Re: Need help securing SFTP inbound (virtual root equivalent)

From: JWL (janwillem.delange_at_nospam.tiscali.nl)
Date: 05/05/04

  • Next message: Timothy J. Bogart: "Re: Speed of an IBM ESS (shark) disk subsystem"
    Date: Wed, 5 May 2004 18:15:26 +0200
    
    

    "ron" <rarms@adelphia.net> schreef in bericht
    news:903c07a0.0405050546.167f8f1b@posting.google.com...
    > Installed Openssl and ssh and have setup public key authentication.
    > Looking to automate an inbound file transfer using SFTP. Everything
    > is working fine, however, I need to lock the user down to a specific
    > directory, basically a restricted user account, or virtual root.
    >
    > Does SCP/SFTP use ftp where I could setup anonymous ftp maybe. I
    > tried a restricted shell, but that broke the public key
    authentication
    > and this needs to be an automated process.
    >
    > Basically the other vendor needs to send a daily file, and I want to
    > make sure they can't run around on the system from the SFTP shell as
    > some directory permissions are open.
    >
    > Currently running AIX 5.2 with openssl 0.9.6m and openssh3.6.1p2_52
    > with all the native AIX utilities such as FTP. Can the equivalent
    of
    > virtural root be setup for sftp or do I need to load a third party
    ftp
    > utility or something to accomplish what I'd like.
    >
    > Thanks for your input,
    > Ron

    Ron,
    Use a SSH-agent (program that caches the key, recommended method) or a
    plaintext key or a passphraseless key (less secure) or trusted host
    authentication.
    Jan Willem


  • Next message: Timothy J. Bogart: "Re: Speed of an IBM ESS (shark) disk subsystem"

    Relevant Pages

    • Re: Need help securing SFTP inbound (virtual root equivalent)
      ... "ron" schreef in bericht ... > Installed Openssl and ssh and have setup public key authentication. ... > Looking to automate an inbound file transfer using SFTP. ... > Does SCP/SFTP use ftp where I could setup anonymous ftp maybe. ...
      (comp.unix.aix)
    • RE: [fw-wiz] Locking down public wireless access
      ... The authentication is web-based using https. ... We don't encrypt anything because we didn't feel that protecting the ... Current problems with unrestricted access ... floating on the net about how to achieve this sort of setup, ...
      (Firewall-Wizards)
    • Re: Secure Server & Services
      ... You can setup a proxy and configure it to allow only ... authenticated users (Integrated authentication) to have access to the ... In this case if users are loged on to their computers as members ... of domain they will not be allowed access to the internet... ...
      (microsoft.public.windows.server.security)
    • Re: MOSS Hosting
      ... our setup is configured at the moment is that we configure their top ... problem as I see it is that the dedicated service is in our hosting AD ... MOSS server in our hosting domain. ... there someway this can be done using forms based authentication and ...
      (microsoft.public.sharepoint.portalserver)
    • Re: FL--Haleighs Dad & Misty getting married
      ... My thoughts as well about a possible setup. ... While I would prefer to think that neither Ronald nor Misty had any ... It's as if the Cummings family (Ron, grandma and great grandma) are having ... what media events can we engage in that would garner sympathy for Ron/Misty. ...
      (alt.true-crime)