- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- ftponly configuration for sftp chrooted account
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2005 09:05 PM
10-02-2005 09:05 PM
ftponly configuration for sftp chrooted account
This meeans that the account can be used for access through telnet.
What needs to be done if I want the account to be 'ftponly' as well as sftp?
(so no shell should be available to the user to avoid the access through telnet)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2005 09:14 PM
10-02-2005 09:14 PM
Re: ftponly configuration for sftp chrooted account
-- /etc/profile --
ps | grep -q 'telnet
if [ ${?} -eq 0 ]
then
if [ $USER = "ftponly" || $USER = "sftp" ]
then
echo "Don't login with this"
sleep 1
fi
exit 1
fi
hth.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2005 09:28 PM
10-02-2005 09:28 PM
Re: ftponly configuration for sftp chrooted account
http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=943669
http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=942006
Have you tried with /bin/false ?
-Arun
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2005 09:33 PM
10-02-2005 09:33 PM
Re: ftponly configuration for sftp chrooted account
change ftponly and sftp account's shell to /usr/bin/false. Add this /usr/bin/false to /etc/shells file as well.
Try now with telnet login using ftponly or sftp account.
hth.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2005 09:37 PM
10-02-2005 09:37 PM
Re: ftponly configuration for sftp chrooted account
http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=957193
Or you can try with your script also as,
# cat > /usr/bin/blockshell
echo "Sorry you can not use this account"
echo "Contact @ Guus van Luijn"
sleep 4
exit 1
# chmod 555 /usr/bin/blockshell
# cat >> /etc/shells
/usr/bin/blockshell
# passwd -e /usr/bin/blockshell ftponly
# passwd -e /usr/bin/blockshell sftp
Now try with ftponly / sftp account for login. what is it saying.
hth.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2005 11:36 PM
10-02-2005 11:36 PM
Re: ftponly configuration for sftp chrooted account
simply put 'exit 0' in .profile without any sleep otherwise the user can type ctrl-c and interrumpt the profile and in this way he will hack you.
HTH,
Art
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2005 11:41 PM
10-02-2005 11:41 PM
Re: ftponly configuration for sftp chrooted account
You can not break /etc/profile setting of sleep + exit 1 by normal user's ctr+c.
It will not allow you. .profile is user based one.
Guus,
Change $USER to $LOGNAME as,
ps | grep -q 'telnet
if [ ${?} -eq 0 ]
then
if [ $LOGNAME = "ftponly" || $USER = "sftp" ]
then
echo "Don't login with this"
sleep 1
fi
exit 1
fi
where, $USER is ssh related variable.
hth.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2005 11:42 PM
10-02-2005 11:42 PM
Re: ftponly configuration for sftp chrooted account
hth.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-03-2005 01:13 AM
10-03-2005 01:13 AM
Re: ftponly configuration for sftp chrooted account
you are rigth abut /etc/profile, but your reply assume that Guus has root privilege.
My answer is for user without root capability.
Guus has only to change the .profile for the involved user.
Art