LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-09-2006, 07:57 PM   #1
matthew.collins
LQ Newbie
 
Registered: Mar 2004
Location: Sydney
Distribution: Slackware, Fedora
Posts: 10

Rep: Reputation: 0
How to Create an Account with only SSH Access


Hello,

Sorry for the complete newbie question but...

I have a Windows 2003 Domain with a SME linux box running as my gateway. I can SSH into the SME box and then RDP into my desktop at work; using the root account on the SME box.

I'd like to set this kind of access up for some of the executives at place of work, but dont want them logging in with the root account. Can someone please send me a quick how-to for setting up an account on the SME box that only has SSH access and can't modify or change anything on the it?

Any help would be much appreciated!

Thanks,

Matthew Collins
 
Old 03-09-2006, 08:13 PM   #2
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
It sounds like you just want to add an ordinary user to the Linux box. Have you tried the useradd tool (it creates a user based on the command line parameters you give it) or the adduser tool (it creates a user based on the answers you give to its prompts)?

In either case an ordinary user is limited in what they can change or access on the box. I'd recommend that you don't use root to login to the SSH server either. Just su when you need to perform administrative tasks.
 
Old 03-09-2006, 08:15 PM   #3
matthew.collins
LQ Newbie
 
Registered: Mar 2004
Location: Sydney
Distribution: Slackware, Fedora
Posts: 10

Original Poster
Rep: Reputation: 0
Gilead,

Thanks...You sure just adding a user using useradd will not give them too much permission on the box? I figured there'd be some way of locking it down more.

Matthew Collins
 
Old 03-09-2006, 08:27 PM   #4
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
Usually that's fine Matthew. With default permissions they can't delete system configuration files or application programs and they can't see inside system logs. They can delete their own stuff in their home directory, but that sort of thing can be retrieved from backups.

Unix system are designed for multiple users so you can be pretty confident. Just don't give them the root account's password
 
Old 03-09-2006, 08:30 PM   #5
matthew.collins
LQ Newbie
 
Registered: Mar 2004
Location: Sydney
Distribution: Slackware, Fedora
Posts: 10

Original Poster
Rep: Reputation: 0
Steve,

Thank you... I'll keep the root password in a safe spot

Matthew Collins
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to create a root account avimd Ubuntu 5 10-09-2005 08:10 AM
Create FTP account Swakoo Linux - Newbie 1 06-13-2005 06:16 AM
cannot create new user account kpachopoulos Linux - Newbie 4 08-17-2004 07:38 AM
How do I create new account for my linux box jbeedham Mandriva 10 08-22-2003 08:22 AM
limit directory access for ssh account spammity Linux - Security 2 02-02-2003 12:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:27 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration