1848183 Members
5232 Online
104022 Solutions
New Discussion

ftp user

 
Sharon Bi
Frequent Advisor

ftp user

Dear all,

I am going to create an ftp account ( not anonymous account): ftp_dca.

This account should ONLY be able to read ( which is to do a "get" ) from /ftp. And this account shouldn't have any shell. Because this will be used to external user, we don't want them to be able to telnet or even to ls some other directory than /ftp.

Can someone tell me how to do that? Thanks in advance!!

2 REPLIES 2
James R. Ferguson
Acclaimed Contributor

Re: ftp user

Sharon:

Probably your best choices are to setup FTP restrictions in /etc/ftpusers (see man 4 ftpusers) and inetd.sec (see man 4 inetd.sec). In addition, enable logging for FTP in inetd (see man 1 inetd). I would suggest setting both the -l and -v options to cause the most information logged (see man 1M ftpd). You can also see the default umask with the -u option for the ftpd daemon when it is started (man 1M ftpd).

...JRF...
James R. Ferguson
Acclaimed Contributor

Re: ftp user

Sharon:

BTW, ftpd accesses local accounts without using their login shells. Therefore, setting up accounts with restricted shells doesn't achieve what one might think. Use the /etc/ftpusers file for restrictive purposes.

...JRF...