SCPonly Problem

Thread Tools Search this Thread
Top Forums UNIX for Advanced & Expert Users SCPonly Problem
# 1  
Old 07-06-2011
SCPonly Problem

I am running apache server 2.2.14 on ubuntu server (Lucid 10.04). Users are not allowed to login locally or remotely through SSH to the server, however I would like users to be able to sftp to the server.

I thought of using “scponly” which will give users an alternative shell, the problem is that I have 3,000 which authenticate to LDAP.

As I cannot change their shell in LDAP I wrote a script to create /etc/passwd from ldap. Now I have 3,000 user's /etc/passwd in a file, I can change their shell in the file however how do I tell sftp to read the users shell from the file?

Basically, how do configure the server, so that the Shell is read from the file and at the same time users can authenticate to LDAP to use sftp?

Any suggestion of a better way to solve the problem?
Can you help? Please.
# 2  
Old 07-07-2011
usermod  -s /usr/local/bin/scponly [username]

This (/usr/local/bin/scponly) depends on where you already installed the scponly binaries.
In /etc/passwd the directory field is number 6.
# 3  
Old 07-15-2011
Thanks for your response

My question is do I lists all 3,000 users in /etc/passwd considering that users authenticate to LDAP?
How do I go about solving the problem? please
# 4  
Old 07-15-2011
Authentication is part of logging in and presenting credentials.

Who you are on the system is different. Without An entry in /etc/passwd, the user
will not have a uid, a gid, a home directory, or a default shell, for example.
Yes you need 3000 entries and any additions to /etc/group to support them.
You do not necessarily need 3000 login directories, depending on what the users are doing.
# 5  
Old 07-28-2011
I figure it out; I modified my /etc/ldap.conf to include the following:
“nss_override_attribute_value loginShell /usr/bin/scponly”
And all 3,000 users inherited the login shell “/usr/bin/scponly” on the machine.

The next problem is how do to I chroot 3,000 sftp users
According to the scponly documentation you will need to specify each user’s home directory to chroot
Unfortunately I have 3,000 different home directories in different directory structure like:

All users authenticate to LDAP
The openssh solution involves modifying /etc/ssh/sshd_config
# Use the following line to *replace* any existing 'Subsystem' line
Subsystem sftp internal-sftp

# These lines must appear at the *end* of sshd_config
Match Group sftponly
ChrootDirectory %h
ForceCommand internal-sftp
AllowTcpForwarding no

The problem with the above is how do I specify 3,000 LDAP users “ChrootDirectory” and also make all users a member of sftponly.

How do I chroot sftp, (all users) bearing in mind that all 3,000 users have different directory structure and all authenticate to LDAP?

Can you help or suggest a way to solve the problem? Please
# 6  
Old 07-28-2011
Could you match a particular group, maybe?
Login or Register to Ask a Question

Previous Thread | Next Thread

8 More Discussions You Might Find Interesting

1. UNIX for Dummies Questions & Answers

sed Or Grep Problem OR Terminal Problem?

I don't know if you guys get this problem sometimes at Terminal but I had been having this problem since yesterday :( Maybe I overdid the Terminal. Even the codes that used to work doesn't work anymore. Here is what 's happening: * I wanted to remove lines containing digits so I used this... (25 Replies)
Discussion started by: Nexeu
25 Replies

2. IP Networking

Problem with forwarding emails (SPF problem)

Hi, This is rather a question from a "user" than from a sys admin, but I think this forum is apropriate for the question. I have an adress with automatic email forwarding and for some senders (two hietherto), emails are bouncing. This has really created a lot of problems those two time so I... (0 Replies)
Discussion started by: carwe
0 Replies

3. AIX

AIX OS problem? network problem?

Dear ALL. I installed AIX OS on customer sites. but Only one site is too slow when I connected telnet, ftp.. Ping is too fast. but telnet and FTP is not connected.. of course i check the configuration file on aix but it's normal. Do any Idea?? thanks in advance. - Jun - (3 Replies)
Discussion started by: Jeon Jun Seok
3 Replies

4. UNIX for Dummies Questions & Answers

DHCP problem and eth1 problem

At work I am trying to get this one Linux machine (let's call it ctesgm07) to behave like another Linux machine that we have (let's call it test007). test007 returns the following version info: cat /etc/debian_version: lenny/sid uname -a: Linux test007 2.6.27-7-generic #1 SMP Tue Nov 4... (0 Replies)
Discussion started by: sllinux
0 Replies

5. Red Hat

Mail Problem. Maybe, it is a DNS Problem!

Hi, i've a redhat linux 9 upadated by redhat from 7 version to 9 version. A couple of days ago i was a problem with my mail, in other words i'm not able to get any email nor to send any email. I've a proxy configuration and i tried to set iptables in order to verify the port. The 110,255 and 995... (1 Reply)
Discussion started by: pintalgi
1 Replies

6. AIX

user login problem & Files listing problem.

1) when user login to the server the session got colosed. How will resolve? 2) While firing the command ls -l we are not able to see the any files in the director. but over all view the file system using the command df -g it is showing 91% used. what will be the problem? Thanks in advance. (1 Reply)
Discussion started by: pernasivam
1 Replies

7. Solaris

problem in finding a hardware problem

Hi I am right now facing a strange hardware problem. System get booted with the following error: Fatal Error Reset CPU 0000.0000.0000.0003 AFSR 0100.0000.0000.0000 SCE AFAR 0000.07c6.0000.1000 SC Alert: Host System has Reset It happen 4 or 5 times and get the same error every time.I... (8 Replies)
Discussion started by: girish.batra
8 Replies

8. Shell Programming and Scripting

ssh script problem problem

Hi Please help me with the following problem with my script. The following block of code is not repeating in the while loop and exiting after searching for first message. input_file ========== host001-01 host001-02 2008-07-23 13:02:04,651 ConnectionFactory - Setting session state... (2 Replies)
Discussion started by: pcjandyala
2 Replies
Login or Register to Ask a Question