Updated: 28 September 2026 · Applies to: rsync 3.2 to 3.5 on AlmaLinux and Rocky Linux 9 and 10, RHEL 9 and 10, Ubuntu 24.04 and 26.04, Debian 13
rsync normally copies files over SSH, which needs an SSH login on the target. In daemon mode, rsync runs as its own service on TCP port 873 and offers named folders ("modules"), with their own user names and passwords that do not give shell access. This suits backup targets and file distribution. We tested the setup below on AlmaLinux 9 with rsync 3.2.7.
Security note: the rsync protocol is not encrypted. Use daemon mode on a private network or VPN, and allow port 873 only from your own addresses. Over the internet, rsync over SSH is the safer choice.
1. Install the daemon
dnf install rsync rsync-daemon # AlmaLinux, Rocky Linux, RHEL (service: rsyncd) apt install rsync # Ubuntu, Debian (service: rsync)
2. Configure a module
Create /etc/rsyncd.conf:
uid = nobody
gid = nobody
use chroot = yes
max connections = 4
log file = /var/log/rsyncd.log
[backups]
path = /srv/backups
comment = Backup area
read only = no
auth users = backupuser
secrets file = /etc/rsyncd.secrets
hosts allow = 198.51.100.7
On Ubuntu and Debian, use gid = nogroup. uid and gid are the local account the daemon writes files as; hosts allow limits which clients may connect.
3. Create the password file and the folder
echo "backupuser:ChooseAStrongPassword" > /etc/rsyncd.secrets chmod 600 /etc/rsyncd.secrets mkdir -p /srv/backups chown nobody:nobody /srv/backups
The user name here is only for rsync; it does not need to exist as a Linux account. rsync refuses a secrets file that others can read.
4. Start it and open the firewall
systemctl enable --now rsyncd # AlmaLinux, Rocky Linux, RHEL systemctl enable --now rsync # Ubuntu, Debian firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.7" port port="873" protocol="tcp" accept' firewall-cmd --reload
On AlmaLinux, Rocky Linux and RHEL, allow the daemon to write outside its default locations: setsebool -P rsync_full_access on.
5. Use it from a client
echo "ChooseAStrongPassword" > $HOME/.rsync-pass && chmod 600 $HOME/.rsync-pass rsync -av --password-file=$HOME/.rsync-pass /var/www/ rsync://backupuser@203.0.113.10/backups/www/ rsync --password-file=$HOME/.rsync-pass rsync://backupuser@203.0.113.10/ # list modules
Note the rsync:// address (or host::module): with a single colon, rsync uses SSH instead of the daemon.
Common problems
- "@ERROR: auth failed on module backups": wrong user or password, or the secrets file is readable by others.
- "@ERROR: access denied": the client address is not in
hosts allow. - "Permission denied" when writing: the module folder does not belong to the
uiduser, or SELinux blocks it (step 4).
Official documentation: rsyncd.conf manual.
Ucartz services for this topic
- KVM VPS hosting: NVMe SSD and full root access, with Free Basic Managed Support.
- Unmanaged dedicated servers: full root access and free IPMI KVM, with Free Basic Managed Support.
- Linux server management: hardening, patching, monitoring and automation for Ubuntu, Debian, RHEL and AlmaLinux.
