Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: SFTP Jails Management?
PostPosted: Fri Jun 24, 2011 2:18 pm 
Offline
Senior Newbie

Joined: Thu Jun 23, 2011 12:57 pm
Posts: 19
I hope this is the right forum for this question btw. I wasn't sure because it is related to the web server site locations... Sorry if I posted this in the wrong place.

I am curious as to what sftp jail management methods everyone is using?

In other words my first thought right now is to create a shell script that jails my users for me. Does all the work.

The trouble is I have grew fond of the srv directory lately. I have all my sites in /srv/www/www.example.com. This makes backup a breeze. My first thought has been to jail users right in those directories... Here is the problem though.

Some users might have more than one site. So my solution was to create symlinks to www.example.com www.example2.com in their home folders. However I am not sure how to handle the jail if I do this. Wouldn't this break out of the jail? Inside each site folder I like to keep logs and public_html if it matters.

Also does anyone have any experience with RSSH? So my allowusers only allows me to access ssh on the server. Root obviously disabled. The trouble is some users I don't want to totally block. I would like to allow them to sftp in.
http://www.pizzashack.org/rssh/

Debian 6 squeeze fyi


Top
   
 Post subject:
PostPosted: Fri Jun 24, 2011 2:35 pm 
Offline
Senior Member

Joined: Sun Mar 07, 2010 7:47 pm
Posts: 1970
Website: http://www.rwky.net
Location: Earth
I just follow this http://library.linode.com/security/sftp-jails

_________________
Paid support
How to ask for help
1. Give details of your problem
2. Post any errors
3. Post relevant logs.
4. Don't hide details i.e. your domain, it just makes things harder
5. Be polite or you'll be eaten by a grue


Top
   
 Post subject:
PostPosted: Sat Jun 25, 2011 12:20 am 
Offline
Senior Member

Joined: Sat Jun 12, 2010 4:53 pm
Posts: 77
For this sort of thing yeah I've used rssh. Then they can only connect sftp and not ssh. Can't get an ssh shell, which could lead to security issues.


Top
   
 Post subject:
PostPosted: Mon Jun 27, 2011 10:26 am 
Offline
Senior Newbie

Joined: Thu Jun 23, 2011 12:57 pm
Posts: 19
Ended up shell scripting the process to ensure ssh is disabled etc. This seems to be working great. Thanks for the feedback.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group