Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 14 Aug 2015 14:06:25 +0100
From:      Matthew Seaman <matthew@freebsd.org>
To:        freebsd-current@freebsd.org
Subject:   Re: r286615: /usr/libexec/ftpd broken!
Message-ID:  <55CDE7D1.10607@freebsd.org>
In-Reply-To: <20150814134533.690e2091@freyja.zeit4.iv.bundesimmobilien.de>
References:  <20150811074041.6700e943@freyja.zeit4.iv.bundesimmobilien.de> <20150811104451.2031fff2@freyja.zeit4.iv.bundesimmobilien.de> <CABh_MKm9tD=Fa1MZTGLUkF=MF7y%2Bf8Oy6n3oy5Ty93pWrBohHA@mail.gmail.com> <20150814134533.690e2091@freyja.zeit4.iv.bundesimmobilien.de>

next in thread | previous in thread | raw e-mail | index | archive | help
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--mnXQAhBdbikvGBtuANNpjTHxLOLAAWVfa
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

On 08/14/15 12:45, O. Hartmann wrote:
> Man page "ftpusers(5)" states, that an entry "username allow" will allo=
w access
> to ftpd. But every user listed in /etc/ftpusers is denied access, no ma=
tter
> whether there is "allow" appended to the entry or not! This is strange.=

> Whenever I delete a user's name from that file I wish to have access to=
 the
> ftpd service, that user can login - but addig the users even as "userna=
me
> allow" (no * in the file, nothing else but the initial users names) acc=
ess is
> denied.

If you've got a ftpusers(5) that presumably comes from some ported
software -- doesn't exist in the base system.  There is pam_ftpusers(8)
in base, although that doesn't seem to be in use by default.

Traditionally 'ftpusers' was just a plain list of usernames or groups
(indicated by a leading '@' character).  According to ftpd(8) it lists
the people *not* allowed access via FTP.

However, other implementations of FTP servers have adopted the ftpusers
file and expanded its capabilities in various ways, by adding some
additional flag fields for each username.  It depends on what ftpd
you're using exactly what syntax is used there.  Properly ported
software should really be using /usr/local/etc/ftpusers though.

	Cheers,

	Matthew





--mnXQAhBdbikvGBtuANNpjTHxLOLAAWVfa
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJVzefRAAoJEABRPxDgqeTnTJgP/jIiEAaOrj7c4zk/CSkAwRIR
J8eOnD7UVVU+Zu7Niu8aRwRdVZRRQaozjvlIcUKNNIcj4//x78WlBSER6+xVnUAp
dCW3jAtNLxwpAHy5srpxW3JxXuJSEFY7yozgHPTQ7Ovzoj/jRm/7/ijO4wB0NWMV
NmjzvIyZK/EcvKIiTOf6RVEHt6g1nrmnrriI+wJOtQgWLG/IOhP8Ki4ocvxvpRaQ
pqfJtO/QUAXNiRwdmI4yEoOQJAicRGRxLwrqN9yeOT5cFH4lVw2D2u5ehaXaiP5r
TDZvkRlLJCh/Glgn4veI08xchohq07elpO2ptd7PGRtgZe/rloKL9ZeXZAsbkzis
BJX1HgatQtuaswo60v6gwFQnsriAevErW0ZTHJuWySR5+e6Bdcat7yw2STxS2BXU
/12hwpxrHO24cWM0FOkraUeD4pIcgLwi1ganoVcO6StOGwLYQYMFGZ2RsVKlwHs9
AwvezqQVOMhjyLw/85MrochN+O5bxQjOLIm7DiL9WNkjjKrVP0IBA3/C+N3+MRjG
EUrSUcKYgkREgI6S1eIGEOgYgqrlXH08lGclHURvNeBIOkltnrwoL24pzdelbpvl
D7OXugqY4sJsow4calZjQhU3+2XEc9QagmLmerqREWCX6JT98Jyea1moFlMFQlWP
Dft8ggFm/V1vf7aQtD9c
=IV5N
-----END PGP SIGNATURE-----

--mnXQAhBdbikvGBtuANNpjTHxLOLAAWVfa--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?55CDE7D1.10607>