OpenSSH & ChRoot

From: Richard Secor (rsecor_at_seqlogic.com)
Date: 05/20/05

  • Next message: Hicks,Rodger: "SCP fails with publickey"
    To: secureshell@securityfocus.com
    Date: Fri, 20 May 2005 15:15:31 -0400
    
    

    I've been using SSH 3.2.9.1 from ssh.org/ssh.com for quite awhile now.

    Since FreeBSD uses OpenSSH as part of the install I figured I might
    move over to it.

    However, it seems there may be some issues with what OpenSSH can or
    more accurately cannot do over what SSH 3.2.9.1 can/could do.

    With SSH I can do have a "ChRootUser" configuration line in my
    sshd2_config, however there does not seem to be an easy way of
    getting the same result from OpenSSH.

    Before I get asked why I would want this....
    I would like to give my customers the option of having Shell access
    to the server without having to "jail" everything.
    And I do not want them poking around (whether everything is tied up
    or not is not the issue, however, piece of mind is).

    I'm sure someone will try and explain to me why I don't need to
    ChRoot in SSH, but I want to do it, and with SSH I can. That should
    be enough to find out how to do it with OpenSSH (otherwise I'm stuck
    with SSH, until something comes along)

    As an additional note I'm a little reluctant to use the available
    openssh-chroot patch at sourceforge as it seems to implement some
    strange way of doing chroot "./../home/$USER" or something like that
    instead of just leaving "/home/$USER" and it using that for the chroot.

    Please make sure my E-Mail Address is in the To, CC or BCC field as I
    have not subscribed to the discussion list.

    Thanks,
    Richard Secor
    rsecor@seqlogic.com


  • Next message: Hicks,Rodger: "SCP fails with publickey"

    Relevant Pages

    • Re: trojaned SSHD ?
      ... I'd recommend moving to OpenSSH, which supports both ssh1 and ssh2 ... platforms, including Solaris. ... Information relevant to the installation of SSH on NCMIR systems. ... * Install Zlib 1.1.2 libraries, compiling from source, on Solaris and IRIX ...
      (Focus-SUN)
    • Re: SSH 3.0.2 wont install
      ... I have gotten openssh 3.1 to install and working ... Able to SSH in as any user from anyhere. ... # Kerberos TGT Passing only works with the AFS kaserver ...
      (comp.security.ssh)
    • Re: hacked
      ... > I HAD a RH6.2 firewall/ internet sharing pc that was hacked recently. ... > unnecessary processes were turned off leaving only ssh (openssh 1.2.2-6), ... install aptitude", and use aptitude for package management. ...
      (comp.security.ssh)
    • Re: OpenSSH CHROOT newbie
      ... >solution to keep users within a home directory. ... >Chroot plugin for SSH, but for the life of me I cannot figure out how to ... You then need to install a chroot cage in the "/./" ...
      (comp.security.ssh)
    • Re: Upgraded SSH Public Key Authorization on FC4 Not Working
      ... RY> It appeared that the default ssh that wsa installed by the FC4 ... I very much doubt the FC4 included OpenSSH ... RY> Since the FAQ pretty much dissed anything below version 2.20, ... the "better" software install at the current time was ...
      (comp.security.ssh)

  • Quantcast