Unix Technical Forum

Restricting ftp access

This is a discussion on Restricting ftp access within the AIX Operating System forums, part of the Unix Operating Systems category; --> Can anyone tell me (or point me to a how-to resource) how to restrict users to their home directory ...


Go Back   Unix Technical Forum > Unix Operating Systems > AIX Operating System

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-05-2008, 10:48 AM
Andy Luddy
 
Posts: n/a
Default Restricting ftp access

Can anyone tell me (or point me to a how-to resource) how to restrict
users to their home directory when they connect via ftp under AIX? A
whole bunch of web searches have made it clear that it is done using
chroot, but none of them explained how.

--
Andy Luddy
Perform appendectomy to reply
aluddy.appendix@adelphia.net
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 01-05-2008, 10:48 AM
base60
 
Posts: n/a
Default Re: Restricting ftp access

Andy Luddy wrote:
> Can anyone tell me (or point me to a how-to resource) how to restrict
> users to their home directory when they connect via ftp under AIX? A
> whole bunch of web searches have made it clear that it is done using
> chroot, but none of them explained how.


You can't do this with the ftpd supplied with AIX (I'm not sure about
5.3).

There a number of daemons which will do this, the most notable is
probably wu-ftpd.

http://www.wu-ftpd.org/

Note that you have to apply several security patches to the source.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 01-05-2008, 10:48 AM
Andy Luddy
 
Posts: n/a
Default Re: Restricting ftp access

base60 wrote:
> Andy Luddy wrote:
>> Can anyone tell me (or point me to a how-to resource) how to restrict
>> users to their home directory when they connect via ftp under AIX? A
>> whole bunch of web searches have made it clear that it is done using
>> chroot, but none of them explained how.

>
> You can't do this with the ftpd supplied with AIX (I'm not sure about
> 5.3).
>
> There a number of daemons which will do this, the most notable is
> probably wu-ftpd.
>
> http://www.wu-ftpd.org/
>
> Note that you have to apply several security patches to the source.


OK, thanks. I may look into that.

--
Andy Luddy
Perform appendectomy to reply
aluddy.appendix@adelphia.net
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 01-05-2008, 10:48 AM
steven_nospam at Yahoo! Canada
 
Posts: n/a
Default Re: Restricting ftp access


Andy Luddy wrote:
> Can anyone tell me (or point me to a how-to resource) how to restrict
> users to their home directory when they connect via ftp under AIX? A
> whole bunch of web searches have made it clear that it is done using
> chroot, but none of them explained how.


Hi Andy,

I had loads of "fun" trying to get this to work so that I had a
standard user with a dedicated password to log in to a simulated root
directory and not let them go up any levels. The default ftp services
that come with AIX can do this only for anonymous users, as best as I
can tell, and with anonymous the password contains the email address of
the user logging on. Depending on if you verify that email or not, it
could just let a person connect and upload or download at will.

As another poster replied to you, the wu/ftpd seems to be the one that
is easiest to set up, and is the one I finally chose for the special
login I needed for a supplier to reach our system.

If I get a chance to capture and "de-sensitize" our /etc files, I'll
post what we ended up with as a solution.

Steve

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 01-05-2008, 10:48 AM
Joachim Gann
 
Posts: n/a
Default Re: Restricting ftp access


base60 wrote:

> Andy Luddy wrote:
> > Can anyone tell me (or point me to a how-to resource) how to restrict
> > users to their home directory when they connect via ftp under AIX? A
> > whole bunch of web searches have made it clear that it is done using
> > chroot, but none of them explained how.

>

....
> There a number of daemons which will do this, the most notable is
> probably wu-ftpd.


I find proftpd very convenient. It doesn't requre setting up chroot
jails to restrict directory access. It's configuration resembles
apache.

There is an older release of proftpd in the IBM AIX toolbox.
current release is on http://www.proftpd.org

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 07:37 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com