[Samba] Encryption of shares

Jeremy Allison jra at samba.org
Mon Nov 14 17:33:41 UTC 2022


On Mon, Nov 14, 2022 at 01:44:48PM +0100, lists--- via samba wrote:
>Am 11.11.2022 um 15:08 schrieb Andrea Venturoli via samba:
>>On 11/11/22 08:03, lists--- via samba wrote:
>>>Good morning list,
>>
>>Hello.
>>
>>>does anybody uses a [homes], and maybe [profiles], encrytion?
>>
>>Yes.
>>
>>>Some users asked me yesterday if that could be done in any, for 
>>>the users easy, way ..
>>
>>This is transparent to users.
>>
>>>The related system runs Debian Bullseye and samba version 
>>>4.15.7-Debian, and acts as an AD member-server - and several 
>>>[homes]-folders are filled with lots of data.
>>
>>I'm doing it in FreeBSD (either with ZFS encrypted datasets or 
>>GELI), so my solutions won't apply to you.
>>
>>This is really not a Samba question: it's the underlying OS that 
>>provides encrypted filesystem; Samba doesn't even know.
>
>Yes, I know its not a feature of samba itself ;)
>But its a samba-ml, and so my thought was that there might be someone 
>else where such a question raised, too ... and found a nice way to do 
>it.
>
>Doing a new installation is possible, but takes time and ressources.

I successfully use ecrytfs to provide disk encryption for
some private data. You'll need to provide a key on boot
somehow, but they should export normally over Samba.

https://ostechnix.com/how-to-encrypt-directories-with-ecryptfs-in-linux/



More information about the samba mailing list