Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Jailed ssh in vesta

General questions about VestaCP
Post Reply
  • Print view
Advanced search
9 posts • Page 1 of 1
Arash
Posts: 6
Joined: Mon Jun 01, 2015 5:19 pm

Jailed ssh in vesta
  • Quote

Post by Arash » Thu Jun 04, 2015 8:33 am

Hello
i want to give the user jailed ssh for git python and ruby commands
what can i do ?
Top

fsoyer
Posts: 14
Joined: Tue May 26, 2015 12:24 pm

Re: Jailed ssh in vesta
  • Quote

Post by fsoyer » Fri Jun 05, 2015 8:24 am

Hi,
I'm also searching for something like that. I have definitely stopped FTP on my servers (unsecure, obsolete, and so so so on), and my users transfer files in SFTP (via SSH port). All tools and frameworks actually know SFTP.
Another reason is that FTP (passive mode) is too boring to open behind firewalls. I'll never open dozen of ports because a protocol is not able to use one unique. FTPS isn't an alternative, for this same reason. You'll say "active mode", but no, FTP is dead, RIP, and look ahead.

But, for some users, it's a problem to be able to navigate in the whole tree, and see other directories next to them (not a problem for the users, rather a problem for the admin ;) ) The chroot feature of sftp (like for ssh) implies to make root as owner of the chroot tree... Impossible.

I know, also, that a file manager is coming, it's a good news, but also not matching some users constraints (using the ability of some frameworks of sending files directly to the server, without an external tool, for example, need FTP - sorry : SFTP).

Anybody's seeing a solution ?
Top

Arash
Posts: 6
Joined: Mon Jun 01, 2015 5:19 pm

Re: Jailed ssh in vesta
  • Quote

Post by Arash » Fri Jun 05, 2015 2:25 pm

before i migrate to vestacp i was using ispconfig
with ispconfig i set up a jailed env and users can easily connect to ssh and run git command inside that
i migrate to vestacp only for users mapping /home/$username/{web,tmp} and so on
now its not secure to give user the bash or rbash .
i want to use jailkit and i want to know how can i deploy jailkit with this user instructure
anyone can help me to fix this and then run gunicorn and unicorn or puma in vesta all my problems will be gone
and i never use ispconfig again :)
Top

fsoyer
Posts: 14
Joined: Tue May 26, 2015 12:24 pm

Re: Jailed ssh in vesta
  • Quote

Post by fsoyer » Wed Jun 10, 2015 4:07 pm

Hi Arash,
well, I didn't know jailkit. I'll try to implement it and do report here.
Top

Arash
Posts: 6
Joined: Mon Jun 01, 2015 5:19 pm

Re: Jailed ssh in vesta
  • Quote

Post by Arash » Wed Jun 24, 2015 12:17 pm

fsoyer wrote:Hi Arash,
well, I didn't know jailkit. I'll try to implement it and do report here.
I tried before but i cant complete the jailed so i give up but i think if we analyse ispconfig that how do this with mysql then we can complete the vesta :)
Top

donat
Posts: 39
Joined: Thu Jul 30, 2015 1:42 pm

Re: Jailed ssh in vesta
  • Quote

Post by donat » Tue Aug 04, 2015 7:03 am

Hi,

Are there any news on this? I'm interested in the solution with jailkit.

Donat
Top

Felix
Posts: 134
Joined: Tue Aug 04, 2015 7:15 pm

Os: Ubuntu 15x
Web: apache + nginx
Re: Jailed ssh in vesta
  • Quote

Post by Felix » Thu Aug 06, 2015 4:30 pm

I'm interested for something like that too. Giving chrooted access to users is really useful!
Top

skurudo
VestaCP Team
Posts: 8099
Joined: Fri Dec 26, 2014 2:23 pm
Contact:
Contact skurudo
Website Facebook Google+ Skype
Twitter

Re: Jailed ssh in vesta
  • Quote

Post by skurudo » Fri Aug 14, 2015 4:15 pm

There is manual -> https://www.howtoforge.com/how-to-creat ... ian-wheezy
Who want to test? ;-)
Top

donat
Posts: 39
Joined: Thu Jul 30, 2015 1:42 pm

Re: Jailed ssh in vesta
  • Quote

Post by donat » Fri Sep 04, 2015 6:55 am

I just installed and tested it for the ftp user access. It seems to work, but it changes all paths of the user to the jailkit path.
Next we will jail the created user. Create a directory /jail for Jail environment
So vesta has to change all paths for this. It would be worthy, but it is part of the vestacp team, I guess.
Top


Post Reply
  • Print view

9 posts • Page 1 of 1

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

cron

Login  •  Register

I forgot my password