<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Latest posts for the topic "在CentOS 6上設定SFTP Chroot Jail"]]></title>
		<link>https://forum.andowson.com/posts/list/16.page</link>
		<description><![CDATA[Latest messages posted in the topic "在CentOS 6上設定SFTP Chroot Jail"]]></description>
		<generator>JForum - http://www.jforum.net</generator>
			<item>
				<title>在CentOS 6上設定SFTP Chroot Jail</title>
				<description><![CDATA[ 自RHEL 6/CentOS 6開始，套件包含OpenSSH 5.3版本，可以不用重新編譯程式只要透過設定就可以限制SSH/SFTP連入的帳號存取的目錄。 
<br>
<br>
1.建立sftponly群組 
<br>
groupadd sftponly 
<br>
<br>
2.新建帳號test 
<br>
useradd -s /bin/false -G sftponly test 
<br>
passwd test 
<br>
chown root /home/test 
<br>
<br>
3.修改/etc/ssh/sshd_config設定(檔案尾端) 
<br>
[code]# override default of no subsystems 
<br>
#Subsystem sftp /usr/libexec/openssh/sftp-server 
<br>
Subsystem sftp internal-sftp 
<br>
<br>
# Example of overriding settings on a per-user basis 
<br>
#Match User anoncvs 
<br>
# X11Forwarding no 
<br>
# AllowTcpForwarding no 
<br>
# ForceCommand cvs server 
<br>
Match Group sftponly 
<br>
ChrootDirectory /home/%u 
<br>
X11Forwarding no 
<br>
AllowTCPForwarding no 
<br>
ForceCommand internal-sftp[/code] 
<br>
<br>
4.重啟SSHd服務 
<br>
service sshd restart 
<br>
<br>
5.測試 
<br>
使用FileZila Client連進去看看，確認可以登入，上傳/下載檔案。 
<br>
<br>
參考資料: 
<br>
http://www.thisisnotsupported.com/sftp-chrootjail-on-centos6/]]></description>
				<guid isPermaLink="true">https://forum.andowson.com/posts/preList/554/1147.page</guid>
				<link>https://forum.andowson.com/posts/preList/554/1147.page</link>
				<pubDate><![CDATA[Wed, 28 Sep 2011 00:11:38]]> GMT</pubDate>
				<author><![CDATA[ andowson]]></author>
			</item>
	</channel>
</rss>