<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Querry on HP Secure SSH in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454679#M536870</link>
    <description>will it allow me to use the new chroot functionality?&lt;BR /&gt;&lt;BR /&gt;Once the line sshd_config is change so the line Subsystem sftp /opt/ssh/libexec/sftp-server is replaced by Subsystem sftp internal-sfp and ChrootDirectory /opt/anonftp, can users that do not have /opt/anonftp as their home directory still use sftp and scp to the server?&lt;BR /&gt;&lt;BR /&gt;Please advice....</description>
    <pubDate>Tue, 07 Jul 2009 14:17:45 GMT</pubDate>
    <dc:creator>Vic006</dc:creator>
    <dc:date>2009-07-07T14:17:45Z</dc:date>
    <item>
      <title>Querry on HP Secure SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454677#M536868</link>
      <description>We are upgrading from version A.04.70.009.  When I installed the 5.20.004, the log contained the following messages.&lt;BR /&gt;&lt;BR /&gt;:    A new version of "/opt/ssh/etc/ssh_config" has been placed on&lt;BR /&gt;         the system. The new version is located at&lt;BR /&gt;         "/opt/ssh/newconfig/opt/ssh/etc/ssh_config".&lt;BR /&gt;&lt;BR /&gt;Do I need to move the new config files to /opt/ssh/etc and apply the configuration changes that were previously done?  Once I do this will it allow me to use the new chroot functionality described in section 1.9 part F(configuring SFTP) of the /opt/ssh/README.hp file. Once the line sshd_config is change so the line  Subsystem sftp /opt/ssh/libexec/sftp-server  is replaced by Subsystem sftp internal-sfp and ChrootDirectory /opt/anonftp, can users that do not have /opt/anonftp as their home directory still use sftp and scp to the server?&lt;BR /&gt;&lt;BR /&gt;Here is the Full log&lt;BR /&gt;&lt;BR /&gt;* Installing bundle "T1471AA,r=A.05.20.004" .&lt;BR /&gt;       * Installing fileset "Secure_Shell.SECURE_SHELL,r=A.05.20.004"&lt;BR /&gt;         (1 of 1).&lt;BR /&gt;NOTE:    A new version of "/etc/rc.config.d/sshd" has been installed on&lt;BR /&gt;         the system.&lt;BR /&gt;NOTE:    A new version of "/opt/ssh/etc/ssh_config" has been placed on&lt;BR /&gt;         the system. The new version is located at&lt;BR /&gt;         "/opt/ssh/newconfig/opt/ssh/etc/ssh_config".&lt;BR /&gt;         The existing version of "/opt/ssh/etc/ssh_config" is not being&lt;BR /&gt;         overwritten since it appears that it has been modified by the&lt;BR /&gt;         administrator since it was delivered.&lt;BR /&gt;NOTE:    A new version of "/opt/ssh/etc/sshd_config" has been placed on&lt;BR /&gt;         the system. The new version is located at&lt;BR /&gt;         "/opt/ssh/newconfig/opt/ssh/etc/sshd_config".&lt;BR /&gt;         The existing version of "/opt/ssh/etc/sshd_config" is not&lt;BR /&gt;         being overwritten since it appears that it has been modified&lt;BR /&gt;         by the administrator since it was delivered.&lt;BR /&gt;NOTE:    A new version of "/opt/ssh/etc/moduli" has been installed on&lt;BR /&gt;         the system.&lt;BR /&gt;       * Running install clean command /usr/lbin/sw/install_clean.&lt;BR /&gt;NOTE:    tlinstall is searching filesystem - please be patient&lt;BR /&gt;NOTE:    Successfully completed&lt;BR /&gt; &lt;BR /&gt;       * Beginning the Configure Execution Phase.&lt;BR /&gt; &lt;BR /&gt;       * Summary of Execution Phase:&lt;BR /&gt;       * 1 of 1 filesets had no Errors or Warnings.&lt;BR /&gt;       * The Execution Phase succeeded.&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Tue, 07 Jul 2009 13:18:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454677#M536868</guid>
      <dc:creator>Vic006</dc:creator>
      <dc:date>2009-07-07T13:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Querry on HP Secure SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454678#M536869</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;If you did customization, you may need to make those changes again.&lt;BR /&gt;&lt;BR /&gt;Not sure, but that is my interpretation of the message.&lt;BR /&gt;&lt;BR /&gt;Though Secure Shell install is pretty smart, and I've never had to make customization more than once.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 07 Jul 2009 13:20:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454678#M536869</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-07-07T13:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: Querry on HP Secure SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454679#M536870</link>
      <description>will it allow me to use the new chroot functionality?&lt;BR /&gt;&lt;BR /&gt;Once the line sshd_config is change so the line Subsystem sftp /opt/ssh/libexec/sftp-server is replaced by Subsystem sftp internal-sfp and ChrootDirectory /opt/anonftp, can users that do not have /opt/anonftp as their home directory still use sftp and scp to the server?&lt;BR /&gt;&lt;BR /&gt;Please advice....</description>
      <pubDate>Tue, 07 Jul 2009 14:17:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454679#M536870</guid>
      <dc:creator>Vic006</dc:creator>
      <dc:date>2009-07-07T14:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Querry on HP Secure SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454680#M536871</link>
      <description>Secure Shell ships with a chroot script.&lt;BR /&gt;&lt;BR /&gt;I find it to be a big hassle to configure, but it can be made to work.&lt;BR /&gt;&lt;BR /&gt;HP-UX Secure shell and chroot environments.&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/T1471-90026/ch01s14.html" target="_blank"&gt;http://docs.hp.com/en/T1471-90026/ch01s14.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 07 Jul 2009 14:22:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454680#M536871</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-07-07T14:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: Querry on HP Secure SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454681#M536872</link>
      <description>You can do configuration changes on your newly installed configuration file and add it to PATH variable. It should work most of the cases. If it not worked then you need move these new configuration files to old location.&lt;BR /&gt;Thanks&lt;BR /&gt;</description>
      <pubDate>Wed, 08 Jul 2009 02:19:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454681#M536872</guid>
      <dc:creator>Roopesh Francis_1</dc:creator>
      <dc:date>2009-07-08T02:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Querry on HP Secure SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454682#M536873</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;As far as config files are concerned u can use&lt;BR /&gt;command line option -f &lt;CONFIG_FILE_PATH&gt; while&lt;BR /&gt;starting sshd. Also if it is starting automatically&lt;BR /&gt;u can pass parameter "-f &lt;CONFIG_FILE_PATH&gt;" to&lt;BR /&gt;&lt;BR /&gt;SSHD_ARGS variable in file /etc/rc.config.d/sshd.&lt;BR /&gt;&lt;BR /&gt;The default location is /opt/ssh/etc/sshd_config&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;-Santosh&lt;BR /&gt;&lt;/CONFIG_FILE_PATH&gt;&lt;/CONFIG_FILE_PATH&gt;</description>
      <pubDate>Wed, 08 Jul 2009 05:05:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454682#M536873</guid>
      <dc:creator>SANTOSH S. MHASKAR</dc:creator>
      <dc:date>2009-07-08T05:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Querry on HP Secure SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454683#M536874</link>
      <description>Well i still get a precise answer for this..&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;1) When I installed the new version of secure SSH it put the new versions of the ssh_config and sshd_config into the directory /opt/ssh/newconfig/opt/ssh/etc/ instead of into /opt/ssh/etc.  Am I suppose to apply the changes made previously to these files and leave them in /opt/ssh/newconfig/opt/ssh/etc or do I need to copy them to /opt/ssh/etc before I restart  sshd. The logfiles produced from the install of the software does not specify.&lt;BR /&gt; &lt;BR /&gt;2) Do not want to run the use  /opt/ssh/utils/ssh_chroot_setup.sh to create a chrooted environment. It is too messy and is an adminstration nightmare as it copies in a bunch of system files that need to be updated into the environment.  Was hoping to use the new functionality specified in section 1.9 part F(configuring SFTP) of the /opt/ssh/README.hp file to jail the user.  Need to know whether implementing this only allows the chrooted users to use sftp.&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Wed, 08 Jul 2009 12:53:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454683#M536874</guid>
      <dc:creator>Vic006</dc:creator>
      <dc:date>2009-07-08T12:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Querry on HP Secure SSH</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454684#M536875</link>
      <description>Hey;&lt;BR /&gt;&lt;BR /&gt;1.  If you want to use the new configuration files, then you should move them into /opt/ssh/etc and update them for your environment.  As previous posters have pointed out, you don't absolutely have to do this, but if you don't, you'll also be editing init scripts to tell sshd where to find the configuration file.&lt;BR /&gt;&lt;BR /&gt;2.  Don't know the answer to this one; you'll have to experiment.  I do know that locking users down to scp/sftp only in ssh tends to be a mite difficult.  I know of a way using forced commands and ssh/public key authentication but tends to be a bit kludgey.  Even then, I'm not sure of sftp.  You can either google search or post another question if your experiments don't show you a valid method.&lt;BR /&gt;&lt;BR /&gt;Doug O'Leary</description>
      <pubDate>Wed, 08 Jul 2009 13:22:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/querry-on-hp-secure-ssh/m-p/4454684#M536875</guid>
      <dc:creator>Doug O'Leary</dc:creator>
      <dc:date>2009-07-08T13:22:03Z</dc:date>
    </item>
  </channel>
</rss>

