<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure ftp in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845055#M91997</link>
    <description>Nope - HELP !</description>
    <pubDate>Fri, 15 Nov 2002 12:38:04 GMT</pubDate>
    <dc:creator>Andy Macleod</dc:creator>
    <dc:date>2002-11-15T12:38:04Z</dc:date>
    <item>
      <title>Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845043#M91985</link>
      <description>One of the items in my roll out of a secure ftp solution is to insert /./ (chroot) into the path of a ftp users home directory.&lt;BR /&gt;&lt;BR /&gt;but when I ftp in using this user's id and do the pwd comand I can still see the full path.&lt;BR /&gt;&lt;BR /&gt;Can anyone think why this is ?</description>
      <pubDate>Thu, 14 Nov 2002 16:00:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845043#M91985</guid>
      <dc:creator>Andy Macleod</dc:creator>
      <dc:date>2002-11-14T16:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845044#M91986</link>
      <description>Are you using ftpaccess?&lt;BR /&gt;&lt;BR /&gt;Look at this:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0xa9635c7609e9d61190050090279cd0f9,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0xa9635c7609e9d61190050090279cd0f9,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this helps&lt;BR /&gt;&lt;BR /&gt;Chris</description>
      <pubDate>Thu, 14 Nov 2002 16:06:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845044#M91986</guid>
      <dc:creator>Christopher McCray_1</dc:creator>
      <dc:date>2002-11-14T16:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845045#M91987</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;What does the entire entry in the passwd file say?&lt;BR /&gt;&lt;BR /&gt;Do you have something like /usr/bin/false for the users default shell?&lt;BR /&gt;&lt;BR /&gt;Chris</description>
      <pubDate>Thu, 14 Nov 2002 16:06:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845045#M91987</guid>
      <dc:creator>Christopher McCray_1</dc:creator>
      <dc:date>2002-11-14T16:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845046#M91988</link>
      <description>I think I've sorted it.&lt;BR /&gt;I've set up a new group and a new shell called ftpshell.&lt;BR /&gt;&lt;BR /&gt;The shell contains exit 0, then I've copied the ftpaccess file to /etc/ftpd/ and editied it so the ftponly group is the secureftp group.&lt;BR /&gt;then i've sorted all the permissions and ownership.&lt;BR /&gt;&lt;BR /&gt;I then created a file /etc/shells and listed all the shells inculding the new ftpshell, cp'd the ls cmd to a sub dir usr/bin withing the ftpusers home dir.&lt;BR /&gt;&lt;BR /&gt;Here's the link I found&lt;BR /&gt;&lt;A href="http://www2.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&amp;amp;docId=200000063248362" target="_blank"&gt;http://www2.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&amp;amp;docId=200000063248362&lt;/A&gt;</description>
      <pubDate>Thu, 14 Nov 2002 18:24:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845046#M91988</guid>
      <dc:creator>Andy Macleod</dc:creator>
      <dc:date>2002-11-14T18:24:49Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845047#M91989</link>
      <description>If I now want to enable ls and rename for the ftp user, what do I need to do?&lt;BR /&gt;&lt;BR /&gt;I've changed the lines in /etc/ftpd/access to yes for the items rename overwrite and delete but I still cannot do an ls or rename.&lt;BR /&gt;&lt;BR /&gt;Please help</description>
      <pubDate>Fri, 15 Nov 2002 10:18:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845047#M91989</guid>
      <dc:creator>Andy Macleod</dc:creator>
      <dc:date>2002-11-15T10:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845048#M91990</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;for listing you have to copy /sbin/ls to the home directory of the ftp user.&lt;BR /&gt;First create usr/bin under the home dir of the ftp user ie:&lt;BR /&gt;umask 222&lt;BR /&gt;mkdir -p /home/user/usr/bin&lt;BR /&gt;&lt;BR /&gt;Then copy the ls binary:&lt;BR /&gt;cp -p /bin/ls /home/user/usr/bin&lt;BR /&gt;&lt;BR /&gt;Regards</description>
      <pubDate>Fri, 15 Nov 2002 10:32:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845048#M91990</guid>
      <dc:creator>Andreas Voss</dc:creator>
      <dc:date>2002-11-15T10:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845049#M91991</link>
      <description>I've done all that and it still doesnt work.&lt;BR /&gt;&lt;BR /&gt;I've played with combinations of shells and groups and the only way I can get get rename to work is to remove the ftpuser from my secureftp (ftponly) group, but that then allows the user to move around the file structure.&lt;BR /&gt;&lt;BR /&gt;Any ideas ?&lt;BR /&gt;here's a copy of my ftpaccess file&lt;BR /&gt;&lt;BR /&gt;loginfails 2&lt;BR /&gt;&lt;BR /&gt;class   local   real,guest,anonymous *.domain 0.0.0.0&lt;BR /&gt;class   remote  real,guest,anonymous *&lt;BR /&gt;&lt;BR /&gt;limit   local   20  Any                 /etc/msgs/msg.toomany&lt;BR /&gt;limit   remote  100 SaSu|Any1800-0600   /etc/msgs/msg.toomany&lt;BR /&gt;limit   remote  60  Any                 /etc/msgs/msg.toomany&lt;BR /&gt;&lt;BR /&gt;readme  README*    login&lt;BR /&gt;readme  README*    cwd=*&lt;BR /&gt;&lt;BR /&gt;message /welcome.msg            login&lt;BR /&gt;message .message                cwd=*&lt;BR /&gt;&lt;BR /&gt;compress        yes             local remote&lt;BR /&gt;tar             yes             local remote&lt;BR /&gt;&lt;BR /&gt;# allow use of private file for SITE GROUP and SITE GPASS?&lt;BR /&gt;private         yes&lt;BR /&gt;&lt;BR /&gt;# passwd-check  &lt;NONE&gt;  [&lt;ENFORCE&gt;]&lt;BR /&gt;passwd-check    rfc822  warn&lt;BR /&gt;&lt;BR /&gt;log commands real&lt;BR /&gt;log transfers anonymous,real inbound,outbound&lt;BR /&gt;shutdown /etc/shutmsg&lt;BR /&gt;&lt;BR /&gt;# all the following default to "yes" for everybody&lt;BR /&gt;delete          yes     guest,anonymous         # delete permission?&lt;BR /&gt;overwrite       yes     guest,anonymous         # overwrite permission?&lt;BR /&gt;rename          yes     guest,anonymous # rename permission?&lt;BR /&gt;chmod           no      anonymous               # chmod permission?&lt;BR /&gt;umask           no      anonymous               # umask permission?&lt;BR /&gt;&lt;BR /&gt;# specify the upload directory information&lt;BR /&gt;upload  /var/ftp  *             no&lt;BR /&gt;upload  /var/ftp  /incoming     yes     root    daemon  0600 dirs&lt;BR /&gt;upload  /var/ftp  /bin          no&lt;BR /&gt;upload  /var/ftp  /etc          no&lt;BR /&gt;&lt;BR /&gt;# directory aliases&lt;BR /&gt;alias   inc    /incoming&lt;BR /&gt;&lt;BR /&gt;# cdpath&lt;BR /&gt;cdpath  /incoming&lt;BR /&gt;cdpath  /pub&lt;BR /&gt;cdpath  /&lt;BR /&gt;&lt;BR /&gt;# path-filter...&lt;BR /&gt;path-filter  anonymous  /etc/pathmsg  ^[-A-Za-z0-9_\.]*$  ^\.  ^-&lt;BR /&gt;path-filter  guest      /etc/pathmsg  ^[-A-Za-z0-9_\.]*$  ^\.  ^-&lt;BR /&gt;&lt;BR /&gt;# specify which group of users will be treated as "guests".&lt;BR /&gt;guestgroup secureftp&lt;BR /&gt;&lt;/ENFORCE&gt;&lt;/NONE&gt;</description>
      <pubDate>Fri, 15 Nov 2002 10:51:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845049#M91991</guid>
      <dc:creator>Andy Macleod</dc:creator>
      <dc:date>2002-11-15T10:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845050#M91992</link>
      <description>Here's what I see when I log on&lt;BR /&gt;&lt;BR /&gt;230 User hostftp1 logged in.  Access restrictions apply.&lt;BR /&gt;Remote system type is UNIX.&lt;BR /&gt;Using binary mode to transfer files.&lt;BR /&gt;ftp&amp;gt; pwd&lt;BR /&gt;257 "/hostftp1" is current directory.&lt;BR /&gt;ftp&amp;gt; ls&lt;BR /&gt;200 PORT command successful.&lt;BR /&gt;150 Opening ASCII mode data connection for /usr/bin/ls.&lt;BR /&gt;226 Transfer complete.&lt;BR /&gt;&lt;BR /&gt;But the ls command doesnt show the 2 files I've just put in there either.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 15 Nov 2002 10:52:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845050#M91992</guid>
      <dc:creator>Andy Macleod</dc:creator>
      <dc:date>2002-11-15T10:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845051#M91993</link>
