LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-23-2006, 01:16 PM   #1
vbsaltydog
Member
 
Registered: Nov 2005
Distribution: CentOS
Posts: 154

Rep: Reputation: 15
chroot to restrict ssh directory access


I am trying to allow ssh access to web clients so they can see their web direrctory via ssh but not be able to browse the directory structure beyond their web root.

I have found two tools that assist in this procedure.

(1)jailkit
(2)jail

I am using jail currently and the setup seemed to go smoothly but now that I am at the step to launch the jail app I get errors about the user's home directories not being configured for jail.

Jail does not seem to have very thorough documentation and no support forum so I was wondering if anyone here is familiar with this app and the directory error?

I am also open to other suggestions for controlling directory access over ssh.

Thanks to all,

-vbsaltydog
 
Old 07-23-2006, 04:28 PM   #2
btmiller
Senior Member
 
Registered: May 2004
Location: In the DC 'burbs
Distribution: Arch, Scientific Linux, Debian, Ubuntu
Posts: 4,290

Rep: Reputation: 378Reputation: 378Reputation: 378Reputation: 378
I used JailKit at one put but now of late I've just been using either Chroot SSH or one of the similar patches to OpenSSH itself that does chrooting. I don't know anything about jail (thought that waqs FreeBSD only?), but the ways I've used are not particularly hard to get working -- just make sure that all of the libraries, devices, and applications needed by the user are included in the jail (ldd plus some testing really helps here).

Realistically speaking, unless you are on a machine with lots of critical data data / potential for abuse, there's no harm in letting users browse the filesystem. They won't be able to access anything sensitive if permissions are set correctly.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Restrict ssh/sftp with chroot? Chowroc Linux - Networking 4 01-25-2005 10:48 AM
file transfer over ssh restrict directory browsing niall0s Linux - General 11 09-11-2003 02:50 PM
restrict newuser directory access lonerangerusa Linux - Security 2 05-02-2003 02:41 PM
How do I restrict ssh access to certain ip addresses? 360 Linux - Networking 5 04-05-2002 08:04 AM
Restrict directory access bdu Linux - Security 1 02-07-2002 12:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:38 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration