smb.update¶
Update the SMB service configuration.
The group specified as the SMB admin_group is automatically added as a foreign group member of S-1-5-32-544 (the builtin administrators group), affording the group all privileges granted to a local administrator. Any SMB group may be selected, including Active Directory groups.
Mandatory SMB encryption (encryption set to REQUIRED) is not compatible with SMB1 server support.
Note
workgroup and netbiosname must have different values.
Important
smb_options are raw smb.conf parameters that are not covered by the supported configuration
options. Not all options are tested or supported, and their behavior may change between releases.
Stability of smb.conf options is not guaranteed.
No Additional Items
Tuple Validation
Parameter 1: smb_update
smb_update
Type: objectSMBUpdateArgs parameters.
No Additional PropertiesNetbiosname
Type: stringNetbios name of this server
Netbiosalias
Type: array of stringAlternative netbios names of the server that will be announced via netbios nameserver and registered in active directory when joined.
No Additional ItemsEach item of this array must be:
Workgroup
Type: stringWorkgroup. When joined to active directory, this will be automatically reconfigured to match the netbios domain of the AD domain.
Description
Type: stringDescription of SMB server. May appear to clients during some operations.
Enable Smb1
Type: booleanEnable SMB1 support for server. WARNING: using SMB1 protocol is not recommended
Unixcharset
Type: enum (of string)Select characterset for file names on local filesystem. This should only be used in cases where system administrator knows that the filenames are not UTF-8.
Must be one of:
- "UTF-8"
- "GB2312"
- "HZ-GB-2312"
- "CP1361"
- "BIG5"
- "BIG5HKSCS"
- "CP037"
- "CP273"
- "CP424"
- "CP437"
- "CP500"
- "CP775"
- "CP850"
- "CP852"
- "CP855"
- "CP857"
- "CP858"
- "CP860"
- "CP861"
- "CP862"
- "CP863"
- "CP864"
- "CP865"
- "CP866"
- "CP869"
- "CP932"
- "CP949"
- "CP950"
- "CP1026"
- "CP1125"
- "CP1140"
- "CP1250"
- "CP1251"
- "CP1252"
- "CP1253"
- "CP1254"
- "CP1255"
- "CP1256"
- "CP1257"
- "CP1258"
- "EUC_JIS_2004"
- "EUC_JISX0213"
- "EUC_JP"
- "EUC_KR"
- "GB18030"
- "GBK"
- "HZ"
- "ISO2022_JP"
- "ISO2022_JP_1"
- "ISO2022_JP_2"
- "ISO2022_JP_2004"
- "ISO2022_JP_3"
- "ISO2022_JP_EXT"
- "ISO2022_KR"
- "ISO8859_1"
- "ISO8859_2"
- "ISO8859_3"
- "ISO8859_4"
- "ISO8859_5"
- "ISO8859_6"
- "ISO8859_7"
- "ISO8859_8"
- "ISO8859_9"
- "ISO8859_10"
- "ISO8859_11"
- "ISO8859_13"
- "ISO8859_14"
- "ISO8859_15"
- "ISO8859_16"
- "JOHAB"
- "KOI8_R"
- "KZ1048"
- "LATIN_1"
- "MAC_CYRILLIC"
- "MAC_GREEK"
- "MAC_ICELAND"
- "MAC_LATIN2"
- "MAC_ROMAN"
- "MAC_TURKISH"
- "PTCP154"
- "SHIFT_JIS"
- "SHIFT_JIS_2004"
- "SHIFT_JISX0213"
- "TIS_620"
- "UTF_16"
- "UTF_16_BE"
- "UTF_16_LE"
Localmaster
Type: booleanSyslog
Type: booleanSend log messages to syslog. This should be enabled if system administrator wishes for SMB server error logs to be included in information sent to remote syslog server if this is globally configured for TrueNAS.
Aapl Extensions
Type: booleanEnable support for SMB2/3 AAPL protocol extensions. This changes the TrueNAS server so that it is advertised as supporting Apple protocol extensions as a MacOS server, and is required for Time Machine support.
Admin Group
The selected group will have full administrator privileges on TrueNAS over SMB protocol.
Guest
Type: stringMust be at least 1 characters long
Filemask
smb.conf create mask. DEFAULT applies current server default which is 664.
Specific value:
"DEFAULT"
Dirmask
smb.conf directory mask. DEFAULT applies current server default which is 775.
Specific value:
"DEFAULT"
Ntlmv1 Auth
Type: booleanEnable legacy and very insecure NTLMv1 authentication. This should never be done except in extreme edge cases and may be against regulations in non-home environments.
Multichannel
Type: booleanEncryption
Type: enum (of string)Must be one of:
- "DEFAULT"
- "NEGOTIATE"
- "DESIRED"
- "REQUIRED"
Bindip
Type: array of stringNo Additional Items
Each item of this array must be:
Server Sid
Universally-unique identifier for this particular SMB server that serves as domain SID for all local SMB user and group accounts
Smb Options
Type: stringAdditional unvalidated and unsupported configuration options for the SMB server. WARNING: using smb_options may produce unexpected server behavior.
Debug
Type: booleanSet SMB log levels to debug. This should only be used when troubleshooting a specific SMB issue and should not be used in production environments.
SMBEntry
Type: objectNo Additional Properties
Id
Type: integerNetbiosname
Type: stringNetbios name of this server
Netbiosalias
Type: array of stringAlternative netbios names of the server that will be announced via netbios nameserver and registered in active directory when joined.
No Additional ItemsEach item of this array must be:
Workgroup
Type: stringWorkgroup. When joined to active directory, this will be automatically reconfigured to match the netbios domain of the AD domain.
Description
Type: stringDescription of SMB server. May appear to clients during some operations.
Enable Smb1
Type: booleanEnable SMB1 support for server. WARNING: using SMB1 protocol is not recommended
Unixcharset
Type: enum (of string)Select characterset for file names on local filesystem. This should only be used in cases where system administrator knows that the filenames are not UTF-8.
Must be one of:
- "UTF-8"
- "GB2312"
- "HZ-GB-2312"
- "CP1361"
- "BIG5"
- "BIG5HKSCS"
- "CP037"
- "CP273"
- "CP424"
- "CP437"
- "CP500"
- "CP775"
- "CP850"
- "CP852"
- "CP855"
- "CP857"
- "CP858"
- "CP860"
- "CP861"
- "CP862"
- "CP863"
- "CP864"
- "CP865"
- "CP866"
- "CP869"
- "CP932"
- "CP949"
- "CP950"
- "CP1026"
- "CP1125"
- "CP1140"
- "CP1250"
- "CP1251"
- "CP1252"
- "CP1253"
- "CP1254"
- "CP1255"
- "CP1256"
- "CP1257"
- "CP1258"
- "EUC_JIS_2004"
- "EUC_JISX0213"
- "EUC_JP"
- "EUC_KR"
- "GB18030"
- "GBK"
- "HZ"
- "ISO2022_JP"
- "ISO2022_JP_1"
- "ISO2022_JP_2"
- "ISO2022_JP_2004"
- "ISO2022_JP_3"
- "ISO2022_JP_EXT"
- "ISO2022_KR"
- "ISO8859_1"
- "ISO8859_2"
- "ISO8859_3"
- "ISO8859_4"
- "ISO8859_5"
- "ISO8859_6"
- "ISO8859_7"
- "ISO8859_8"
- "ISO8859_9"
- "ISO8859_10"
- "ISO8859_11"
- "ISO8859_13"
- "ISO8859_14"
- "ISO8859_15"
- "ISO8859_16"
- "JOHAB"
- "KOI8_R"
- "KZ1048"
- "LATIN_1"
- "MAC_CYRILLIC"
- "MAC_GREEK"
- "MAC_ICELAND"
- "MAC_LATIN2"
- "MAC_ROMAN"
- "MAC_TURKISH"
- "PTCP154"
- "SHIFT_JIS"
- "SHIFT_JIS_2004"
- "SHIFT_JISX0213"
- "TIS_620"
- "UTF_16"
- "UTF_16_BE"
- "UTF_16_LE"
Localmaster
Type: booleanSyslog
Type: booleanSend log messages to syslog. This should be enabled if system administrator wishes for SMB server error logs to be included in information sent to remote syslog server if this is globally configured for TrueNAS.
Aapl Extensions
Type: booleanEnable support for SMB2/3 AAPL protocol extensions. This changes the TrueNAS server so that it is advertised as supporting Apple protocol extensions as a MacOS server, and is required for Time Machine support.
Admin Group
The selected group will have full administrator privileges on TrueNAS over SMB protocol.
Guest
Type: stringMust be at least 1 characters long
Filemask
smb.conf create mask. DEFAULT applies current server default which is 664.
Specific value:
"DEFAULT"
Dirmask
smb.conf directory mask. DEFAULT applies current server default which is 775.
Specific value:
"DEFAULT"
Ntlmv1 Auth
Type: booleanEnable legacy and very insecure NTLMv1 authentication. This should never be done except in extreme edge cases and may be against regulations in non-home environments.
Multichannel
Type: booleanEncryption
Type: enum (of string)Must be one of:
- "DEFAULT"
- "NEGOTIATE"
- "DESIRED"
- "REQUIRED"
Bindip
Type: array of stringNo Additional Items
Each item of this array must be:
Server Sid
Universally-unique identifier for this particular SMB server that serves as domain SID for all local SMB user and group accounts
Smb Options
Type: stringAdditional unvalidated and unsupported configuration options for the SMB server. WARNING: using smb_options may produce unexpected server behavior.
Debug
Type: booleanSet SMB log levels to debug. This should only be used when troubleshooting a specific SMB issue and should not be used in production environments.
Required roles: SHARING_SMB_WRITE