Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 2nd November 2006, 11:06 PM
fusi0n Offline
Registered User
 
Join Date: Jul 2005
Posts: 7
chroot accounts with sftp access

Hi,

I have search high and low and I have not been able to find a solution tha works for me so I thought I would try you guys

I have a web server running FC4 and vsftpd with all the updates done. I want to be able to lock users with sftp access in there home dirs. So far I am only able to do this with ftp and it works like a charm. Although when I allow the users sftp access they are able to browse right up to the root folder. Also, is there a way to allow sftp without allowin ssh into the box for that account?

Thanks in advance for any help, And I apologize if I missed a post somewhere on this but I have come up empty handed over the last few days of playing with this and trying to get it to work.
Reply With Quote
  #2  
Old 3rd November 2006, 12:32 AM
jhetrick62 Offline
Registered User
 
Join Date: Feb 2005
Location: Buffalo, Ny
Posts: 875
Sftp by definition is:


DESCRIPTION

sftp is an interactive file transfer program, similar to ftp, which performs all operations over an encrypted ssh(1) transport. It may also use many features of ssh, such as public key authentication and compres- sion. sftp connects and logs into the specified host, then enters an interactive command mode.

So, no it won't work without ssh accesss which by it's very nature is meant to allow a user to use the box as if they were sitting there, but through a completely encrytped tunnel. Sftp allows them to transfer files inside of the tunnel thus their passwords never get passed in an un-encrytped state and all information is transferred in the encrypted mode.

Why would you want to allow a standard user that access?

Jeff
__________________
Registered Linux User #411071

If at first you don't suceed, read the man page again!
Reply With Quote
  #3  
Old 3rd November 2006, 01:05 AM
fusi0n Offline
Registered User
 
Join Date: Jul 2005
Posts: 7
fair enough. I was aware of this but just wanted to see if there was a way around it. I want to allow this access as there is only one person who connects to this server besides me (the admin) the other is the webmaster (user in question) He is transfering files that are generated by a piece of software and it produces around 2000 files for updates to a certain section of the website. Everytime he tries to update this using plain ftp it hangs and various other problems. This does not happen at all with sftp so I felt it is a solution to get the webmaster off my case. Now, the question remains, how to I stop him from getting out of his home directory and browsing the rest of the server with sftp? I only want him to ssh and sftp into his home directory which is where all the websites are... he tends to play and causes me grief so if he can only look and mess with his files it will save me many headaches.
Reply With Quote
  #4  
Old 10th November 2006, 02:03 AM
pdb Offline
Registered User
 
Join Date: May 2004
Posts: 269
Never used it, but found this:
http://chrootssh.sourceforge.net

Looks like what you are wanting to do
__________________
http://pdb.homelinux.net
Registered Linux User # 348314
Reply With Quote
Reply

Tags
access, accounts, chroot, sftp

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Simple user config question (Doing chroot with SFTP) DeckMechanic Using Fedora 3 14th April 2009 04:28 PM
FTP, SFTP, Chroot assproductions Servers & Networking 15 28th September 2008 11:35 PM
Can't access F7 box with sftp or scp pobbz Servers & Networking 0 19th October 2007 10:27 AM
SSH SFTP User access johnk Servers & Networking 3 3rd October 2005 04:43 AM
unable to access internet from non-root accounts hari_mj23 Using Fedora 1 18th June 2005 01:49 PM


Current GMT-time: 20:50 (Tuesday, 18-06-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat