø³ÌÒԵǼµÄÓû§Éí·ÝÔËÐÐ,ËùÒÔËûÃÇÎÞ·¨×öÈκÎËûÃDz»ÄÜ×öµÄʶù.

Òª¶ÔÒ»×éÌØÊâµÄÓû§ÏÞÖÆÒ»¸ö·þÎñµÄ»°¿ÉÒÔÓà valid users Ñ¡Ïî.

Èç¹ûÈκÎÓû§ÃûÒÔ'@'×Ö·û¿ªÊ¼Ôò´ËÓû§Ãû½«Ê×ÏÈÔÚNISÍøÂç×éÁбí(Èç¹ûSamba±àÒëʱ¼ÓÈëÁËÍøÂç×éÖ§³ÖµÄ»°)ÖнøÐвéÕÒ,È»ºóÔÚUNIXÓû§×éÊý¾Ý¿âÖвéÕÒ²¢Õ¹¿ª³ÉÊôÓÚÒÔ´ËÃûΪ×éµÄËùÓÐÓû§µÄÁбí.

Èç¹ûÈκÎÓû§ÃûÒÔ'+'×Ö·û¿ªÊ¼Ôò´ËÓû§ÃûÖ»ÔÚUNIXÓû§×éÊý¾Ý¿âÖнøÐвéÕÒ²¢Õ¹¿ª³ÉÊôÓÚÒÔ´ËÃûΪ×éµÄËùÓÐÓû§µÄÁбí.

Èç¹ûÈκÎÓû§ÃûÒÔ'&'×Ö·û¿ªÊ¼Ôò´ËÓû§ÃûÖ»ÔÚNISÍøÂç×éÁбí(Èç¹ûSamba±àÒëʱ¼ÓÈëÁËÍøÂç×éÖ§³ÖµÄ»°)ÖнøÐвéÕÒ²¢Õ¹¿ª³ÉÊôÓÚÒÔ´ËÃûΪ×éµÄËùÓÐÓû§µÄÁбí.

×¢Òâͨ¹ýÓû§×éÊý¾Ý¿â½øÐвéÕÒÒª»¨ºÜ³¤Ê±¼ä,ÔÚ´ËÆÚ¼äÓÐЩ¿Í»§¿ÉÄܻᳬʱ.

²é¿´ NOTE ABOUT USERNAME/PASSWORD VALIDATION ¶ÎÀ´»ñµÃÕâ¸öÑ¡ÏîÈçºÎ¾ö¶¨·ÃÎÊ·þÎñ·½ÃæµÄÐÅÏ¢¡£

ȱʡÉèÖÃ: Èç¹ûÊÇguest·þÎñ¾ÍÊÇguestÕʺÅ,·ñÔòÊÇ¿Õ×Ö·û´®.

ʾÀý:username = fred, mary, jack, jane, @users, @pcgroup

username level (G)
´ËÑ¡ÏîÔںܶàDOS¿Í»§·¢ËÍÈ«´óдµÄÓû§Ãûʱ,°ïÖúsamba³¢ÊԺ͡°²Â²â¡±Êµ¼ÊUNIXÓû§Ãû.¶ÔÓÚȱʡÇé¿ö,Samba³¢ÊÔËùÓÐСдÐÎʽ,È»ºóÊÇÊ××Öĸ´óдÐÎʽ,Èç¹û¸ÃÓû§ÃûÔÚUNIXÖ÷»úÉÏûÓÐÕÒµ½Ôòʧ°Ü.

Èç¹û°Ñ´ËÑ¡ÏîÉèΪ·Ç0,ÔòÇé¿ö¾Í¸Ä±äÁË.´ËÑ¡ÏîÖ¸¶¨µÄÊÇÓÃÓÚ³¢ÊÔͬʱ¼ì²âUNIXÓû§ÃûµÄ´óд×ÖĸµÄ×éºÏÊý.Êý×ÖÔ½¸ß,Ôò³¢ÊÔµÄ×éºÏÊýÔ½¶à,µ«Óû§ÃûµÄ·¢ÏÖÒ²Ô½Âý.µ±ÔÚÄãµÄUNIXÖ÷»úÉÏÓÐÆæÌصÄÓû§ÃûÈçAstrangeUser ʱʹÓôËÑ¡Ïî.

ȱʡÉèÖÃ: username level = 0

ʾÀý: username level = 5

username map (G)
´ËÑ¡ÏîÔÊÐíÄãÖ¸¶¨Ò»¸ö°üº¬¶Ô¿Í»§»úµ½·þÎñÆ÷ÉϵÄÓû§ÃûÓ³ÉäµÄÎļþ.Ëü¿ÉÓÃÓÚ¼¸¸öÄ¿µÄ.×î³£¼ûµÄÊÇ°ÑÓÃDOS»òWindowsÖ÷»úµÄÓû§µÄÃû³ÆÓ³Éäµ½UNIXÖ÷»úÉϵÄÓû§.ÆäËü»¹ÓаѶà¸öÓû§Ó³Éäµ½µ¥¸öÓû§ÃûÉÏÒÔʹËûÃÇ¿ÉÒÔ¸ü¼òµ¥µØ¹²ÏíÎļþ.

Ó³ÉäÎļþ±»ÖðÐнâÎö.ÿ¸öÐж¼Ó¦¸ÃÔÚ'='ºÅ×ó±ß°üº¬Ò»¸öUNIXÓû§Ãû,¶øÔÚÓұ߸úÉÏÒ»ÁÐÓû§Ãû.ÓұߵÄÓû§ÃûÁбí¿ÉÒÔ°üº¬@groupÐÎʽµÄÃû³Æ,Ëü±íʾƥÅäÈκÎ×éÖеÄUNIXÓû§Ãû.ÌØÊâ¿Í»§Ãû'*'ÊÇÒ»¸öͨÅä·ûÓÃÓÚÆ¥ÅäÈκÎÃû³Æ.Ó³ÉäÎļþµÄÿ¸öÐпÉÒÔ´ïµ½1023¸ö×Ö·ûµÄ³¤¶È.

¶ÔÎļþµÄ´¦ÀíÊÇÔÚÿ¸öÐÐÉÏÈ¡µÃÌṩµÄÓû§Ãû²¢°ÑËüÓë'='ºÅÓұߵÄÿ¸öÓû§Ãû½øÐбȽÏ.Èç¹ûÌṩµÄÃû³ÆÆ¥ÅäÓұߵÄÈκÎÃû³ÆÔòÓÃ×ó±ßµÄÃû³ÆÌæ»»ÓұߵÄ.È»ºó¼ÌÐø´¦ÀíÏÂÒ»ÐÐ.

ºöÂÔÒÔ'#' »ò ';'ºÅ¿ªÊ¼µÄÐÐ.

µ±ÔÚÐÐÖз¢ÏÖÁËÆ¥Åä,ÔòÔÚÒÔ'!'¿ªÊ¼µÄÐкóÖÐÖ¹´¦Àí,·ñÔò¼ÌÐø´¦ÀíÿһÐеÄÓ³Éä.µ±ÄãÔÚÎļþÖÐÓÃÁËͨÅäÓ³ÉäµÄ»°'!'¾ÍºÜÓÐÓÃÁË.

ÀýÈç°ÑÃû³Æadmin »ò administratorÓ³ÉäΪUNIXÃû root,Äã¿ÉÒÔÕâÑù£º

root = admin administrator

»ò°ÑUNIX×é systemÖеÄÈκÎÈËÓ³ÉäΪUNIXÃûsys¾Í¿ÉÒÔÕâÑù£º

sys = @system

¿ÉÒÔÔÚÒ»¸öÓû§ÃûÓ³ÉäÎļþÖаüº¬ºÜ¶àÓ³Éä¹Øϵ.

Èç¹ûÄãµÄϵͳ֧³ÖNIS NETGROUPÑ¡Ïî,ÔòÔÚʹÓÃ/etc/group Æ¥Åä×é֮ǰÏȼì²éÍøÂç×éÊý¾Ý¿â.

Äã¿ÉÒÔͨ¹ýÔÚÃû³ÆÉÏʹÓÃË«ÒýºÅÀ´Ó³É京ÓпոñµÄWindowsÓû§Ãû.ÀýÈ磺

tridge = "Andrew Tridgell"

½«°ÑwindowsÓû§Ãû"Andrew Tridgell"Ó³ÉäΪunixÓû§Ãû"tridge".

ÒÔÏÂʾÀý½«°ÑmaryºÍfredÓ³ÉäΪunixÓû§sys,È»ºó°ÑÆäÓàµÄÓ³ÉäΪguest.×¢ÒâʹÓÃ'!'·ûºÅ¿ÉÒÔ¸æËßSambaÈç¹ûÔÚ¸ÃÐлñµÃÒ»¸öÆ¥ÅäµÄ»°¾ÍÍ£Ö¹´¦Àí.

!sys = mary fred
guest = *

×¢ÒâÖØÓ³Éä×÷ÓÃÓÚËùÓгöÏÖÓû§ÃûµÄµØ·½.Òò´ËÈç¹ûÄãÁ¬½Óµ½\\server\fred¶ø fredÒѱ»ÖØÓ³ÉäΪ mary,ÔòÄãʵ¼Ê»áÁ¬½Óµ½\\server\mary"²¢ÐèÒªÌṩmaryµÄ¿ÚÁî¶ø²»ÊÇ fredµÄ.ÕâÖÖÇé¿öÖ»ÓÐÒ»¸öÀýÍâ,ÄǾÍÊÇÓû§ÃûÊDZ»´«µ½ password server(Èç¹ûÄãÓÐÒ»¸öµÄ»°)ÑéÖ¤µÄ.¿ÚÁî·þÎñÆ÷»á½ÓÊÕ¿Í»§ÌṩµÄδ¾­Ð޸ĵÄÓû§Ãû.

ͬʱҪעÒâ·´ÏòÓ³ÉäÊDz»»á³öÏÖµÄ.ÕâÖ÷ÒªÓ°ÏìµÄÊÇ´òÓ¡ÈÎÎñ.ÒѾ­±»Ó³ÉäµÄÓû§»áÔÚɾ³ý´òÓ¡ÈÎÎñʱÓöµ½Âé·³,ÒòΪWfWgÉϵĴòÓ¡¹ÜÀíÆ÷»áÈÏΪËûÃDz»ÊÇ´òÓ¡ÈÎÎñµÄÊôÖ÷.

ȱʡÉèÖÃ: no username map

ʾÀý: username map = /usr/local/samba/lib/users.map

users (S)
Óë username ͬÒå.

use sendfile (S)
If this parameter is yes, and Samba was built with the --with-sendfile-support option, and the underlying operating system supports sendfile system call, then some SMB read calls (mainly ReadAndX and ReadRaw) will use the more efficient sendfile system call for files that are exclusively oplocked. This may make more efficient use of the system CPU's and cause Samba to be faster. This is off by default as it's effects are unknown as yet.

ȱʡÉèÖÃ: use sendfile = no

use spnego (G)
This variable controls controls whether samba will try to use Simple and Protected NEGOciation (as specified by rfc2478) with WindowsXP and Windows2000 clients to agree upon an authentication mechanism. Unless further issues are discovered with our SPNEGO implementation, there is no reason this should ever be disabled.

ȱʡÉèÖÃ: use spnego = yes

utmp (G)
This boolean parameter is only available if Samba has been configured and compiled with the option --with-utmp. If set to yes then Samba will attempt to add utmp or utmpx records (depending on the UNIX system) whenever a connection is made to a Samba server. Sites may use this to record the user connecting to a Samba share.

Due to the requirements of the utmp record, we are required to create a unique identifier for the incoming user. Enabling this option creates an n^2 algorithm to find this number. This may impede performance on large installations.

²Î¼û utmp directory Ñ¡Ïî¡£

ȱʡÉèÖÃ: utmp = no

utmp directory (G)
This parameter is only available if Samba has been configured and compiled with the option --with-utmp. It specifies a directory pathname that is used to store the utmp or utmpx files (depending on the UNIX system) that record user connections to a Samba server. ²Î¼û utmp Ñ¡Ïî¡£ By default this is not set, meaning the system will use whatever utmp file the native system is set to use (usually /var/run/utmp on Linux).

ȱʡÉèÖÃ: no utmp directory

ʾÀý: utmp directory = /var/run/utmp

-valid (S)
This parameter indicates whether a share is valid and thus can be used. When this parameter is set to false, the share will be in no way visible nor accessible.

This option should not be used by regular users but might be of help to developers. Samba uses this option internally to mark shares as deleted.

ȱʡÉèÖÃ: True

valid users (S)
ÕâÊÇÒ»·ÝÔÊÐíµÇ¼·þÎñÏîµÄÓû§Áбí.ÒÔ'@','+'ºÍ'&'¿ªÊ¼µÄÃû³ÆÓÃinvalid users Ñ¡ÏîÖеĹæÔò½øÐнâÎö.

