Updated: 28 September 2026 · Applies to: rsync 3.2 to 3.5 on AlmaLinux and Rocky Linux 9 and 10, RHEL 9 and 10, Ubuntu 24.04 and 26.04, Debian 13

rsync normally copies files over SSH, which needs an SSH login on the target. In daemon mode, rsync runs as its own service on TCP port 873 and offers named folders ("modules"), with their own user names and passwords that do not give shell access. This suits backup targets and file distribution. We tested the setup below on AlmaLinux 9 with rsync 3.2.7.

Security note: the rsync protocol is not encrypted. Use daemon mode on a private network or VPN, and allow port 873 only from your own addresses. Over the internet, rsync over SSH is the safer choice.

1. Install the daemon

dnf install rsync rsync-daemon     # AlmaLinux, Rocky Linux, RHEL (service: rsyncd)
apt install rsync                  # Ubuntu, Debian (service: rsync)

2. Configure a module

Create /etc/rsyncd.conf:

uid = nobody
gid = nobody
use chroot = yes
max connections = 4
log file = /var/log/rsyncd.log

[backups]
    path = /srv/backups
    comment = Backup area
    read only = no
    auth users = backupuser
    secrets file = /etc/rsyncd.secrets
    hosts allow = 198.51.100.7

On Ubuntu and Debian, use gid = nogroup. uid and gid are the local account the daemon writes files as; hosts allow limits which clients may connect.

3. Create the password file and the folder

echo "backupuser:ChooseAStrongPassword" > /etc/rsyncd.secrets
chmod 600 /etc/rsyncd.secrets
mkdir -p /srv/backups
chown nobody:nobody /srv/backups

The user name here is only for rsync; it does not need to exist as a Linux account. rsync refuses a secrets file that others can read.

4. Start it and open the firewall

systemctl enable --now rsyncd      # AlmaLinux, Rocky Linux, RHEL
systemctl enable --now rsync       # Ubuntu, Debian
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="198.51.100.7" port port="873" protocol="tcp" accept'
firewall-cmd --reload

On AlmaLinux, Rocky Linux and RHEL, allow the daemon to write outside its default locations: setsebool -P rsync_full_access on.

5. Use it from a client

echo "ChooseAStrongPassword" > $HOME/.rsync-pass && chmod 600 $HOME/.rsync-pass
rsync -av --password-file=$HOME/.rsync-pass /var/www/ rsync://backupuser@203.0.113.10/backups/www/
rsync --password-file=$HOME/.rsync-pass rsync://backupuser@203.0.113.10/     # list modules

Note the rsync:// address (or host::module): with a single colon, rsync uses SSH instead of the daemon.

Common problems

  • "@ERROR: auth failed on module backups": wrong user or password, or the secrets file is readable by others.
  • "@ERROR: access denied": the client address is not in hosts allow.
  • "Permission denied" when writing: the module folder does not belong to the uid user, or SELinux blocks it (step 4).

Official documentation: rsyncd.conf manual.

Ucartz services for this topic

Was this answer helpful? 0 Users Found This Useful (0 Votes)