How To Limit SFTP client's access?

From: Markus Karg (markus.karg_at_quipsy.de)
Date: 03/24/04

  • Next message: Burak Bilen: "Re: HowTo Disable execution of commands whit ssh and scp/sftp"
    To: <secureshell@securityfocus.com>
    Date: Wed, 24 Mar 2004 07:47:21 +0100
    
    

    I am using OpenSSH to allow SFTP access to our server. For I don't want
    everyone to see the complete directory structure (best would be, user can
    only see the structure inside his very own home directory and is not able to
    leave it to superdirs or siblingdirs), I am desperately seeking a method to
    limit navigation without the need to remove "o+r" rights on every file and
    directory of our server. Unfortunately I did not find that information in
    the OpenSSH documentation.

    Any idea welcome! :-)

    Markus

    ----- Original Message -----
    From: "Adam Shostack" <adam@homeport.org>
    To: "Darren Tucker" <dtucker@zip.com.au>
    Cc: <secureshell@securityfocus.com>
    Sent: Tuesday, March 23, 2004 4:05 AM
    Subject: Re: Strange SCP problem

    > On Tue, Mar 23, 2004 at 01:51:01PM +1100, Darren Tucker wrote:
    > | Adam Shostack wrote:
    > | >I'm having a problem where I can copy files from a server to my
    > | >laptop, but not the other way. It's not the scp failure listed in FAQ
    > | >2.9, that test works fine.
    > | >
    > | >When I attempt to do a copy, I see the "progress bar" go, the file is
    > | >created on the other side, and I get an eventual time-out.
    > |
    > | Maybe this?
    > | http://www.snailbook.com/faq/mtu-mismatch.auto.html
    >
    > Bing! Give the man a gold star!
    >
    > Any advice on path mtu discovery tools that let me set something
    > bigger than 576?
    >
    > Adam
    >
    >


  • Next message: Burak Bilen: "Re: HowTo Disable execution of commands whit ssh and scp/sftp"

    Relevant Pages

    • Announce: OpenSSH 4.2 released
      ... OpenSSH 4.2 has just been released. ... implementation and includes sftp client and server support. ...
      (SSH)
    • Re: GSSAPI SSH WIN 2003
      ... OpenSSH does not have this flexibility. ... server that does; it is one of the most long-standing inadequacies of most ... used publickey authentication, for the simple reasons that it's ... > group will get Service ticket for my HP-UX box. ...
      (comp.security.ssh)
    • Announce: OpenSSH 4.3 released
      ... OpenSSH 4.3 has just been released. ... implementation and includes sftp client and server support. ...
      (SSH)
    • =?Utf-8?Q?DC_hin=C3=BCber_nach_=C3=84nderung_von_Pri?= =?Utf-8?Q?vilegien_=28OpenSSH_auf_Ser
      ... Server, zusammen bilden die eine AD Domäne ab. ... Jetzt versuche ich OpenSSH auf beiden zum Laufen zu bekommen. ... dass der Local System Account unter Windows Server 2003 nicht ... GPOs, da unsere GPO zuerst zieht und damit die Benutzer, die in den o.g. ...
      (microsoft.public.de.german.windows.server.general)
    • RE: SecureID Question
      ... I used to work for RSA Security and built most of their "unsupported" Linux ... OpenSSH or the native Login is used. ... I did some work to integrate SecurID with OpenSSH for a couple of specific ... When I log into my openssh server I then try to ssh to a server from there ...
      (SSH)