LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-26-2011, 11:58 PM   #1
fjkum
Member
 
Registered: Feb 2006
Posts: 40

Rep: Reputation: 15
How to restrict permission to ssh user


Hi,

I would like to allow a user to login through SSH but with different permission coming from different ipaddress.

For example, a user "tester" login to SSH through 192.168.1.1 and another user login with the same login id "tester" but from different ip 192.168.1.2.

How do I restrict 192.168.1.2 to only allow for viewing the content in the home directory while giving 192.168.1.1 full access?
 
Old 01-27-2011, 08:56 AM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
With the OpenSSH Match and ChrootDirectory directives. Match is able to recognize IP address (and several other pattern types). Please see the manpages for sshd_config(5).
 
1 members found this post helpful.
Old 01-27-2011, 11:22 PM   #3
fjkum
Member
 
Registered: Feb 2006
Posts: 40

Original Poster
Rep: Reputation: 15
Thanks! But I don't see Match directives in the help.
 
Old 01-27-2011, 11:28 PM   #4
lazydog
Senior Member
 
Registered: Dec 2003
Location: The Key Stone State
Distribution: CentOS Sabayon and now Gentoo
Posts: 1,249
Blog Entries: 3

Rep: Reputation: 194Reputation: 194
Why not just give everyone their own accounts and adjust as needed there.
It is never a good idea to share any login accounts.
 
1 members found this post helpful.
Old 01-28-2011, 10:37 AM   #5
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Quote:
Originally Posted by fjkum
Thanks! But I don't see Match directives in the help.
Which help would that be? And what OS/version is your question regarding? Match is a relatively* new-ish OpenSSH feature.

---

* It's not really that new. But certain highly conservative/stable OSes haven't incorporated it into their repositories yet.
 
Old 01-28-2011, 12:35 PM   #6
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by lazydog View Post
Why not just give everyone their own accounts and adjust as needed there.
It is never a good idea to share any login accounts.
^^^ Good points!
 
Old 01-30-2011, 12:16 AM   #7
fjkum
Member
 
Registered: Feb 2006
Posts: 40

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by anomie View Post
Which help would that be? And what OS/version is your question regarding? Match is a relatively* new-ish OpenSSH feature.

---

* It's not really that new. But certain highly conservative/stable OSes haven't incorporated it into their repositories yet.
I'm using CentOS 5.5.
Which version of SSH has this feature included?
 
Old 01-30-2011, 12:23 AM   #8
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Quote:
Originally Posted by fjkum
I'm using CentOS 5.5.
Which version of SSH has this feature included?
Your question (and more) answered here:
http://www.linuxquestions.org/questi...on-rhel5-3495/

If you want a chrooted shell rather than just chrooted sftp, you'll need to do some additional research (i.e. it's more work).
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
h t restrict user permission? abdoullah Linux - Newbie 8 06-14-2010 09:11 AM
restrict ssh users to single user group winkydo Ubuntu 2 02-25-2008 11:07 AM
Restrict SSH to Group & User Hammad101 Linux - Security 2 10-16-2007 08:12 AM
restrict ssh logins by ip by user account Beans0063 Linux - Security 4 10-04-2004 01:29 PM
How to restrict the ssh operation for one user fidelis Linux - Security 2 09-13-2004 02:37 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:28 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration