LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 06-30-2010, 04:48 AM   #1
nkjha
Member
 
Registered: Apr 2008
Posts: 30

Rep: Reputation: 15
User account with Minimum Privileges on Fedora


Hi all,
I need to create a special linux user account that has a very
limited set of permissions on the system. Essentially to
have read-only permissions for his home dir (and sub dirs)
and nothing else - i.e. this user has no write or execute
permissions and should not be able to read/access other user
dirs or indeed anything outside of his home directory,
irrespective of rwx permissions.


Thanks,
 
Old 06-30-2010, 05:14 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well you can't prevent them reading anything outside of a home directory otherwise they can't use the system commands etc - they'd have no way to do the few things you want them to be able to do. And if they are not executing anything, why do they need a shell login, is this not more of an ftp / http access that's needed?

I guess you probably want to look at a chroot jail, but not of their home directory, as they still own that, so you'd actually want them no have no home directory, but instead be dumped somewhere else, with the tools they are allowed to use to do whatever they can do symlinked into that mini environment with chroot, so there is nowhere else to go.
 
Old 06-30-2010, 06:17 AM   #3
Gridley
LQ Newbie
 
Registered: Apr 2010
Posts: 10

Rep: Reputation: 1
Quote:
...read-only permissions for his home dir...
That doesn't make any sense. His home dir is there as a place for ANY application he uses to store his preferences, histories, etc. The whole point of home directories is that they are isolated from the rest of the file structure.

Quote:
...this user has no write or execute permissions...
So, what do you propose he do with this set of permissions; that wouldn't even allow him to log in, or list files, or *anything*. Since this is the whole point of creating a user, this requirement seems to be senseless.
 
Old 06-30-2010, 09:56 AM   #4
nkjha
Member
 
Registered: Apr 2008
Posts: 30

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by Gridley View Post
That doesn't make any sense. His home dir is there as a place for ANY application he uses to store his preferences, histories, etc. The whole point of home directories is that they are isolated from the rest of the file structure.


So, what do you propose he do with this set of permissions; that wouldn't even allow him to log in, or list files, or *anything*. Since this is the whole point of creating a user, this requirement seems to be senseless.
--

Actually I want to create a user for FTP Server which has no any privileges to access any things outside his home directory .

Thanks.
 
Old 07-02-2010, 08:12 AM   #5
nkjha
Member
 
Registered: Apr 2008
Posts: 30

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by nkjha View Post
--

Actually I want to create a user for FTP Server which has no any privileges to access any things outside his home directory .

Thanks.
I am still waiting for this problem .
Is there anything wrong in my thread .


Thanks
 
Old 07-02-2010, 11:22 AM   #6
ordinary
Member
 
Registered: Apr 2007
Location: the Rocket City
Distribution: Debian, Ubuntu, CentOS; in days past Fedora, Solaris, SunOS, 4.2BSD, 4.3BSD, SVR4, AIX, HP-UX
Posts: 101

Rep: Reputation: Disabled
Quote:
Originally Posted by nkjha View Post
I am still waiting for this problem .
You may be waiting a while. This isn't paid tech support, it just folks generously giving their time and effort.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Create new account with root privileges? prasannasellam Linux - Newbie 2 01-21-2008 01:34 AM
fedora 7 user account problems on sighn in earlgray Fedora 1 05-17-2007 10:33 AM
Creating user account with no root privileges grob115 Linux - General 7 02-13-2007 04:43 AM
give account root privileges mgichoga Debian 3 08-08-2005 07:50 AM
user account for fedora core 3 lbotes Linux - Newbie 4 03-02-2005 01:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 08:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration