Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Kerberized FTP, FTP TLS/SSL



For anyone who is interested in a good cross platform method for remote access, I've ended up doing this.

Installing my own version of openssh that includes the chroot patches.
http://chrootssh.sourceforge.net

I've changed the NFSHomeDirectory settings in the relevant mount points for my users to be like:
/Network/Servers/servername/Volumes/./SomeVolume/blah/blah/blah


This means they get chrooted at "/Volumes" on the server, thus disallowing them access to the system drive. This does not appear to pose any problems for network home directories, but this could be because all my students are on AFP home directories anyway.

I've also installed the scponly shell:
http://www.sublimation.org/scponly/
and set this to be the shell for the student users.

This means that they can only scp and sftp, and do not have a 'real' ssh account available to them.


I do realise that firstly a chroot is possible to break out of, but it's much more difficult without a real shell account, and secondly that scponly has had problems in the past. I still feel more comfortable doing this than any of the alternatives, as it lets my students use free SFTP software on any platform to have secure remote access.


I might write the instructions for doing this up and post them somewhere if anyone is interested.

nigel

--
Nigel Kersten				Systems Administrator
College of Fine Arts, UNSW 	Sydney, Australia.
CRICOS Provider Code: 		00098G

_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/macos-x-server/email@hidden

This email sent to email@hidden
References: 
 >Kerberized FTP, FTP TLS/SSL (From: nigel kersten <email@hidden>)
 >Re: Kerberized FTP, FTP TLS/SSL (From: Matt Richard <email@hidden>)
 >Re: Kerberized FTP, FTP TLS/SSL (From: nigel kersten <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.