Èç¹û´ËÏîΪ¿Õ(ȱʡ)ÔòÈκÎÓû§¶¼¿ÉÒԵǼ.Èç¹ûÒ»¸öÓû§Ãûͬʱ´æÔÚÓÚ´ËÁÐ±í¼°invalid usersÁбí,Ôò¾Ü¾ø´ËÓû§·ÃÎÊ.

%S Ì滻Ϊµ±Ç°·þÎñÃû. ÕâÔÚ[homes]¶ÎÀï·Ç³£ÓÐÓÃ.

²Î¼û invalid users

ȱʡÉèÖÃ: ¿Õ (ÈκÎÈ˶¼²»»á±»¾Ü¾ø)

ʾÀý: valid users = greg, @pcusers

veto files (S)
ÕâÊÇÒ»·Ý¼È²»¿É¼ûÓÖ²»¿É·ÃÎʵÄÎļþ¼°Ä¿Â¼µÄÁбí.ÔÚÁбíÖеÄÿһÏî±ØÐëÓÃ'/'½øÐзָô,ÏîÄ¿ÖÐÔÊÐíÓпոñ.¿ÉÒÔÓÃDOSͨÅä·û'*'ºÍ'?'À´Ö¸¶¨¶à¸öÎļþ»òĿ¼.

ÿÏî±ØÐëÊÇÒ»¸öUNIX·¾¶,¶ø·ÇÒ»¸öDOS·¾¶,ͬʱ±ØÐë²»º¬ UNIXĿ¼·Ö¸ô·û'/'.

×¢Òâcase sensitiveÑ¡ÏîÊÊÓÃÓÚ¶ÔÎļþµÄ½ûֹĿµÄ.

ÐèÒªÃ÷°×Õâ¸öÑ¡ÏîµÄºÜÖØÒªµÄÒ»¸öÌصã: ÔÚSambaɾ³ýÒ»¸öĿ¼ʱµÄÐÐΪ¡£Èç¹ûÒ»¸öĿ¼³ýÁËveto filesÖ®Íâ²»°üº¬ÈκÎÄÚÈÝ£¬É¾³ý²Ù×÷½«Ê§°Ü£¬³ý·ÇÉèÖÃÁËdelete veto files ÊÇyes.

ÉèÖôËÑ¡Ïî»áÓ°ÏìSambaµÄÐÔÄÜ,ÒòΪËü½«Ç¿ÖÆÔÚɨÃèËùÓÐÎļþºÍĿ¼ʱ¼ì²éÊÇ·ñÆ¥Åä.

²Î¼û hide files ºÍ case sensitive.

ȱʡÉèÖÃ: ûÓÐÒþ²ØÈκÎÎļþ.

ʾÀý:

; Òþ²ØÈκÎÎļþÃû´øÓÐ'Security'µÄÎļþ£¬
; ÈκÎÀ©Õ¹ÃûÊÇ.tmpµÄÎļþ,ÈκÎÎļþÃû´øÓÐ'root'µÄÎļþ
veto files = /*Security*/*.tmp/*root*/

; Òþ²ØNetAtalk·þÎñÆ÷´´½¨µÄAppleרÓõÄÎļþ
veto files = /.AppleDouble/.bin/.AppleDesktop/Network Trash Folder/

veto oplock files (S)
´ËÑ¡ÏîÖ»ÔÚ¶ÔÒ»¸ö¹²Ïí´ò¿ªÁËoplocksÑ¡Ïîʱ²ÅÓÐЧ.ËüÔÊÐíSamba¹ÜÀíÔ±ÔÚËùÑ¡ÎļþÉÏÑ¡ÔñÐԵعرÕÔÊÐíoplocks,ÕâЩÎļþ¿ÉÒÔÓÃͨÅä·ûÁбíÀ´Æ¥Åä,ÀàÄâÓÚÔÚveto files Ñ¡ÏîÖÐËùÓõÄͨÅä·ûÁбí.

