The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Dummies Questions & Answers
.
google unix.com



UNIX for Dummies Questions & Answers If you're not sure where to post a UNIX or Linux question, post it here. All UNIX and Linux newbies welcome !!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
restrict the user not to key in more than 50 chars injeti Shell Programming and Scripting 18 08-16-2008 11:06 AM
restrict the user not to key in more than 50 chars injeti UNIX for Advanced & Expert Users 1 08-14-2008 10:08 AM
Restrict FTP access to a single directory for only one user. santhoshkumar_d UNIX for Advanced & Expert Users 8 05-23-2008 08:08 AM
restrict a user to certain command vikas027 SUN Solaris 1 03-07-2008 09:52 AM
need to restrict user to his home dir lidram SUN Solaris 5 02-06-2008 11:03 AM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 08-24-2008
jim mcnamara jim mcnamara is offline Forum Staff  
...@...
  
 

Join Date: Feb 2004
Location: NM
Posts: 5,717
I too would like to know chroot will not work.
  #2 (permalink)  
Old 08-25-2008
itobenon itobenon is offline
Registered User
  
 

Join Date: Aug 2008
Posts: 5
I guess I should clarify some things...
when I said chroot wasn't an acceptable solution - I only meant by itself.

I do, in fact, use chroot; which limits the user ONLY to sftp.
In fact, my chroot jail, is about as lean as you can possibly have one. - the whole jail (excluding the home directory) contains only 20 files in total (~ 4M in size) - in only 3 directory's: /dev; /lib; and /usr (and /dev only contains null)

I guess in the ideal - if I could have a user chroot'd to their home directory (without the need for them to see those 3 directories), and if sftp existed in some "rsftp" version, where I could eliminate the 'cd' command (or restrict) it, and if I could have all of this in a form that's easy enough to delagate user maintenance, I would be perfectly happy.

It doesn't seem to me that, that's asking for alot...
I suppose the easy/delagate part may simply be me writing a bash script - I'm ok w/ that. But the rest seems to be very difficult to attain - which surprises me.
  #3 (permalink)  
Old 08-26-2008
era era is offline Forum Advisor  
Herder of Useless Cats (On Sabbatical)
  
 

Join Date: Mar 2008
Location: /there/is/only/bin/sh
Posts: 3,652
Isn't sftp basically just a wrapper for ssh? Then perhaps you could assign the users a custom shell which lacks or restricts the commands you find problematic.
  #4 (permalink)  
Old 08-26-2008
itobenon itobenon is offline
Registered User
  
 

Join Date: Aug 2008
Posts: 5
an interesting question...

I'm not sure that sftp is a wrapper, but I'm guessing it is not...

I make this statement based on the fact that my own chroot jail does not include ssh in it. The only "executable" in my jail is "sftp-server" (which is located under /usr/lib)

So I've always seen sftp as a separate app; I'm not sure if it does work thru ssh (even in a chroot jail)?

Anyone know if the command set can be limited somehow - either thru sftp itself or ssh (if that's the "mother app") ?
Closed Thread

Bookmarks

Tags
chroot, home, jail, rbash, rsh, rssh, sftp

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 06:36 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0