LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-03-2006, 10:59 AM   #1
rob_xx17
Member
 
Registered: Jan 2004
Location: USA
Distribution: SuSE
Posts: 54

Rep: Reputation: 15
restricting user access with ssh


Hey

I'm running SuSE 9.3 as a file server on the Internet. I want users to be able to securely login and deposit/retrieve files. But I don't want them to see other users' files. Also I don't want them to wander around the file system / I want the server to be secure. I know that I could 'jail' the home directory. But I'm having so much problems with it. SSH works fine but I created a new directory with 'bash' and all the required libraries and bash works fine but when I tried to put 'ssh' into that directory and it's not working. I got the following error message: "PRNG is not seeded".

Also, I'm not really sure if the 'passwd' and 'shadow' files are to be located inside the jail or can they be located outside of the jail. When I put them (with the appropriate entries only for the users that I want to access remotely) inside the jail, that user cannot login.

I tried to bind the user to different shells (rsh, rbash, false) but with no success. I also tried restricting user access by changing the properties of a directory (drwxr-xr-- 6 root root 144 2006-01-03 10:04 ..) but that failed as well.

Does anybody know of a simpler method of restricting a user to only a single directory? All I want the user to be able to do is to deposit and retrieve files. Thanks a million for your help.

r.
 
Old 01-03-2006, 11:28 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Google for Scponly or Rssh. Both provide (at least) scp/sftp functionality and can chroot a user.
 
Old 01-05-2006, 03:47 PM   #3
rob_xx17
Member
 
Registered: Jan 2004
Location: USA
Distribution: SuSE
Posts: 54

Original Poster
Rep: Reputation: 15
thanks. I'm trying to get the 'rssh' working. But I'm having a tremendous problems with setting up the jail. I did everything that was suggested in the chroot manual for rssh but when I'm trying to connect to the account I get the 'connection closed' message. I know that I must have the jail not set up properfly because when I comment out the like setting up the chroot in the 'rssh.conf' file then I CAN log in. The problem is that, in such a case, the account is not jailed; it's not limited to the jail.
 
Old 01-05-2006, 03:55 PM   #4
benjithegreat98
Senior Member
 
Registered: Dec 2003
Location: Shelbyville, TN, USA
Distribution: Fedora Core, CentOS
Posts: 1,019

Rep: Reputation: 45
There is something else you could look into, which is 'rbash' or 'bash -r'. You might want to google that and see if it something you are looking for.
 
Old 01-05-2006, 06:22 PM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
If you installed rssh-2.3.0 look in the docdir for the CHROOT doc and read the first 20 lines about "Connection closed" and the need for the systems shell because of wordexp().
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Restricting SSH access by IP sooner5150 Linux - Security 3 11-18-2004 11:09 AM
User Group for Restricting Internet Access kyleinc Linux - General 6 04-17-2004 05:49 AM
Restricting SSH Access ErocM Linux - Security 4 02-20-2004 10:52 AM
ssh access allowed only to root user? zovres Linux - Newbie 5 09-25-2003 04:19 PM
SSH user IP restricted access??? ifm Linux - Security 3 07-21-2002 11:01 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration