The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Show Samba versionsmbd --versionView examples
Validate configurationtestparm --suppress-prompt /etc/samba/smb.confView examples
Inspect one sharetestparm --suppress-prompt --section-name projects \ /etc/samba/smb.confView examples
List configured servicestestparm --suppress-prompt --show-all-parameters \ /etc/samba/smb.confView examples
List server sharessmbclient --list=files1.example.net --user=aliceView examples
Open an SMB clientsmbclient //files1.example.net/projects --user=aliceView examples
Connect with Kerberossmbclient //files1.example.net/projects \ --use-kerberos=required --no-passView examples
Show active sessionssudo smbstatus --sharesView examples
Show locked filessudo smbstatus --locksView examples
Reload configurationsudo smbcontrol all reload-configView examples
Add a Samba passwordsudo smbpasswd -a aliceView examples
Disable a Samba accountsudo smbpasswd -d aliceView examples
Enable a Samba accountsudo smbpasswd -e aliceView examples
Read a share ACLsmbcacls //files1.example.net/projects / --user=aliceView examples
Read filesystem ACLsgetfacl --absolute-names /srv/samba/projectsView examples
Show protocol boundstestparm --suppress-prompt \ --parameter-name='server min protocol' \ /etc/samba/smb.confView examples
Show signing policytestparm --suppress-prompt \ --parameter-name='server signing' /etc/samba/smb.confView examples
Inspect SMB listenersss -ltnp 'sport = :445'View examples
Read smbd logsjournalctl -u smb.service -u smbd.service --since today \ --no-pagerView examples
Mount an SMB sharesudo mount -t cifs //files1.example.net/projects \ /mnt/projects -o \ credentials=/root/.smb-projects,vers=3.1.1View examples

Samba maps SMB identities and access checks onto Linux filesystems, so a successful connection can still fail at share, ACL, mode-bit, SELinux, or filesystem boundaries. Treat smb.conf as security policy, reject SMB1 unless a documented legacy exception requires it, never put passwords on command lines, and test changes with a non-administrative account before exposing TCP 445 beyond a trusted network.

Step by step

Detailed examples

01

Identify role, version, services, and listeners

A standalone file server, domain member, and Active Directory domain controller run different daemon combinations and identity paths. Record the packaged version and security support, active units, configured shares, and bound addresses before editing. Never expose SMB directly to the public Internet.

Capture service inventory
smbd --version
testparm --suppress-prompt /etc/samba/smb.conf
systemctl status smb.service smbd.service nmb.service winbind.service --no-pager
ss -ltnp 'sport = :445'
Back to quick reference ↑
02

Validate effective configuration, not merely syntax

testparm catches parsing errors and shows defaults but cannot prove a path exists, storage is writable, identities resolve, ACLs work, or firewall and SELinux policy permit access. Includes and registry shares can alter effective configuration. Build a candidate file, compare its normalized output, and retain a known-good rollback.

Review a candidate safely
testparm --suppress-prompt /etc/samba/smb.conf
testparm --suppress-prompt --section-name projects /etc/samba/smb.conf
# Validate a staged candidate without installing it:
# testparm --suppress-prompt /root/change/smb.conf.candidate
Back to quick reference ↑
03

Test authentication and authorization as a real user

Administrative credentials can hide broken ordinary-user access. smbclient prompts securely by default; avoid -U user%password because process lists and histories can expose the secret. Kerberos tests require correct DNS, time, SPNs, and tickets. Test list, read, create, rename, and delete only in an approved scratch path.

Perform read-only client checks
smbclient --list=files1.example.net --user=alice
klist
smbclient //files1.example.net/projects --use-kerberos=required --no-pass --command='ls'
Back to quick reference ↑
04

Protect active clients and file locks

Reloading generally does not retrofit every setting onto existing connections, while restart disconnects users. Locks may protect databases and office documents; killing sessions or removing lock state can corrupt data. Inventory sessions, open files, durable handles, and maintenance owners before disruptive work.

Review current usage
sudo smbstatus --shares
sudo smbstatus --locks
sudo smbstatus --processes
# Coordinate with application owners before terminating any session.
Back to quick reference ↑
05

Reload only after validation and rollback preparation

smbcontrol reload-config asks running daemons to reread configuration, but existing clients can keep old settings until reconnect. Some global changes require restart, which is an outage. Validate the exact installed file, reload, re-run testparm, inspect logs, and test a new client connection before closing the change window.

Review a reload sequence
testparm --suppress-prompt /etc/samba/smb.conf
# sudo smbcontrol all reload-config
# testparm --suppress-prompt /etc/samba/smb.conf
# journalctl -u smb.service -u smbd.service --since '-5 minutes' --no-pager
Back to quick reference ↑
06

Separate Unix accounts from Samba credentials

In local passdb deployments, smbpasswd -a expects an existing Unix account and creates separate SMB credential material. Domain-member deployments normally use directory identities instead. Disable before deletion when preserving ownership history, use strong passwords, and never share accounts or synchronize secrets through scripts.

Audit identity before enrollment
getent passwd alice
sudo pdbedit --list --verbose alice
# Passdb-only workflow, prompts securely:
# sudo smbpasswd -a alice
# sudo smbpasswd -d alice
Back to quick reference ↑
07

Reconcile share policy with filesystem and security labels

Access is the intersection of share parameters, authentication, valid users, Windows ACLs, POSIX ACLs and modes, parent-directory traversal, filesystem features, and MAC policy such as SELinux. Broad chmod 777 masks design errors and creates exposure. Decide whether ACLs are managed from Windows or Unix and preserve required xattrs during backup.

Inspect all permission layers
testparm --suppress-prompt --section-name projects /etc/samba/smb.conf
namei -l /srv/samba/projects
getfacl --absolute-names /srv/samba/projects
ls -ldZ /srv/samba/projects
smbcacls //files1.example.net/projects / --user=alice
Back to quick reference ↑
08

Set protocol and cryptographic policy intentionally

Disable SMB1 unless an isolated, time-bounded legacy exception is unavoidable. Signing protects integrity; encryption protects confidentiality but costs resources and must be negotiated by clients. Guest access, wide hosts allow rules, symlink-following behavior, and writable shares expand risk. Validate current-version defaults rather than copying old smb.conf advice.

Audit security-relevant parameters
testparm --suppress-prompt --parameter-name='server min protocol' /etc/samba/smb.conf
testparm --suppress-prompt --parameter-name='server signing' /etc/samba/smb.conf
testparm --suppress-prompt --parameter-name='smb encrypt' /etc/samba/smb.conf
testparm --suppress-prompt --parameter-name='map to guest' /etc/samba/smb.conf
Back to quick reference ↑
09

Mount SMB without placing secrets in fstab

Use a root-owned mode-0600 credentials file or Kerberos rather than inline username and password options. Explicit dialect selection can prevent downgrade but must match the server. CIFS mounts can hang workloads during outages; test ownership mapping, permissions, cache semantics, reconnect behavior, and unmount recovery before production.

Review a protected client mount
# /root/.smb-projects must be root-owned mode 0600 and contain username/domain secrets.
# sudo mount -t cifs //files1.example.net/projects /mnt/projects -o credentials=/root/.smb-projects,vers=3.1.1
# findmnt --target /mnt/projects
Back to quick reference ↑
10

Diagnose negotiation, identity, permissions, and transport separately

A refused connection differs from failed dialect negotiation, bad credentials, denied share policy, and backing-filesystem denial. Capture bounded logs and client debug output, but sanitize usernames, addresses, share names, and tokens. Raising global log level indefinitely can expose sensitive metadata and exhaust storage.

Collect bounded server evidence
testparm --suppress-prompt /etc/samba/smb.conf
ss -ltnp 'sport = :445'
sudo smbstatus --shares
journalctl -u smb.service -u smbd.service --since '-15 minutes' --no-pager
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Samba Projectsmb.conf(5) Manualsamba.org
  2. Samba Projecttestparm(1) Manualsamba.org
  3. Samba Projectsmbclient(1) Manualsamba.org
  4. Samba Projectsmbstatus(1) Manualsamba.org
  5. Samba Projectsmbcontrol(1) Manualsamba.org
  6. Linux CIFS Utilities Projectmount.cifs(8) Manualman7.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback