SFTP and umask and enhanced security (only using shadow passwords)

From: Garsha, Adam (adam.garsha_at_marquette.edu)
Date: 07/25/05

  • Next message: Garsha, Adam: "SUMMARY: SFTP and umask and enhanced security (only using shadow passwords)"
    Date: Mon, 25 Jul 2005 11:59:05 -0500
    To: tru64-unix-managers@ornl.gov
    
    

    After moving to use shadow passwords, our sftp users now end up creating
    files with mode -rw------- (600).

    When users actually log in via ssh and create files locally, the files
    are instead -rw-r--r-- (644); this also used to be true for sftp prior
    to using shadow passwords.

    In /etc/profile the umask is set to 022. So, my working theory is that
    enhanced security changed the default umask from 022 to 077 and that
    sftp does not run commands in /etc/profile.

    1.) What do you think about this theory.
    2.) Do you know a way to force the sshd daemon to make sftp use a
    certain umask and/or run /etc/profile?
    3.) Do you know a reasonable way to change the default system umask to
    022?

    Adam Garsha
    Systems Engineer
    Marquette University IT Services
    414-288-3750 (Office)
    414-235-0112 (Cell)
    adam.garsha@marquette.edu


  • Next message: Garsha, Adam: "SUMMARY: SFTP and umask and enhanced security (only using shadow passwords)"

    Relevant Pages

    • Re: sftp file transfer log
      ... openssh does not support sftp transfer logging. ... > Do you know how to turn on SFTP file transfer log? ... environment to the sftp-server subsystem. ... log("setting file creation mode to 0666 and umask to %o", ...
      (comp.security.ssh)
    • SUMMARY: SFTP and umask and enhanced security (only using shadow passwords)
      ... After moving to use shadow passwords, our sftp users now end up creating ... In /etc/profile the umask is set to 022. ... Enhanced security changes the default umask to 077 ...
      (Tru64-UNIX-Managers)
    • Re: SFTP and umask
      ... Did you get any solution on changing the umask for files you are ... Drew Boone wrote: ... The umask for sftp on my server appears to be 066, ... to uninstall and compile OpenSSH myself. ...
      (SSH)
    • openssh: Default umask for SFTP?
      ... openssh package is currently openssh-3.9p1-8.RHEL4.15. ... The issue is that when I SFTP a file onto the server, the default umask ...
      (SSH)