Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

vsftpd: locking users to home directories using chroot_local_user

Posted on 2011-02-20
10
Medium Priority
?
830 Views
Last Modified: 2013-12-16
I'm trying to lock one specific user to their home directory.
I've googled the issue and read all the other posts, (http://www.experts-exchange.com/OS/Linux/Administration/Q_24193390.htm).

I've tried:
chroot_local_user=YES
# chroot_list_enable=YES
#chroot_list_file=/etc/vsftpd/chroot_list

I've tried:
chroot_local_user=NO
chroot_list_enable=YES
chroot_list_file=/etc/vsftpd/chroot_list
(with chroot_list having the name of the user I want to restrict)

And I've tried some other combinations.
My /home directory permissions are 2751.

What am I missing?

vsftpd.conf:
anonymous_enable=NO
local_enable=YES
write_enable=YES
local_umask=022
dirmessage_enable=YES
xferlog_enable=YES
connect_from_port_20=YES
xferlog_std_format=YES
chroot_local_user=YES
listen=YES
pam_service_name=vsftpd
userlist_enable=YES
tcp_wrappers=YES

Open in new window

0
Comment
Question by:indsupport
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
10 Comments
 
LVL 40

Expert Comment

by:omarfarid
ID: 34940291
did you follow the links

http://www.experts-exchange.com/OS/Linux/Q_23155804.html

and the example config file given?

See also

http://vsftpd.beasts.org/vsftpd_conf.html
0
 
LVL 40

Expert Comment

by:omarfarid
ID: 34940318
did you try to restart vsftpd ?
0
 

Author Comment

by:indsupport
ID: 34943295
Yes, I've already seen both of those links, and I restarted vsftpd after every config change I made.
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 
LVL 40

Expert Comment

by:omarfarid
ID: 34944168
can you post your config file?
0
 

Author Comment

by:indsupport
ID: 34944462
My config file is posted in the first post on this question.
0
 
LVL 40

Expert Comment

by:omarfarid
ID: 34944945
Are you sure that below lines are added to the config file? the posted config file doesn't contain them

chroot_local_user=NO
chroot_list_enable=YES
chroot_list_file=/etc/vsftpd/chroot_list
0
 

Author Comment

by:indsupport
ID: 34945291
In my original post, I stated that I tried different things:

I've tried:
chroot_local_user=YES
# chroot_list_enable=YES
#chroot_list_file=/etc/vsftpd/chroot_list

I've tried:
chroot_local_user=NO
chroot_list_enable=YES
chroot_list_file=/etc/vsftpd/chroot_list
(with chroot_list having the name of the user I want to restrict)

The version of my config file above shows the first iteration of these tries (chroot_local_user=YES).

Again, I really appreciate your time with this.  It is really baffling me.
0
 
LVL 2

Expert Comment

by:maxalarie
ID: 35084766
Whats the value of this option in vsftpd.conf: local_enable
0
 

Accepted Solution

by:
indsupport earned 0 total points
ID: 35202254
Still looking
0
 

Author Closing Comment

by:indsupport
ID: 35775534
No answer found
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction We as admins face situation where we need to redirect websites to another. This may be required as a part of an upgrade keeping the old URL but website should be served from new URL. This document would brief you on different ways ca…
Google Drive is extremely cheap offsite storage, and it's even possible to get extra storage for free for two years.  You can use the free account 15GB, and if you have an Android device..when you install Google Drive for the first time it will give…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Suggested Courses

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question