ȱʡÉèÖÃ: ûÓÐÒþ²ØoplocksÐí¿É

Äã¿ÉÄÜÏëÔÚÒÑÖª¿Í»§»áÃÍÁÒÕù¶áµÄÎļþÉÏʹÓôËÏî.ÔÚNetBench SMB»ù×¼³ÌÐòÏÂÃæ¾ÍÊǸöºÃÀý×Ó,Ëüµ¼Ö¿ͻ§ÃÍÁҵضÔÒÔ.SEMºó׺µÄÎļþ½øÐÐÁ¬½Ó.ΪʹSamba²»ÔÚÕâЩÎļþÉÏÔÊÐíoplocks,Äã¿ÉÒÔÔÚ[global]¶Î»òÌض¨µÄNetBench¹²ÏíÖÐʹÓôËÐУº

ʾÀý: veto oplock files = /*.SEM/

vfs object (S)
Óë vfs objects ͬÒå.

vfs objects (S)
This parameter specifies the backend names which are used for Samba VFS I/O operations. By default, normal disk I/O operations are used but these can be overloaded with one or more VFS objects.

ȱʡÉèÖÃ: no value

ʾÀý: vfs objects = extd_audit recycle

volume (S)
´ËÑ¡ÏîÔÊÐíÄãºöÂÔ¹²ÏíÏîÌṩµÄ¾í±ê.Õâ¶ÔÓÚÄÇЩ¼á³ÖҪʹÓÃÒ»¸öÌØÊâ¾í±êµÄ°²×°³ÌÐò¹âÅÌÀ´ËµºÜÓÐÓÃ.ȱʡ¾ÍÊǹ²ÏíÏîµÄ¾í±ê.

ȱʡÉèÖÃ: ¹²ÏíµÄÃû³Æ

wide links (S)
´ËÑ¡Ïî¿ØÖÆ·þÎñÆ÷ÊÇ·ñ¸ú×ÙUNIXÎļþϵͳÖеķûºÅÁ´½Ó.Ö¸Ïò·þÎñÆ÷µ¼³öµÄĿ¼Ê÷µÄÁ´½Ó×ÜÊDZ»ÔÊÐíµÄ£»´ËÑ¡ÏîÖ»ÊÇ¿ØÖƶԵ¼³öĿ¼Ê÷ÒÔÍâµÄÇøÓòµÄ·ÃÎÊÇé¿ö.

×¢ÒâÉèÖôËÑ¡Ïî¿É¶Ô·þÎñÆ÷ÐÔÄܲúÉú¸ºÃæÓ°Ïì,ÒòΪsamba±ØÐë×öһЩ¶îÍâµÄϵͳµ÷ÓÃÒÔ¼ì²éÄÇЩÁ´½Ó.

ȱʡÉèÖÃ: wide links = yes

winbind cache time (G)
This parameter specifies the number of seconds the winbindd(8) daemon will cache user and group information before querying a Windows NT server again.

ȱʡÉèÖÃ: winbind cache type = 300

winbind enable local accounts (G)
This parameter controls whether or not winbindd will act as a stand in replacement for the various account management hooks in smb.conf (e.g. 'add user script'). If enabled, winbindd will support the creation of local users and groups as another source of UNIX account information available via getpwnam() or getgrgid(), etc...

ȱʡÉèÖÃ: winbind enable local accounts = yes

winbind enum groups (G)
On large installations using winbindd(8) it may be necessary to suppress the enumeration of groups through the setgrent(), getgrent() and endgrent() group of system calls. If the winbind enum groups parameter is no, calls to the getgrent() system call will not return any data.

Warning: Turning off group enumeration may cause some programs to behave oddly.

ȱʡÉèÖÃ: winbind enum groups = yes

winbind enum users (G)
On large installations using winbindd(8) it may be necessary to suppress the enumeration of users through the setpwent(), getpwent() and endpwent() group of system calls. If the winbind enum users parameter is no, calls to the getpwent system call will not return any data.

Warning: Turning off user enumeration may cause some programs to behave oddly. For example, the finger program relies on having access to the full user list when searching for matching usernames.

ȱʡÉèÖÃ: winbind enum users = yes

winbind gid (G)
This parameter is now an alias for idmap gid

The winbind gid parameter specifies the range of group ids that are allocated by the winbindd(8) daemon. This range of group ids should have no existing local or NIS groups within it as strange conflicts can occur otherwise.

ȱʡÉèÖÃ: winbind gid = <¿Õ×Ö·û´®>

ʾÀý: winbind gid = 10000-20000

winbind separator (G)
This parameter allows an admin to define the character used when listing a username of the form of DOMAIN \user. This parameter is only applicable when using the pam_winbind.so and nss_winbind.so modules for UNIX services.

