- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Another FTP access denied (530) problem
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 02:11 AM
тАО12-03-2003 02:11 AM
I'm an SA using HP-UX 11.11, recently I meet a strange problem with FTP access.
A user(oracle) tried to connect server via FTP but failed:
530 User oracle access denied...
Login failed.
I used root to check my config file at /etc, but I can't find /etc/ftpd/ftpaccess or /etc/shells.
Then I tried to create a new user(user01) and it can ftp to the server, no error at all. (of course, i also tried 'root', and no problem)
So, where i should look into to solve this problem ?
Thanks a lot !
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 02:16 AM
тАО12-03-2003 02:16 AM
Re: Another FTP access denied (530) problem
And if this system has tcp_wrappers installed that there are no entries in /etc/hosts.deny to prevent this access.
Also what shell does this user have defined in it's /etc/passwd entry?
HTH,
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 03:27 AM
тАО12-03-2003 03:27 AM
Re: Another FTP access denied (530) problem
because I installed everything by default.
(I tried to use a new user to ftp the server, it works fine)
And here's the line I cut from /etc/passwd for 'oracle'(the user can't ftp):
oracle:*:102:102:Oracle Owner:/home/oracle:/bin/ksh
(this is: ksh)
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 03:38 AM
тАО12-03-2003 03:38 AM
Re: Another FTP access denied (530) problem
Thanks
Dipak
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 03:42 AM
тАО12-03-2003 03:42 AM
Re: Another FTP access denied (530) problem
If not, then the fact that oracle user has no PW defined (not even null) could prevent the ftp connection.
Can the oracle user login?
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 03:43 AM
тАО12-03-2003 03:43 AM
Re: Another FTP access denied (530) problem
If your oracle id is locked, this will happen.
What about the ftpuser file, is it in there?
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 04:11 AM
тАО12-03-2003 04:11 AM
Re: Another FTP access denied (530) problem
is there a /etc/ftpd/ftpusers file?
greetings,
Michael
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 05:24 AM
тАО12-03-2003 05:24 AM
Re: Another FTP access denied (530) problem
I created another user(user02) using /bin/ksh, and I can successfully ftp
the server by using this user(user02). And as I mentioned before that user01
used /bin/sh, and it's ok too. So, I don't think it should be the problem of
/etc/shells.
RE: Jeff Schussele
Yes, i think it's a trusted system, because there is /tcb folder.
yes, user 'oracle' can login via telnet, but it is denied via ftp :(
RE: Steven E Protter
there's no oracle logins when i tried ftp using user 'oracle'
and there's no oracle process running(I stopped all of them).
RE: Michael Schulte
# ll /etc/ftpd
total 0
dr-xr--r-- 2 bin bin 96 Nov 15 2000 ftp-exec
dr-xr--r-- 2 bin bin 96 Nov 15 2000 pids
That's all in /etc/ftpd, and those 2 folders are empty inside.
NO ftpusers
NOTE: there is one of my co-works who has access to this oracle user,
it's possible that he changed some files that under his control, so...
Any other idea about this problem ? Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 06:52 AM
тАО12-03-2003 06:52 AM
Re: Another FTP access denied (530) problem
Any message in /var/adm/syslog/syslog.log.
HTH,
Umapathy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 06:55 AM
тАО12-03-2003 06:55 AM
Re: Another FTP access denied (530) problem
run
ckpw
And check the output.
You could have a corrupted passwd file.
Rgds,
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 09:11 AM
тАО12-03-2003 09:11 AM
Re: Another FTP access denied (530) problem
I think you are right, here's the log from /var/adm/syslog/syslog.log:
Dec 3 15:12:14
Dec 3 15:12:16
(I replaced those info in "< >" for security purpose.)
Jeff Schussele:
Yes, I think I need to check the integrity of the passwd file, but I
forget where I can find 'ckpw' :(
So, please tell me how to run this. Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 02:10 PM
тАО12-03-2003 02:10 PM
Re: Another FTP access denied (530) problem
thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-03-2003 05:55 PM
тАО12-03-2003 05:55 PM
Re: Another FTP access denied (530) problem
So what you need to do is take a look at the entry of oracle in /etc/passwd and check that it has:
a) a passwd
b) a correct homedir. It should exist and be accessible by oracle. I'm not sure if it has to be owned by oracle.
c) a correct shell, or otherwise you need to add the shell to /etc/shells (create one to test, then add the default shells that can be found in "man shells")
If it still doesn't work, take a look in /etc/ftpd. The file ftpusers blocks users, perhaps oracle too.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 12:20 AM
тАО12-04-2003 12:20 AM
Re: Another FTP access denied (530) problem
Thanks.
Once again, here's the line for 'oracle' in /etc/passwd :
oracle:*:102:102:Oracle Owner:/home/oracle:/bin/ksh
/home/oracle exists, and I can telnet the server using 'oracle' and
also use this account to successfully install Oracle 9i, but just
cannot FTP :(
I run 'pwck' this morning, it showed another 2 user(not 'oracle')
"Login directory not found", but I don't think the ftp problem raised
because of this.
And
drwxr-xr-x 6 oracle oinstall 8192 Dec 4 07:56 /home/oracle
shows the user(oracle) home is owned by 'oracle', and all files and folder
under /home/oracle are all owned by by 'oracle' and 'oinstall'.
And as I mentioned above, I have setup another account using the same shell
(ksh) and successfully connected to the server via FTP, and i think if
something wrong with the shell of user 'oracle', there must be a problem
when I use it, but I have installed Oracle 9i without problem.
As I said above, there is NO ftpusers file under /etc/ftpd, NO /etc/shells,
because it's a new system with HP-UX 11.11B.
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 12:27 AM
тАО12-04-2003 12:27 AM
Re: Another FTP access denied (530) problem
If present rename it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 12:29 AM
тАО12-04-2003 12:29 AM
Re: Another FTP access denied (530) problem
As the syslog shows bad shell.
Try logging into oracle user and check the login shell whether it the ksh as defined in /etc/passwd
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 01:01 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 01:05 AM
тАО12-04-2003 01:05 AM
Re: Another FTP access denied (530) problem
1. The following is all files under /home/oracle
-rwxrwxrwx 1 oracle oinstall 0 Nov 30 15:15 .ICEauthority
-rwxr-xr-x 1 oracle oinstall 74 Nov 30 14:48 .TTauthority
-rwxr-xr-x 1 oracle oinstall 98 Nov 30 14:48 .Xauthority
-r-------- 1 oracle oinstall 832 Nov 30 11:54 .cshrc
drwxr-xr-x 11 oracle oinstall 8192 Dec 2 09:49 .dt
-rwxr-xr-x 1 oracle oinstall 5451 Nov 30 11:54 .dtprofile
-r-------- 1 oracle oinstall 347 Nov 30 11:54 .exrc
-r-------- 1 oracle oinstall 334 Nov 30 11:54 .login
drwx------ 5 oracle oinstall 8192 Dec 3 14:55 .netscape
-rwxrw-rw- 1 oracle oinstall 1132 Dec 3 14:37 .profile
-rw------- 1 oracle oinstall 2344 Dec 4 08:50 .sh_history
drwx------ 5 oracle oinstall 96 Nov 30 11:54 .sw
-rw------- 1 oracle oinstall 1521324 Nov 30 11:54 core
-rwx------ 1 oracle oinstall 628 Dec 3 16:01 dd
drwx------ 2 oracle oinstall 96 Dec 3 14:53 nsmail
-rw------- 1 oracle oinstall 760 Nov 30 11:54 oratab
-rw------- 1 oracle oinstall 340 Nov 30 11:54 redoit
-rw------- 1 oracle oinstall 8010 Nov 30 11:54 sqlnet.log
NO file named .netrc
And I also tried to rename the file '.profile' to 'abc.profile', and tried
to ftp again, same problem :(
2. And here's the output under '/etc'
# ll -aR ftp*
total 16
dr-xr--r-- 4 bin bin 96 Nov 15 2000 .
dr-xr-xr-x 30 bin bin 8192 Dec 3 12:56 ..
dr-xr--r-- 2 bin bin 96 Nov 15 2000 ftp-exec
dr-xr--r-- 2 bin bin 96 Nov 15 2000 pids
ftpd/ftp-exec:
total 0
dr-xr--r-- 2 bin bin 96 Nov 15 2000 .
dr-xr--r-- 4 bin bin 96 Nov 15 2000 ..
ftpd/pids:
total 0
dr-xr--r-- 2 bin bin 96 Nov 15 2000 .
dr-xr--r-- 4 bin bin 96 Nov 15 2000 ..
So, NO ftpusers file.
3.
$whoami
oracle
$echo $SHELL
/bin/ksh
So, it shows as it defined in /etc/passwd:
oracle:*:102:102:Oracle Owner:/home/oracle:/bin/ksh
Any idea ? Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 01:08 AM
тАО12-04-2003 01:08 AM
Re: Another FTP access denied (530) problem
(Make sure you have /usr/bin/ksh in /etc/shells, and perms on /etc/shells are OK)
Also telnet with oracler user and say logname
Post the results.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 01:09 AM
тАО12-04-2003 01:09 AM
Re: Another FTP access denied (530) problem
According to the manpage of getusershell(3C) /bin/ksh is not in the default list of shells, while /usr/bin/ksh is. This could very well be the cause of the problem.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 01:27 AM
тАО12-04-2003 01:27 AM
Re: Another FTP access denied (530) problem
WOOOOOOOOOOOOOOOOOOOOOOOOOOOOOW, you are so COOOOOOOOOOOOOOOOOOOOOOL !
I add you 10 points !!!
Yes, after I change '/bin/ksh' to '/usr/bin/ksh' in /etc/passwd, it works!
I can FTP using 'oracle' now !
And those users I created for testing(user01,user02,those i mentioned
above) are all using '/usr/bin/ksh', I haven't noticed that before !!!
And I tried to compared those 2 ksh files:
# ll /bin/ksh
-r-xr-xr-x 2 bin bin 159744 Nov 29 2002 /bin/ksh
# ll /usr/bin/ksh
-r-xr-xr-x 2 bin bin 159744 Nov 29 2002 /usr/bin/ksh
I wonder whether the file '/bin/ksh' is corrupted or not, but if it's corrupted,
why can i still use it to telnet the server with user 'oracle', and everything
seems fine ? And there's NO error in syslog.log file after I telnet! Strange !
Any idea on this ?
Here, thanks a lot for every one helps on this case !
I greatly appreciate all your efforts!!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 01:33 AM
тАО12-04-2003 01:33 AM
Re: Another FTP access denied (530) problem
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 01:34 AM
тАО12-04-2003 01:34 AM
Re: Another FTP access denied (530) problem
Yes, the problem is from the /bin/ksh. I got it from Ettore Rossi.
And Elmar, do you know what's the difference of those 2 shell files?
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 01:34 AM
тАО12-04-2003 01:34 AM
Re: Another FTP access denied (530) problem
Reason of that is that Elmar said.
If /etc/shells doens't exist on system then it uses /usr/bin/ksh if user shell is ksh, otherwise /usr/bin/csh if user shell is csh.
Anyway you could create /etc/shells and insert /bin/ksh (just a test too ;-). Then you will see that ftp will work fine with /bin/ksh in /etc/passwd too.
Best regards,
Ettore
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-04-2003 01:41 AM
тАО12-04-2003 01:41 AM
Re: Another FTP access denied (530) problem
thanks!