[HPADM] Restricted SFTP without user being able to SSH into server.

From: James J. Perry (jjperry_at_water.com)
Date: 03/25/05

  • Next message: Neil Paniraj: "[HPADM] SUMMARY: I/O Time Out: PVDISPLAY Related."
    Date: Fri, 25 Mar 2005 14:33:56 -0500
    To: <hpux-admin@dutchworks.nl>
    
    

    We are migrating to servers where security policy dictates secure ftp
    sessions only. In the past we just used restricted FTP with the user's
    shell prompt set to /bin/false or /etc/ftponly.

     

    When I do an sftp to that server, I get a message "illegal user XYZ from
    ip ..." and the access is denied. When I set the shell to /bin/sh, I
    can sftp into the server, but it is not directory restricted to their
    home directory. Also, the user can use SSH to login to the server,
    which is most undesirable.

     

    I have dug around on man pages, Googled, and looked at OpenSSH.org, but
    cannot find out a way to configure the sshd or sftp to make sftp work
    like restricted FTP.

     

       Thanks

       -Jim

    --
                 ---> Please post QUESTIONS and SUMMARIES only!! <---
            To subscribe/unsubscribe to this list, contact majordomo@dutchworks.nl
           Name: hpux-admin@dutchworks.nl     Owner: owner-hpux-admin@dutchworks.nl
     
     Archives:  ftp.dutchworks.nl:/pub/digests/hpux-admin       (FTP, browse only)
                http://www.dutchworks.nl/htbin/hpsysadmin   (Web, browse & search)
    

  • Next message: Neil Paniraj: "[HPADM] SUMMARY: I/O Time Out: PVDISPLAY Related."

    Relevant Pages

    • Re: SPAM sudden increase
      ... > Dude was on a tech call with f-secure and the tech asked, "So, ... dude is trying to FTP to their server using WSFTP. ... but I think he is talking about sftp protocol - FTP via ...
      (alt.2600)
    • using java with sftp
      ... JCraft JSch package to SFTP files. ... //First Create a JSch session ... System.err.println("Unable to connect to FTP server. ...
      (comp.lang.java.programmer)
    • Re: using java with sftp
      ... JCraft JSch package to SFTP files. ... //First Create a JSch session ... System.err.println("Unable to connect to FTP server. ...
      (comp.lang.java.programmer)
    • Re: Pasting via ssh causes data loss
      ... sftp of the file to the remote and ... I then opened an ssh session to a FreeBSD ... errors shown on the interface of the server? ...
      (freebsd-questions)
    • Re: sftp password authentication question
      ... > I have a W2k server machine (equippend with SSH Secure Shell) which ... > NetworkSimplicity SSH server). ... > can be apparently easily accomplished with normal FTP. ... > this to work with SFTP or SFTP2 ??? ...
      (comp.security.ssh)