      <description>Hi,&lt;BR /&gt;When you establish the ftp session, does the system then say "Users &lt;USERNAME&gt; logged in. Access restrictions apply"? &lt;BR /&gt;If you execute "pwd" immediately after you have established your ftp session, it should show what has been entered after the full stop in the 6th field of the &lt;USERNAME&gt; definition in /etc/passwd. Does it do that?&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;John K.&lt;BR /&gt;&lt;/USERNAME&gt;&lt;/USERNAME&gt;</description>
      <pubDate>Fri, 15 Nov 2002 10:55:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845051#M91993</guid>
      <dc:creator>john korterman</dc:creator>
      <dc:date>2002-11-15T10:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845052#M91994</link>
      <description>Hi again,&lt;BR /&gt;The way I see the sequence of question/answers here, you can probably guess my next question (!): Did you copy the statically  linked ls command from /sbin/ls (which is the correct one) or?&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;John K.&lt;BR /&gt;</description>
      <pubDate>Fri, 15 Nov 2002 11:14:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845052#M91994</guid>
      <dc:creator>john korterman</dc:creator>
      <dc:date>2002-11-15T11:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845053#M91995</link>
      <description>I did this &lt;BR /&gt;&lt;BR /&gt;cd /home/username&lt;BR /&gt;mkdir usr&lt;BR /&gt;mkdir usr/bin&lt;BR /&gt;cp -p /sbin/ls usr/bin&lt;BR /&gt;chown -R bin:bin usr&lt;BR /&gt;chmod -R 555 usr&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 15 Nov 2002 11:17:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845053#M91995</guid>
      <dc:creator>Andy Macleod</dc:creator>
      <dc:date>2002-11-15T11:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845054#M91996</link>
      <description>Hmm,&lt;BR /&gt;.... almost out of ideas. Does it make a difference to use "dir"?&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;John K.</description>
      <pubDate>Fri, 15 Nov 2002 12:13:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845054#M91996</guid>
      <dc:creator>john korterman</dc:creator>
      <dc:date>2002-11-15T12:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845055#M91997</link>
      <description>Nope - HELP !</description>
      <pubDate>Fri, 15 Nov 2002 12:38:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845055#M91997</guid>
      <dc:creator>Andy Macleod</dc:creator>
      <dc:date>2002-11-15T12:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845056#M91998</link>
      <description>Hi,&lt;BR /&gt;have you made the ftp-connection from the server itself or from a PC client?&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;John K.</description>
      <pubDate>Fri, 15 Nov 2002 13:54:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845056#M91998</guid>
      <dc:creator>john korterman</dc:creator>
      <dc:date>2002-11-15T13:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ftp</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845057#M91999</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;You need to have that usr/bin/ls tree under the hostftp1 directory the user is chroot'ed to .&lt;BR /&gt;&lt;BR /&gt;I also noticed that you kept a lot of the default variables in you ftpaccess file, which won't work.  For example:&lt;BR /&gt;&lt;BR /&gt;# specify the upload directory information &lt;BR /&gt;upload /var/ftp * no &lt;BR /&gt;upload /var/ftp /incoming yes root daemon 0600 dirs &lt;BR /&gt;upload /var/ftp /bin no &lt;BR /&gt;upload /var/ftp /etc no &lt;BR /&gt;&lt;BR /&gt;The /var/ftp should be changed to what you have, like /home/user and do you even have an incoming directory, I believe it was hostftp1:&lt;BR /&gt;&lt;BR /&gt;upload /home/user /ftpuser1 yes &lt;USERNAME&gt; &lt;GROUPNAME&gt; 0600 dirs &lt;BR /&gt;&lt;BR /&gt;Do a search on ftpaccess and really read the man pages clarification on all these values; you may not even need them all.  There are also release notes in /usr/share/doc/RelNotes_newftp.txt&lt;BR /&gt;&lt;BR /&gt;Hope this helps&lt;BR /&gt;&lt;BR /&gt;Chris&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/GROUPNAME&gt;&lt;/USERNAME&gt;</description>
      <pubDate>Fri, 15 Nov 2002 14:21:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-ftp/m-p/2845057#M91999</guid>
      <dc:creator>Christopher McCray_1</dc:creator>
      <dc:date>2002-11-15T14:21:07Z</dc:date>
    </item>
  </channel>
</rss>

