LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 05-20-2010, 05:02 AM   #1
Kenichi Kato
Member
 
Registered: Jun 2007
Location: Asia
Distribution: Ubuntu, Fedora, CentOS & TCL
Posts: 62
Blog Entries: 1

Rep: Reputation: 16
Chroot SSH on CentOS 5


Hello,

I'm trying to jail a group of users (under sftp) to their home when they SSH/SFTP over to the server. I read somewhere I should add the following into the /etc/ssh/sshd_config but even after adding the first line, SSH couldn't start & error said bad configuration:

Match Group sftp
ChrootDirectory %h
ForceCommand internal-sftp
AllowTcpForwarding no

Can anyone help me? Appreciate it!!
 
Old 05-21-2010, 11:52 AM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
IIRC, CentOS 5 - which is of course based on RHEL5 - provides OpenSSH 4.3 in its standard repositories.

The features you are trying to use are not available until a later minor version of the OpenSSH 4.x branch (4.8, I think).
 
Old 05-21-2010, 04:32 PM   #3
alli_yas
Member
 
Registered: Apr 2010
Location: Johannesburg
Distribution: Fedora 14, RHEL 5.5, CentOS 5.5, Ubuntu 10.04
Posts: 559

Rep: Reputation: 92
Hi

anomie is correct - openssh as in RHEL 5 / CentOS 5 will not support it.

Depending on your application; in terms of what your users will be ftp'ing (and whether over the internet or not) you may want to consider "normal" FTP (vsftpd/proFTPd) - I have set up chroot jails in RHEL 5 with vsftpd; for users on my internal network (which is secured from threats via firewalls etc).
 
Old 05-22-2010, 07:25 AM   #4
Kenichi Kato
Member
 
Registered: Jun 2007
Location: Asia
Distribution: Ubuntu, Fedora, CentOS & TCL
Posts: 62

Original Poster
Blog Entries: 1

Rep: Reputation: 16
Thank you anomie & alli yas. Didn't know that about RHEL5

Great, that gives me another idea. I'll split into 2 hosts. Host 1 allows read/write by internal users (behind firewall) & another purely for downloading data (encrypted) over the internet. I'll cron those data in specified folder meant for access by members outside office.
 
Old 05-22-2010, 04:41 PM   #5
alli_yas
Member
 
Registered: Apr 2010
Location: Johannesburg
Distribution: Fedora 14, RHEL 5.5, CentOS 5.5, Ubuntu 10.04
Posts: 559

Rep: Reputation: 92
Hi Kenichi

Quote:
Host 1 allows read/write by internal users (behind firewall) & another purely for downloading data (encrypted) over the internet. I'll cron those data in specified folder meant for access by members outside office.
Hope that you mean separate machines though - if you're talking 2 VM's on the same machine I don't think that is a good idea security wise
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
named-checkzone not working on Centos 5.3 in chroot-ed enviroment? MheAd Linux - Software 2 03-29-2010 08:04 AM
CentOS BIND CHROOT problem. bentman78 Linux - Networking 3 04-30-2009 01:39 PM
Chroot SSH problem: ssh working, not SFTP & SCP. NaCo Linux - Security 3 02-01-2009 02:23 AM
chroot ssh maxy7710 Linux - Newbie 4 08-28-2008 10:51 AM
chroot ssh Manuel-H Slackware 3 09-15-2005 05:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 04:12 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration