Re: No shell scripts ...

From: Richard E. Silverman (slade@shore.net)
Date: 02/03/03


From: slade@shore.net (Richard E. Silverman)
Date: 03 Feb 2003 14:03:55 -0500


>>>>> "DE" == Darren <dledmonds@nospam-btopenworld.com> writes:

    DE> No, I don't want to say 'can log in', but perhaps 'can get a
    DE> shell' makes more sense. I want behaviour like sourceforge where
    DE> you get a ssh login to use with cvs, but if you do,

    DE> ssh cvs.sourceforge.net it acknowloges your attempt then boots you
    DE> out stating you are not allowed a shell.

This was not possible to infer from your post, since you said nothing
about wanting to do anything at all via SSH with the rejected accounts,
and your mention of /etc/nologin implied that you wanted to prevent
logins.

-- 
  Richard Silverman
  slade@shore.net


Relevant Pages

  • Re: CVS over ssh question
    ... Tom Maddox wrote: ... > has been put on me, namely that the remote developers not be allowed shell ... > access to the CVS machine, and I can't figure out a good way to accomplish ... > that while still allowing CVS access over ssh. ...
    (comp.os.linux.security)
  • CVS over ssh question
    ... our CVS repository securely over an encrypted connection, ... that while still allowing CVS access over ssh. ... I've tried using /bin/false as a shell as well as a simple text file ...
    (comp.os.linux.security)
  • Specify shell at ssh login, not appearing in w, who or last output
    ... I am having an unusual problem whereby if I specify the shell during ... an ssh login, I do not appear in the w, who or last output. ... I've tried this on Solaris 9 and Solaris 10, ... stable Ubuntu Server and the current stable Debian. ...
    (comp.security.ssh)
  • Re: CVS without a shell
    ... >my developers secure cvs access (via ssh). ... You'll need to set up a restricted shell. ... Good judgement comes with experience. ...
    (comp.security.ssh)
  • RE: Best methods for preventing SSH allowing FTP
    ... I used /usr/bin/passwd as the shell (users could ... On my primary mail and ftp machines, I no longer use the system passwd ... > For FTP accounts, we set the user's shell to /usr/local/bin/ftponly. ... > they'd get the "No SSH login allowed" message. ...
    (freebsd-isp)