From owner-freebsd-questions@FreeBSD.ORG Sat Mar 14 01:12:15 2009 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3FE94106567E for ; Sat, 14 Mar 2009 01:12:15 +0000 (UTC) (envelope-from steve@ibctech.ca) Received: from ibctech.ca (v6.ibctech.ca [IPv6:2607:f118::b6]) by mx1.freebsd.org (Postfix) with SMTP id CF3758FC08 for ; Sat, 14 Mar 2009 01:12:14 +0000 (UTC) (envelope-from steve@ibctech.ca) Received: (qmail 84740 invoked by uid 89); 14 Mar 2009 01:16:32 -0000 Received: from unknown (HELO ?192.168.1.114?) (steve@ibctech.ca@::ffff:208.70.104.100) by pearl.ibctech.ca with ESMTPA; 14 Mar 2009 01:16:32 -0000 Message-ID: <49BB0467.6090606@ibctech.ca> Date: Fri, 13 Mar 2009 21:12:07 -0400 From: Steve Bertrand User-Agent: Thunderbird 2.0.0.17 (Windows/20080914) MIME-Version: 1.0 To: "freebsd-questions@freebsd.org Questions -" References: <49BB0161.3070800@ibctech.ca> In-Reply-To: <49BB0161.3070800@ibctech.ca> X-Enigmail-Version: 0.95.7 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Subject: Re: Execute and lock a user into a program upon login X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 14 Mar 2009 01:12:15 -0000 Steve Bertrand wrote: > Hi everyone, > > Although the application of my question focuses on network operation, I > believe that the objective fits this list. > > Mostly irrelevant, I have been working on securing my network perimeter. > I have a FreeBSD box that acts as a host-based BGP peer to all edge > connected routers. > > I use this host-based Quagga FBSD router to distribute routes that are > to be blackholed by the edge devices. > > What I want is to set up an environment so that when a specific user > logs in to the box via SSH, a command is run, and they immediately get > dropped into the environment that the command produces. > > When they exit this 'command', the login session is dropped. > > Essentially, I want to 'lock' a user into a program upon SSH login, and > drop them from the SSH session when the program terminates. > > In essence: > > - user 'router' connects via SSH > - user is dropped into the application 'vtysh' > - user performs operations > - user exits from program > - shell drops (ie. user does not have to exit the csh shell to drop the > SSH connection) I probably should have explicitly stated that I'd like help as to how I would go about doing what I want to do, instead of simply stating my goals ;) Steve