LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-20-2009, 05:13 AM   #1
alexxxutz
LQ Newbie
 
Registered: Mar 2009
Posts: 19

Rep: Reputation: 0
Concurrent nologin access to ssh


Hello,
I need to have a linux account witch have access only to tcp forwarding (tunneling), no shell access and concurently just 1 login per account.
I tried to create accounts with nologin shell and set the limit of concurrent connections * hard maxlogins 1 in /etc/security/limits.conf . If i create a nologin account and check the "Don't start a shell or a command at all" in putty, the port forwarding works, the account don't have access to shell, but I can open more than one session. The problem is the condition in /etc/security/limits.conf works only if a shell opens. It doesn't works for nologin with "Don't start a shell or a command at all" checked in putty. So i tried to create a simple shell witch only says "welcome". The port forwarding works, i cannot login multiple times with an account and i don't have shell access, but if my clients checks the "Don't start a shell or a command at all" in putty they can login many times concurently and forward ports.Is there a way to force terminal open, so the "dont start.." option stop working? Or to make the port forwarding work only after shell starts?
I need a solution for the problem.
Please help
 
Old 03-20-2009, 05:18 AM   #2
robertjinx
Member
 
Registered: Oct 2007
Location: Prague, CZ
Distribution: RedHat / CentOS / Ubuntu / SUSE / Debian
Posts: 749

Rep: Reputation: 73
I think you have to play with pam settings and add at login or sshd the option

session required pam_limits.so

In rest Im not sure you can do other settings which could help.
 
Old 03-20-2009, 06:39 AM   #3
alexxxutz
LQ Newbie
 
Registered: Mar 2009
Posts: 19

Original Poster
Rep: Reputation: 0
still not working

i tried now to add that line to login restarted the sshd service but i'm still able to open more than one sessions with that option checked in putty
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSH Help - How to limit concurrent logins by a user brokenpromises Linux - Server 4 03-29-2009 03:03 AM
SSH access problems: Can only allow users SSH access by adding to root group dhupke Slackware 10 12-21-2008 09:48 AM
Disabling login access to account, nologin,false or null? humbletech99 Linux - Security 2 03-16-2007 10:36 AM
Package updater concurrent access bertie57 Linux - Newbie 3 01-12-2007 02:07 AM
how to allow multiple users concurrent access to the sound card under linux kosaspree Linux - Hardware 2 09-17-2004 04:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 08:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration