Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 8 Dec 2000 16:37:08 -0600 (CST)
From:      "Nicolai L. Brown" <nbrown@iowaone.net>
To:        Bill Paul <wpaul@FreeBSD.ORG>
Cc:        <freebsd-questions@freebsd.org>
Subject:   Re: scp only
Message-ID:  <Pine.BSF.4.30.0012081625500.29163-100000@everest.iowaone.net>
In-Reply-To: <20001208202307.0CE0E37B401@hub.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help

On Fri, 8 Dec 2000, Bill Paul wrote:

> > Don't know if this is the best solution, but it will work.
>
> No it won't, monkeyboy. Even though the user doesn't have write access
> to the files, he still owns the directory in which they reside. All
> he has to do is FTP in and delete or rename them. Chown'ing the user's
> home directory, would prevent this, but it might screw up other things.

First of all, you flame me and you're wrong.  Second of all, I don't know
why someone would open FTP when they want people to use scp.  Having a bad
day?  Don't take it out on loyal FreeBSD users.

Also, if they chown'd the home directory, that would break qmail.

> I would set the user's shell to /bin/false instead. I'm not sure
> how sshd will react to this though.

No go.

What is the best solution?  As I said, my suggestion may not be the best
solution, but at least it works.  And, you haven't proven that you can
break it without enabling ftp for the user.

Nicolai

> -Bill



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.30.0012081625500.29163-100000>