LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 01-03-2018, 11:17 PM   #1
jfabiani
Member
 
Registered: Apr 2003
Location: Woodland, CA
Distribution: RH 8.0
Posts: 33

Rep: Reputation: 15
different security requirements for vsftp users


I have installed vsftp (opensuse 42.3) and it is working and I created a self signed cert for the ftp site. So SSL is working. The problem is that a second user is required to use the same ftp but without using the SSL cert. IOW they want to use the site without SSL. The reason for this is that they are using a software program that includes a way to access an ftp site but it has no way to deal with SSL. I guess it's old. Is it possible to have different security for different users?

BTW I'm not a vsftp guru so please explain carefully.

Thanks in advance.
 
Old 01-05-2018, 11:51 AM   #2
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
Before going down this road you might want to examine security requirements for you organization. If you take credit cards in the US you have to be PCI compliant. Also you might have Sarbanes Oxley (SOX) requirements or others depending on what your organization does. Many of these specifically prohibit use of ftp without ssl so you have to do at least ftps. (Better yet just do sftp and show other organizations how to use WinSCP from their lame Windows systems.) We recently completely disabled inbound ftp for compliance reasons here.

Even if you're not in the U.S. their might be other requirements in you country.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
vsftp - some users see files, some don't, but all users are in same group anon091 Linux - Newbie 10 01-18-2010 07:41 PM
VSFTP Users daveginorge Linux - Server 6 10-18-2008 04:18 AM
vsftp security steinz Linux - Software 1 12-01-2007 06:15 AM
VSFTP Virtual users Rage79 Linux - Security 7 01-10-2005 06:57 AM
todays requirements regarding security (not limited to linux security) markus1982 Linux - Security 8 04-25-2004 10:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 02:02 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration