allow SFTP FTP but not SSH. Can ??

Alexander Dalloz ad+lists at uni-x.org
Tue May 3 12:51:09 UTC 2005


Am Di, den 03.05.2005 schrieb M E Fieu um 13:17:

> > If you want to allow certain users sftp only access
> > and not ssh or any
> > other service access you could change out the users
> > shell with the
> > sftp-server binary.  This will allow users to sftp
> > into the machine in
> > question, but allow them access to no other
> > services.
> 
> Sorry for my stupidness, could you explain what is
> mean by "change out the users shell with the
> sftp-server binary"??  Can provide a example if it is
> easy ?

/etc/passwd:

adalloz:x:500:500:Alexander Dalloz:/home/adalloz:/bin/bash

becomes by using "vipw" or "chsh":

adalloz:x:500:500:Alexander
Dalloz:/home/adalloz:/usr/libexec/openssh/sftp-server

(Not my recommendation, but what you ask as an explanation for.)

Alexander


-- 
Alexander Dalloz | Enger, Germany | GPG http://pgp.mit.edu 0xB366A773
legal statement: http://www.uni-x.org/legal.html
Fedora Core 2 GNU/Linux on Athlon with kernel 2.6.11-1.14_FC2smp 
Serendipity 14:49:36 up 22:55, 18 users, 0.13, 0.11, 0.09 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: Dies ist ein digital signierter Nachrichtenteil
URL: <http://listman.redhat.com/archives/fedora-list/attachments/20050503/f0e4965f/attachment-0001.sig>


More information about the fedora-list mailing list