LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-04-2014, 03:01 AM   #1
gajanan
LQ Newbie
 
Registered: Oct 2006
Location: bangalore
Posts: 11

Rep: Reputation: 0
Give Access to user only on his home and /var/log/ directory


Hi All,

I have one local account created in my syslog server. My requirement is to allow user to login to system and access only his home directory and /var/log/syslog-ng/ directory. Except that he should not browse any other directories. Please suggest how this can be achieved.

Note: I do not want to use Jail and ACL here.

OS: redhat enterprise Linux 5.3 (64 bit).

Thank You
Gajanan Hegde
 
Old 08-04-2014, 05:52 AM   #2
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,627

Rep: Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695Reputation: 2695
limited access user

Why not use jail?
You need to provide more information:
1. What access do you want the user to have, really? You mention browse, are you talking sftp, ftp, http, or other access?
2. Does this user get a shell? (there are some nice sftp-only setups that jail a user without a true chroot jail)
3. Why the restriction re: not using ACL or jail? If we do not understand your restrictions, suggestions we make may not be appropriate.


My first approximate, lacking better information about your objective, would be to assume sftp only and point you at the recent ssh pages about how to accomplish this using the ssh conf files only. Then add the bind mount option to make that log folder appear to be RO mounted under the users home.

Last edited by wpeckham; 08-04-2014 at 05:53 AM.
 
Old 08-04-2014, 01:21 PM   #3
mboelen
LQ Newbie
 
Registered: Nov 2013
Location: The Netherlands
Distribution: Several ones for testing purposes
Posts: 15

Rep: Reputation: Disabled
Use a restricted shell (like with sftp). If you still want to use normal SSH access, then I would still opt for using file ACLs (as it is unclear why you prefer not to use it).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
if user can access /var/log from web interface, how bad can it be ? 5883 Linux - Security 4 06-23-2014 08:28 PM
setfacl to provide user access to /var/log does not work Curiosity42 Red Hat 19 02-16-2013 05:53 AM
How to give access to user only home directory through ssh? jeevar Linux - Newbie 1 08-06-2012 08:51 AM
convert LAN IP address to Host Name when I give cmd tail -f /var/log/squid/access.log rs15 Linux - Networking 6 01-22-2012 01:45 AM
How do I give access to an ftp user to the var/www/html dir shootinstr8 Linux - Newbie 1 10-13-2006 03:32 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:50 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration