- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Restricting ftp on HP 11.0
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-09-2004 09:25 AM
03-09-2004 09:25 AM
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-09-2004 09:35 AM
03-09-2004 09:35 AM
Re: Restricting ftp on HP 11.0
That will prevent shell logins.
Two links to help you.
http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B2355-90696/B2355-90696_top.html&con=/hpux/onlinedocs/B2355-90696/00/00/36-con.html&toc=/hpux/onlinedocs/B2355-90696/00/00/36-toc.html&searchterms=chroot%7cftpaccess&queryid=20040309-153446
http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/5969-4306/5969-4306_top.html&con=/hpux/onlinedocs/5969-4306/00/00/4-con.html&toc=/hpux/onlinedocs/5969-4306/00/00/4-toc.html&searchterms=chroot%7cftpaccess&queryid=20040309-153446
Take a look at chroot configuration in those links.
Air tight, meets your needs.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-09-2004 09:39 AM
03-09-2004 09:39 AM
SolutionYes.
You will need to basically setup a user with the default shell of /usr/bin/false. This way user will not be able to logon to the server. Add /usr/bin/false to /etc/shells.
Make the user's home directory as chrooted one. For ex
grep test /etc/passwd
test:*:10101:2000::/home/test/./:/usr/bin/false
grep guest /etc/group
guest::2000
Now add the following entries to your ftpaccess file
guestgroup guest
Now try ftp'ing as 'test'.
It should say "Access restrictions Apply". In the ftp session try 'cd /usr' etc., You shouldn't get to those directories.
There are further restrictions you can apply to this user like no delete , no chmod etc., for this guest group. Man page should give you more details.
-Sri
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-09-2004 09:45 AM
03-09-2004 09:45 AM
Re: Restricting ftp on HP 11.0
ftp stream tcp nowait root /usr/lbin/ftpd ftpd -l -a
2) # inetd -c
3) # groupadd -g 999 onlyftp
4) # useradd -g 999 -m -s /usr/bin/false ftptest
5) # echo "/usr/bin/false" >> /etc/shells
6) # cp /usr/newconfig/etc/ftpd/examples/ftpaccess /etc/ftpd/
7) vi /etc/ftpd/ftpaccess
guestgroup onlyftp
8) done
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-09-2004 10:24 AM
03-09-2004 10:24 AM
Re: Restricting ftp on HP 11.0
Attached are the HP docks we used to accomplish what you are attempting.
Best of luck.
Regards,
dl