LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-18-2010, 04:01 AM   #1
golden_boy615
Member
 
Registered: Dec 2008
Distribution: Ubuntu Fedora
Posts: 445

Rep: Reputation: 18
how to define ssh users


hello
How can I define some users as ssh user( ssh to linux remotely ) and the others not ( do not ssh)?

Thanks
 
Old 12-18-2010, 04:22 AM   #2
druuna
LQ Veteran
 
Registered: Sep 2003
Posts: 10,532
Blog Entries: 7

Rep: Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405Reputation: 2405
Hi,

The sshd_config file has an AllowUsers and AllowGroups directive, which makes it possible to set which users/groups are allowed to use ssh.

Have a look here for the details: man sshd_config

Hope this helps.
 
Old 12-18-2010, 05:17 AM   #3
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,631

Rep: Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696
allow ssh to some users, not others

Can you provide more detail about what you really want to achieve?
Do you mean that some user accounts on the machine should only be able to be used at the console, no remote access?
Do you mean some users should not get a shell (as sftp/scp only) to transfer files but NOT to run programs?
Perhaps something else?
 
Old 12-19-2010, 08:34 AM   #4
golden_boy615
Member
 
Registered: Dec 2008
Distribution: Ubuntu Fedora
Posts: 445

Original Poster
Rep: Reputation: 18
I meant ,some user accounts on the machine should only be able to be used at the console, no remote access.
 
Old 12-20-2010, 08:57 AM   #5
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,631

Rep: Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696
allow ssh to some users, not others

Then the post from Druuna gives you the critical piece. If ONLY the users you want to allow are properly listed as allowed, NO ONE ELSE will be able to access the server over ssh from any remote location.

Read the docs, set up some two users (one listed, one not) and run a few tests. It should not take long for you to gain confidence in using these settings to control access.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
All users SSH -> YES ... All users Console -> NO kspann Linux - Server 2 05-26-2010 10:56 AM
[SOLVED] pam_listfile to limit users domain users SSH access r3z Linux - Enterprise 5 09-19-2009 01:25 AM
How to set up ssh to allow users to ssh into the machine mrotsliah Linux - Server 14 06-03-2009 12:00 PM
SSH access problems: Can only allow users SSH access by adding to root group dhupke Slackware 10 12-21-2008 09:48 AM
How to add users to ssh (Configure ssh) A.Sai Hareesh Linux - Newbie 2 06-30-2008 08:23 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:50 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration