Force restrict command on all users except those in a group?

From: Finlay Dobbie (finlay_at_mysurname.net)
Date: 01/23/05

  • Next message: Finlay Dobbie: "Re: Force restrict command on all users except those in a group?"
    Date: Sun, 23 Jan 2005 22:30:30 +0000
    
    

    I have 3 servers, and I'm trying to centralise their user databases into
    LDAP.

    On server 1, only users in the administrative group should be able to
    get a shell. Everyone else should be restricted to sftp.
    On server 2, only users in the administrative group should be able to
    get a shell. Everyone else should be restricted to cvs.
    On server 3, anyone should be allowed to get a shell.

    What is the easiest way of doing this? Currently there are horrible
    scripts set up to restrict people, generating lots of
    .ssh/authorized_keys files and rsync'ing them about... I'd much rather
    delegate this information into the directory somehow.

      -- Finlay


  • Next message: Finlay Dobbie: "Re: Force restrict command on all users except those in a group?"

    Relevant Pages

    • Re: How to specify an exchange 2003 as remote bridgehead?
      ... We are also planning a year to go to Exchange 2007. ... I think with an administrative group with only RGs, ... Exchange server to their own RG. ... In the Routing Groups container, ...
      (microsoft.public.exchange.admin)
    • Re: I think I messed up big time... v.Delete Administrative Groups
      ... re-installation where it has automatically detected that the server ... existed and is not allowing me to change the Administrative Group. ... should I proceed with the install, put it back as it was, then attempt ... James Chong wrote: ...
      (microsoft.public.exchange.admin)
    • Re: Renaming an Administrative Group?
      ... The KB also says shows you how to bring the server back into a supported state, ... Although this change appears to be merely cosmetic there are dependencies on the Administrative Group name. ... Please do not send email directly to this alias. ... Administrative Group names in Exchange Server 2003 or in Exchange 2000 ...
      (microsoft.public.exchange.admin)
    • Re: ADC removal from administrative group in a multi-administrative group organization
      ... I shutdown the 5.5 server to test mail flow without the 5.5 server ... was able to send email to the other administrative group but the user ... > You can remove the ADC now. ... >>organization in Exchange. ...
      (microsoft.public.exchange.admin)
    • Re: ADC removal from administrative group in a multi-administrative group organization
      ... >I shutdown the 5.5 server to test mail flow without the 5.5 server ... >was able to send email to the other administrative group but the user ... >>>I have a question on when to remove the ADC in a mixed environement. ... >>>organization in Exchange. ...
      (microsoft.public.exchange.admin)