Please note that setting this parameter to + causes problems with group membership at least on glibc systems, as the character + is used as a special character for NIS in /etc/group.

ȱʡÉèÖÃ: winbind separator = ''

ʾÀý: winbind separator = +

winbind trusted domains only (G)
This parameter is designed to allow Samba servers that are members of a Samba controlled domain to use UNIX accounts distributed vi NIS, rsync, or LDAP as the uid's for winbindd users in the hosts primary domain. Therefore, the user 'SAMBA\user1' would be mapped to the account 'user1' in /etc/passwd instead of allocating a new uid for him or her.

ȱʡÉèÖÃ: winbind trusted domains only = <no>

winbind uid (G)
This parameter is now an alias for idmap uid

The winbind gid parameter specifies the range of user ids that are allocated by the winbindd(8) daemon. This range of ids should have no existing local or NIS users within it as strange conflicts can occur otherwise.

ȱʡÉèÖÃ: winbind uid = <¿Õ×Ö·û´®>

ʾÀý: winbind uid = 10000-20000

winbind use default domain (G)
This parameter specifies whether the winbindd(8) daemon should operate on users without domain component in their username. Users without a domain component are treated as is part of the winbindd server's own domain. While this does not benifit Windows users, it makes SSH, FTP and e-mail function in a way much closer to the way they would in a native unix system.

ȱʡÉèÖÃ: winbind use default domain = <no>

ʾÀý: winbind use default domain = yes

wins hook (G)
µ±°ÑSamba×÷Ϊһ̨WINS·þÎñÆ÷ÔËÐÐʱ,´ËÑ¡ÏîÔÊÐíÄãµ÷ÓÃÒ»¸öÍⲿ³ÌÐò¸ü¸ÄWINSÊý¾Ý¿â.´ËÏîÖ÷ÒªÓÃÓÚ¶¯Ì¬¸üÐÂÍⲿÃû×Ö½âÎöÊý¾Ý¿â,È綯̬DNS.

´ËÑ¡ÏîÒÔÈçÏÂÐÎʽָ¶¨Òªµ÷ÓõÄÒ»¸ö½Å±¾Ãû»ò¿ÉÖ´ÐгÌÐò£º

wins_hook operation name nametype ttl IP_list

µÚÒ»²¿·Ö²ÎÊýÊÇopration(²Ù×÷·û),ËüÓÐÈýÖÖ£º"add"¡¢"delete"ºÍ"refresh".ÔںܶàÇé¿öϸòÙ×÷·û¿ÉÒÔºöÂÔ,ÒòΪÆäËüÑ¡Ïî¿ÉÌṩ×ã¹»µÄÐÅÏ¢.×¢Òâµ±ÓÐÃû³ÆÒÔǰûÓмÓÈë¹ý,ÔòÓÐʱ»áÓõ½"refresh",ÔÚÕâÖÖÇé¿öÏÂ,ËüÓ¦¸ÃºÍ"add"ÓÐͬÑùº¬Òå.

µÚ¶þ²¿·Ö²ÎÊýÊÇnetbiosÃû.Èç¹û¸ÃÃû³Æ²»ÊǺϷ¨ÃûµÄ»°,¸Ã¹¦ÄܾͲ»ÔËÐÐ.ºÏ·¨µÄÃû³ÆÓ¦Ö»°üº¬×Öĸ,Êý×Ö,¼õºÅ,Ï»®Ïߺ;äµã.

µÚÈý²¿·Ö²ÎÊýÊÇÓÃ2λʮÁù½øÖÆÊý×Ö±íʾµÄnetbiosÃû³ÆÀàÐÍ.

µÚËIJ¿·Ö²ÎÊýÊÇÒÔÃë¼ÆËãµÄÃû³ÆÓÐЧʱ¼äTTL (time to live).

µÚÎ岿·ÖÊǵ±Ç°¸ÃÃû³ÆËù×¢²áµÄIPµØÖ·±í.Èç¹û±íΪ¿ÕÔò¸ÃÃû³Æ±»É¾³ý.

Ò»¸öµ÷ÓÃBIND¶¯Ì¬DNS¸üгÌÐònsupdateµÄ½Å±¾Ê¾ÀýÔÚsambaÔ´´úÂëµÄʾÀýĿ¼¿ÉÒÔÕÒµ½.

wins partners (G)
A space separated list of partners' IP addresses for WINS replication. WINS partners are always defined as push/pull partners as defining only one way WINS replication is unreliable. WINS replication is currently experimental and unreliable between samba servers.

ȱʡÉèÖÃ: wins partners =

ʾÀý: wins partners = 192.168.0.1 172.16.1.2

wins proxy (G)
´Ë²¼¶ûÁ¿Ñ¡Ïî¿ØÖÆnmbd(8) ÊÇ·ñ´úÌæÆäËüÖ÷»úÏìÓ¦¹ã²¥Ãû×Ö²éѯ.¶ÔһЩ¾É°æ±¾¿Í»§¾Í¿ÉÄÜÐèÒª°ÑËüÉèΪyes .

ȱʡÉèÖÃ: wins proxy = no

wins server (G)
´ËÑ¡ÏîÖ¸¶¨nmbdҪע²áµÄWINS·þÎñÆ÷µÄIPµØÖ·(»òDNSÓòÃû£ºIPµØÖ·ÓÅÏÈ(for preference)).Èç¹ûÔÚÄãµÄÍøÂçÉÏÓÐһ̨WINS·þÎñÆ÷,¾ÍÓ¦¸Ã°Ñ´ËÏîÉèΪ¸Ã·þÎñÆ÷µÄIPµØÖ·.

Èç¹ûÄãÓжà¸ö×ÓÍøµÄ»°,Ó¦¸ÃÖ¸¶¨ÏòÄãµÄWINS·þÎñÆ÷

If you want to work in multiple namespaces, you can give every wins server a 'tag'. For each tag, only one (working) server will be queried for a name. The tag should be seperated from the ip address by a colon.

×¢Òâ,ÈçÓжà×ÓÍø²¢Ï£Íû¿ç×ÓÍøä¯ÀÀ¹¤×÷Õý³£µÄ»°,Ó¦¸ÃÉèÖÃSambaÖ¸Ïòһ̨WINS·þÎñÆ÷.

ȱʡÉèÖÃ: δÆôÓÃ

ʾÀý: wins server = mary:192.9.200.1 fred:192.168.3.199 mary:192.168.2.61

For this example when querying a certain name, 192.19.200.1 will be asked first and if that doesn't respond 192.168.2.61 . If either of those doesn't know the name 192.168.3.199 will be queried.

ʾÀý: wins server = 192.9.200.1 192.168.2.61

wins support (G)
´Ë²¼¶ûÁ¿Ñ¡Ïî¿ØÖÆnmbd(8)½ø³ÌÊÇ·ñ×÷ΪWINS·þÎñÆ÷.Äã²»Ó¦¸Ã°ÑËüÉèΪyes,³ý·ÇÓжà×ÓÍø»òÏ£ÍûÌض¨µÄnmbd×÷ΪÄãµÄWINS·þÎñÆ÷.×¢ÒâÔÚÍøÂçÉÏÓжą̀WINS·þÎñÆ÷ʱ²»Ó¦°ÑËüÉèΪyes.

ȱʡÉèÖÃ: wins support = no

workgroup (G)
´ËÑ¡Ïî¹æ¶¨SambaËùÔڵŤ×÷×éÒÔ±ãÈÿͻ§²éѯ.×¢ÒâËüÒ²¹æ¶¨ÔÚʹÓÃsecurity = domainʱËùÓõÄÓòÃû.

ȱʡÉèÖÃ: ±àÒëʱÉèÖÃΪ WORKGROUP

ʾÀý: workgroup = MYGROUP

writable (S)
Óë writeable Ïàͬ£¬ÊÇΪƴд´íÎóÕß×¼±¸µÄ :-)

writeable (S)
×¢ÒâËüÓë read only ·´Òå.

write cache size (S)
If this integer parameter is set to non-zero value, Samba will create an in-memory cache for each oplocked file (it does not do this for non-oplocked files). All writes that the client does not request to be flushed directly to disk will be stored in this cache if possible. The cache is flushed onto disk when a write comes in whose offset would not fit into the cache or when the file is closed by the client. Reads for the file are also served from this cache if the data is stored within it.

