LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 03-27-2006, 09:07 AM   #1
OneEye
LQ Newbie
 
Registered: Mar 2006
Location: Valhalla
Distribution: fedora core 4
Posts: 3

Rep: Reputation: 0
Jailkit Problems


What I'm trying to do is chroot an sftp account and I can't seem to get it to work properly. My setup of the account is as follows.

/var/www/html/jail is my jail root and it has the following directories in it dev,etc,home,lib,usr,var xlan

The users jail area is /var/ww/html/jail/xlan


my /etc/passwd looks like.

jake6937:x:504:504::/var/www/html/jail/./xlan:/usr/sbin/jk_chrootsh

my /var/www/html/jail/etc/passwd looks like

root:x:0:0:root:/root:/bin/bash
jake6937:x:504:504::/xlan:/usr/sbin/jk_lsh

The service is running:

nobody 20458 0.0 0.0 1664 188 ? Ss Mar24 0:00 /usr/sbin/jk_so

But I get this error message when I try to connect

Mar 27 08:06:41 localhost sshd(pam_unix)[2724]: session opened for user jake6937 by (uid=0)
Mar 27 08:06:41 localhost jk_chrootsh[2725]: abort, path /var/www/html/jail/./xlan does not have group 504
Mar 27 08:06:41 localhost sshd(pam_unix)[2724]: session closed for user jake6937


At this point any comments or suggestions would be greatly appreciated.
 
Old 03-28-2006, 05:19 AM   #2
timmeke
Senior Member
 
Registered: Nov 2005
Location: Belgium
Distribution: Red Hat, Fedora
Posts: 1,515

Rep: Reputation: 61
Quote:
path /var/www/html/jail/./xlan does not have group 504
Can you do an "ls -l -d /var/www/html/jail/./xlan"?

Are you sure user jake6937 has access (at least execute) to all directories leading up to /var/www/html/jail/./xlan?
 
Old 03-30-2006, 02:35 PM   #3
OneEye
LQ Newbie
 
Registered: Mar 2006
Location: Valhalla
Distribution: fedora core 4
Posts: 3

Original Poster
Rep: Reputation: 0
I figured it out. I just had to to a chgrp 504 /var/www/html/jail/xlan to get it to work.


I'm comming across another problem now. I'm setting up a jail for a second user, I did the exact same thing but I'm getting this error.

Mar 30 13:18:28 localhost jk_chrootsh[14317]: now entering jail /var/www/html/jail for user cent241 (505)
Mar 30 13:18:28 localhost jk_chrootsh[14317]: abort, groupname cent241 differs from jail groupname cent6938 for group ID 505, check /etc/passwd and /var/www/html/jail/etc/passwd


I checked both those password files and the groupname and id are both cent241 and if: 505. I'm not sure what the problemo is here.
 
Old 03-31-2006, 01:44 AM   #4
timmeke
Senior Member
 
Registered: Nov 2005
Location: Belgium
Distribution: Red Hat, Fedora
Posts: 1,515

Rep: Reputation: 61
Please post all the groups (GID) involved:
-groups from both etc/passwd files and etc/group files
-group ownership of the jail directory
and see where they are inconsistent.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Marvell Yukon Network driver problems, Lilo Windows boot Problems mellowdog Slackware - Installation 7 01-25-2006 02:18 AM
jailkit issues mithereal Linux - Software 3 01-22-2006 05:06 AM
Ethernet Adsl Modem Driver Problems And Install Problems... akhilnair Linux - Hardware 12 11-28-2004 08:19 AM
Problems, problems, problems. Lets start with the soundcard Kre8ive Linux - Newbie 5 08-07-2003 01:20 AM
Problems, problems, problems. Lets start with the ES 1868 AudioDrive Kre8ive Linux - Newbie 1 08-06-2003 07:04 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 10:54 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration