Fedora Linux Support Community & Resources Center
  #1  
Old 31st January 2009, 02:38 PM
mtant621 Offline
Registered User
 
Join Date: Jun 2008
Posts: 12
Cool SSH Server Help Needed

Hi all. I'm working on setting up a ssh server that will be restricted availability. I have decided to run the server as follows:

Configure the sshd_config file for the standard users (AllowUsers will be used to explicitly declared for users and will exclude the sudo user.) I want this to be configured to a ChrootDirectory. Within the chroot directory these users will only have either rssh or scponly shell (as they will be running either WinSCP or SftpDrive to access) and will not need nor be allowed command access. DSA key Authentication with password set to no. X forwarding, gateways, etc no. It will function purely as a central remote file storage. At the end I will use either Match Host or Match Address to accomodate the sudo. This will restrict the address for the sudo user. Under this match clause it will have no chrootdirectory, and other options specific to the sudo user. This will be in place to allow for a separation of the userspace from the / dir. Other security which is not relevant to this question will be in place, such as iptables, hosts.*, denyhosts, firewall, selinux, etc.

The main area I am having much difficulty with is how to establish the chroot directory. I will wish this directory to reside within its own partition preferredly on the secondary drive. I will allocate enough space and enable quotas to help in management of the disk usage. However, reading the man page tells me that I will have to move any files required for the users into the chroot directory. This is where the help is needed.

I have the partition allocated, but don't have any directory structures setup or files allocated. The mount point will likely be a directory off of / somewhere for the partition. Within that mount point is where I want the chroot to reside. (the partition is currently mounted at /chsshrd)

Can someone please help me to establish the necessary directory structure and files? I know I wish to have a private directory for each user (permissions set to the user only) with the ability for them to add / remove directories within their private directory. I also wish to have a shared common directory (Public) with the ability to add remove directories (sticky bit though so only the owner can edit or remove their own content.) Permissions here also will be set to the public directory and each recursive directory and file from that should inherit permissions from the Public parent. These should reflect *rw-r--r-t (no executables or binaries should exist within the chroot accessible to users.)

I know this seems kinda vague on the intended setup, but the ultimate goal is to have a separation of the standard users form the core system, and to restrict the available access location of the sudo user, because sudo will not be in the chroot. Can this be done? If so, what files/structures should exist within /chsshrd?

I appreciate any help I can get with this. I've considered the other options such as dual sshd's running or a vm, but weighing the work necessary against security needed I feel that the level of security that will exist is adequate to meet the risk assessment. I feel this option should provide the separation I need. Again, other measure will be in place ahead of this server that will assist in protecting it from attack. It's not foolproof or even fancy, but it meets the needs I have.

Thanks so much for helping me with this, and with the learning process in general!!!
Reply With Quote
Reply

Tags
needed, server, ssh

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
help needed with dhcp3-server petee1979 Servers & Networking 0 12th March 2009 09:38 AM
ms server setup help needed panamszr12 Using Fedora 0 27th October 2005 04:23 PM
Server Crashed Help Needed ***Badly**** gdkulkar Using Fedora 1 19th October 2005 11:36 PM


Current GMT-time: 07:28 (Wednesday, 19-06-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat