Solved

Restricting user to home directory when using SFTP

Posted on 2004-09-10
8
1,555 Views
Last Modified: 2013-12-27
I have SSH working on server and using WINSCP on XP as a GUI secure ftp utility. Want to be able to set up a login name that cannot be used as a normal login (ie no shell) but want that user to be used for sftp. However, the user should not be able to navigate away from his home directory on the server for file transfers. Server is Solaris 8

Thanks
0
Comment
Question by:cjshepherd
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
  • +1
8 Comments
 
LVL 18

Expert Comment

by:liddler
ID: 12026975
There is a chroot patch for ssh, but it's not supported by Openssh team, take a look at http://www.google.com/search?q=chroot+sftp
There is also rssh - http://sourceforge.net/projects/rssh/
0
 

Author Comment

by:cjshepherd
ID: 12027569
Don't really want to put an unsupported patch on.

Downloaded and compiled rssh. Used that as the ftp users "shell" in /etc/passwd but get a message
"unable to initialise SFTP" when I try to use sftp.

Could not find much documentation on the usage of rssh - am I doing something wrong?
0
 
LVL 18

Expert Comment

by:liddler
ID: 12028084
hmm, did this once, but it was a long time ago, looking at the script, I used scp rather than sftp, maybe I couldn't get that to work..?
0
Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

 
LVL 38

Expert Comment

by:yuzh
ID: 12040693
0
 

Author Comment

by:cjshepherd
ID: 12054349
scponly - not on-site at present but tried this last week but got errors when I tried to compileit - found error or line 3 or 5

chroot - loks as if this replaces the OpenSSH which I don't reallt want to do. Also looks as if its all or nothing ie all ssh shels will be restricted

rksh - had already set this up but does not work with sftp
0
 
LVL 38

Expert Comment

by:yuzh
ID: 12060909
>>>scponly - not on-site at present but tried this last week but got errors when I tried to compileit - found error or line 3 or 5.

Do you have a working C complier installed on your system (eg, GNU gcc  etc), if not
you can download it from:
http://sunfreeware.com/

If you are sure that you C compiler is ok then, you can send an email to scponly
mail-list to see if you can get a patch to fix it.

also have a look at:

https://lists.ccs.neu.edu/pipermail/scponly/2002-November/000160.html

Good luck!
0
 
LVL 1

Accepted Solution

by:
Computer101 earned 0 total points
ID: 12393296
PAQed - no points refunded (of 125)

Computer101
E-E Admin
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

My previous tech tip, Installing the Solaris OS From the Flash Archive On a Tape (http://www.experts-exchange.com/articles/OS/Unix/Solaris/Installing-the-Solaris-OS-From-the-Flash-Archive-on-a-Tape.html), discussed installing the Solaris Operating S…
Java performance on Solaris - Managing CPUs There are various resource controls in operating system which directly/indirectly influence the performance of application. one of the most important resource controls is "CPU".   In a multithreaded…
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
This video shows how to set up a shell script to accept a positional parameter when called, pass that to a SQL script, accept the output from the statement back and then manipulate it in the Shell.
Suggested Courses

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question