Setup guide

System (NFS), Microsoft Windows’ Server Message Block (SMB), and File Transfer
Protocol (FTP). Each of these protocols is appropriate for certain situations.
4.10.1 Disable File Sharing
File sharing services should be disabled unless it is necessary for the system to share
files stored on it. To disable file sharing services:
1. Open Workgroup Manager and connect to the server you’re configuring.
2. Click the Sharing icon and then click the Share Points tab (which will
contain Groups, Public, and Users by default).
3. For each Share Point listed, uncheck “Share this item and its contents” and
click Save.
4. Open Server Admin.
5. Click AFP under the Server you’re configuring.
6. Click on the Overview button and verify that the pane says “Apple File
Service is: Stopped”. If not, click Stop.
7. Click FTP under the Server you’re configuring.
8. Click on the Overview button and verify that the pane says “FTP Service is:
Stopped”. If not, click Stop.
9. Click NFS under the Server you’re configuring.
10. Click on the Overview button and verify that the pane says “NFS Service is:
Stopped.”
11. Click Windows under the Server you’re configuring.
12. Click on the Overview button and verify that the pane says “Windows
Service is: Stopped”. If not, click Stop.
4.10.2 Choosing a File Sharing Protocol
If the system is to act as a file server, then share points should be created and
configured using Workgroup Manager. Most installations will need only one file
sharing protocol, and as few protocols as possible should be used. Limiting the
number of protocols used by a system limits its exposure to vulnerabilities
discovered in those protocols. Deciding among AFP, SMB, NFS and FTP depends on
the client systems and networking needs.
AFP is the preferred method of file sharing for Macintosh or compatible client
systems. AFP supports authentication of clients, and also supports encrypted
network transport using SSH.
SMB is the native file sharing protocol for Microsoft Windows. It supports
authentication but does not support encrypted network transport. SMB may be an
appropriate protocol for Windows clients systems when the network between the
49
UNCLASSIFIED