LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 01-13-2009, 11:53 AM   #1
iinfi
LQ Newbie
 
Registered: Dec 2008
Posts: 26

Rep: Reputation: 15
Question deny browse access to users


i m running RHEL 5 on my company system.

there is a client requirement that when users log into the system through SSH they should not be able to even browse through the directory other than their home directory.

is this possible?
i v referred http://www.fuschlberger.net/programs...p-chroot-jail/ but when i create a chroot the user is not able to log in at all!! be it normally on the system itself or thru ssh.

the end goal is to set up an SFTP server so that the client can send files securely to their customers.

set up an FTP server with vsftpd is an option but again I find that the ftp user (not anonymous users, not root user, <anon user login on FTP is disabled>) is able to go up the directories and view the contents of all the root directories. the client does not want this also.

am i clear? any workarnd? thanks
 
Old 01-13-2009, 12:26 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well you definitely want a chroot jail. vsftpd has many many good tutorials online to guide you through it, same for sftp too really. if you do get stuck, ask us specific questions and we'll see what we can suggest. Personally I'd probably suggest vsftpd with SSL/TLS, as it's more generic, but sftp is just as secure.
 
Old 01-15-2009, 12:52 AM   #3
iinfi
LQ Newbie
 
Registered: Dec 2008
Posts: 26

Original Poster
Rep: Reputation: 15
thanks for your reply.
the requirement was, if i was configuring a FTP server the transfer of files should also be thru a secure channel. Whn i configured SSL for the same the client did not like it as they didnt want to spend money to get a proper certificate frm CA and didnt want pop ups in the browser or FTP client saying the SSL Certificate is not digitally signed by CA.

So i tried for SFTP. config was dont but the issue again is that, all users who login are able to browse thru the root directory as well. though they cannot make any changes the client did not want that also. so the resolution was to create a chroot jail. i tried a few utilities like jailkit and makejail which did create a jail like env but didnt allow any users added in the jail. I also ran this script which also successfully created chrooted users but didnt allow them to log in.
can you plz try to run this script and tell me if it works for you?
thanks again
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ssh: deny all users, except one hamish Linux - Security 13 09-07-2008 07:58 PM
Courier IMAP deny users mjnman Linux - Software 2 08-01-2007 01:59 PM
deny login to users sachin1361 Linux - Enterprise 1 02-28-2007 03:01 AM
Deny some users access to the web with IPtables? osX-linux Linux - Networking 4 06-22-2003 01:42 PM
how to deny all users in vsftp except one? lzyking Linux - Software 7 12-11-2002 10:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 08:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration