LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-20-2006, 07:50 AM   #1
reeseslover531
Member
 
Registered: Nov 2005
Distribution: Fedora Core 5
Posts: 64

Rep: Reputation: 15
How do I chroot a user?


I was wondering how I would chroot a User? I am using FC5 and I want to give my friend and ftp account, but need to make sure he is chrooted to his directory. How would I do this?
 
Old 10-20-2006, 08:13 AM   #2
aus9
LQ 5k Club
 
Registered: Oct 2003
Location: Western Australia
Distribution: Icewm
Posts: 5,842

Rep: Reputation: Disabled
umm do you mean, you want a friend on external network to shh into your server but not have access to getting root access?

if so edit your /etc/ssh/shhd-config to disallow root

and lots or reading on security but here is basic
http://wiki.linuxquestions.org/wiki/Securing_ssh

Last edited by aus9; 10-20-2006 at 10:48 AM.
 
Old 10-22-2006, 07:12 AM   #3
reeseslover531
Member
 
Registered: Nov 2005
Distribution: Fedora Core 5
Posts: 64

Original Poster
Rep: Reputation: 15
this is what I want. I want my friend to log in as his user, and it goes to /home/user. Then, he can only stay in that /home/user folder. He can go to anything within that folder, but can't move up out of the /home/user folder. IS that possible?
 
Old 10-22-2006, 08:08 AM   #4
sn68
Member
 
Registered: Oct 2005
Distribution: FC5
Posts: 338

Rep: Reputation: 30
Isn't that the default behaviour?
By default things are exactly as you want them to be..
 
Old 10-22-2006, 09:04 AM   #5
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Take a look at: http://wiki.archlinux.org/index.php/Openssh-chroot
 
Old 10-22-2006, 01:12 PM   #6
nayyares
Member
 
Registered: Oct 2006
Location: JNB, SA
Posts: 33

Rep: Reputation: 15
Hi,
you have to just add those users in your system and make the home directoy you want to use by them and rest is the default behavior, thanks
 
Old 10-22-2006, 01:15 PM   #7
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
@nayyares: I don't believe SSH chroots by default. If so, how is the environment set up with all the executables and libraries they'd need? Every user would need a copy in /home/<user>/
 
Old 10-22-2006, 01:49 PM   #8
~=gr3p=~
Member
 
Registered: Feb 2005
Location: ~h3av3n~
Distribution: RHEL 4, Fedora Core 3,6,7 Centos 5, Ubuntu 7.04
Posts: 227

Rep: Reputation: 30
use rssh that way no patching required for openssh..u may follow a thread posted by me..

http://www.linuxquestions.org/questi...d.php?t=488493
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
sudo /usr/bin/chroot /home/chroot /bin/su - xxx| /bin/su: user xxx does not exist saavik Linux - General 3 07-04-2007 10:30 AM
chroot user mikeshn Linux - General 3 02-03-2005 02:36 PM
chroot sftp user group bmeckle Linux - Newbie 0 06-02-2004 03:58 PM
how do i use chroot to set a user account ... Hano Linux - Security 3 11-11-2003 02:21 PM
chroot sftp user? cliffyman Linux - Security 8 05-08-2003 09:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:40 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration