System Administration
cancel
Showing results for 
Search instead for 
Did you mean: 

Restict some users to do vsftp

restrict a perticular p
Occasional Advisor

Restict some users to do vsftp

Hi Gurus,

I need your help in restricting some users to use the service vsftp.

My system details are as follows

OS SLES Relase 9 update 4
vsftp version vsftpd-2.0.4-0.3

Any help with this reagrds is most welcome.
7 REPLIES
Michal Kapalka (mikap)
Honored Contributor

Re: Restict some users to do vsftp

restrict a perticular p
Occasional Advisor

Re: Restict some users to do vsftp

Thanks for your reply,
But that is not the solution i am looking for.

is there any other way to achieve this.

Regards
Anand
Steven E. Protter
Exalted Contributor

Re: Restict some users to do vsftp

Shalom,

What kind of restrictions do you want to impose?

vsftpd has anonymous ftp enabled by default?

To provide a solution, a goal statement is needed. "Restricting some users..." Restricting them from doing what?

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
restrict a perticular p
Occasional Advisor

Re: Restict some users to do vsftp

Hi Protter,

Thanks for your reply.
below is my requirement,

I need to restict perticular user to use the vsftp service.

That mean the perticular user should not login to the server using vsftp.

For example: Say user abc and xyz are using vsftp to login to server, then I wanted to restrict user abc to login using vsftp and user xyz is allowd on the server to use vsftp.

hope this clears my requirement.
Alexander Chuzhoy
Honored Contributor

Re: Restict some users to do vsftp

From "man vsftpd.conf":
The mentioned below options should be added to the vsftpd.conf file followed by restart of vsftpd:
userlist_deny
This option is examined if userlist_enable is activated. If you set this setting to NO, then users will be denied login unless they are
explicitly listed in the file specified by userlist_file. When login is denied, the denial is issued before the user is asked for a
password.

Default: YES

userlist_enable
If enabled, vsftpd will load a list of usernames, from the filename given by userlist_file. If a user tries to log in using a name in
this file, they will be denied before they are asked for a password. This may be useful in preventing cleartext passwords being trans-
mitted. See also userlist_deny.

Default: NO
restrict a perticular p
Occasional Advisor

Re: Restict some users to do vsftp

I believe yes this is the solution.

I will try this solution in the test servers and let all of you know.

I am planning to do following in /etc/vsftpd.conf file


userlist_file/etc/vsftpd.user_list

userlist_enable=YES

userlist_deny=YES


If anyone already tried this solution or have other tested solution then please let me know.


restrict a perticular p
Occasional Advisor

Re: Restict some users to do vsftp

Forgot to mention,
I will put the resticted user list in the file etc/vsftpd.user_list.