This cache allows Samba to batch client writes into a more efficient write size for RAID disks (i.e. writes may be tuned to be the RAID stripe size) and can improve performance on systems where the disk subsystem is a bottleneck but there is free memory for userspace programs.

The integer parameter specifies the size of this cache (per oplocked file) in bytes.

ȱʡÉèÖÃ: write cache size = 0

ʾÀý: write cache size = 262144

for a 256k cache size per file.

write list (S)
´ËÑ¡ÏîÉèÖöԷþÎñÏîÓжÁдȨµÄÓû§Áбí.Èç¹ûÕýÔÚÁ¬½ÓµÄÓû§ÊôÓÚ´ËÁбí,ÄÇËûÃǾͿÉÒÔÓÐдÈëȨ,¶ø²»¹Üread onlyΪºÎÖµ.´ËÁбí¿ÉÒÔÓÃ@groupÐÎʽÃèÊö×éÃû.

×¢ÒâÈç¹ûÒ»¸öÓû§Í¬Ê±ÊôÓÚ¶ÁÁбíºÍдÁбíÔòÓµÓÐдÈëȨ.

²Î¼û read list Ñ¡Ïî¡£

ȱʡÉèÖÃ: write list = <¿Õ×Ö·û´®>

ʾÀý: write list = admin, root, @staff

write ok (S)
×¢ÒâËüÓë read only ·´Òå.

write raw (G)
´ËÑ¡Ïî¹æ¶¨·þÎñÆ÷ÊÇ·ñÔÚ´Ó¿Í»§¶Ë´«ÊäÊý¾Ýʱ֧³Öԭʼ·½Ê½Ð´SMBÏûÏ¢¿é.Äã²»Ó¦¸Ã¸ü¸ÄËü.

ȱʡÉèÖÃ: write raw = yes

wtmp directory (G)
This parameter is only available if Samba has been configured and compiled with the option --with-utmp. It specifies a directory pathname that is used to store the wtmp or wtmpx files (depending on the UNIX system) that record user connections to a Samba server. The difference with the utmp directory is the fact that user info is kept after a user has logged out.

²Î¼û utmp Ñ¡Ïî¡£ By default this is not set, meaning the system will use whatever utmp file the native system is set to use (usually /var/run/wtmp on Linux).

ȱʡÉèÖÃ: no wtmp directory

ʾÀý: wtmp directory = /var/log/wtmp

¾¯¸æ WARNINGS

ËäÈ»ÅäÖÃÎļþÔÊÐí·þÎñÏîÃû°üº¬¿Õ¸ñ,µ«ÄãµÄ¿Í»§¶ËÈí¼þ¾Í²»Ò»¶¨ÁË.ÒòΪÔڱȽÏÖÐ×ÜÊǺöÂÔ¿Õ¸ñ,ËùÒÔÕâ²»³ÉÎÊÌâ - µ«Ó¦¸ÃÈÏʶµ½ÆäËü¿ÉÄÜÐÔ.

ÓÐÒ»ÌõÀàËÆÌáʾ,ºÜ¶à¿Í»§ÌرðÊÇDOS¿Í»§,»áÏÞÖÆ·þÎñÏîÃûΪ8¸ö×Ö·û.ËäÈ» smbd(8)ûÓÐÕâÑùµÄÏÞÖÆ,µ«Èç¹ûÕâÑùµÄ¿Í»§½ØÈ¥²¿·Ö·þÎñÏîÃûµÄ»°,ËûÃǵÄÁ¬½Ó³¢ÊÔ»áʧ°Ü.Ϊ´ËÄã¿ÉÄÜÒª±£³ÖÄãµÄ·þÎñÏîÃûÔÚ8¸ö×Ö·ûÒÔÄÚ.

¶ÔÓÚ¹ÜÀíÔ±À´Ëµ[homes] ºÍ [printers]ÌØÊâ¶ÎµÄʹÓúÜÈÝÒ×,µ«¶ÔȱʡÊôÐԵĶàÑù×éºÏÓ¦¸ÃСÐÄ.µ±Éè¼ÆÕâЩ¶ÎʱҪÌرð×Ðϸ.ÌرðÊÇҪȷ±£¼ÙÍÑ»úĿ¼ȨÏÞµÄÕýÈ·ÐÔ.

°æ±¾ VERSION

´ËÊÖ²áÒ³ÊÇÕë¶ÔsambaÌ×¼þ°æ±¾3.0µÄ¡£