Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

How to enable SSH access for users only for file transfers?

General questions about VestaCP
Post Reply
  • Print view
Advanced search
9 posts • Page 1 of 1
LightPeak
Posts: 12
Joined: Tue Sep 02, 2014 3:03 am

How to enable SSH access for users only for file transfers?
  • Quote

Post by LightPeak » Thu Sep 04, 2014 10:35 am

As the topic says, how do I enable users to transfers files via SSH FTP only (no shell access) in place of FTP as my server is behind a firewall and FTP passive ports always makes it hard to configure.
Top

imperio
VestaCP Team
Posts: 7000
Joined: Sat Dec 01, 2012 12:37 pm
Contact:
Contact imperio
Website

Re: How to enable SSH access for users only for file transfe
  • Quote

Post by imperio » Thu Sep 04, 2014 2:48 pm

Hi,
you can enable ssh in the settings of user
"SSH Access"
Top

LightPeak
Posts: 12
Joined: Tue Sep 02, 2014 3:03 am

Re: How to enable SSH access for users only for file transfe
  • Quote

Post by LightPeak » Thu Sep 04, 2014 3:13 pm

Hi, but would they be able to access via shell and gain access to admin features?
Otherwise, which ssh access should I enabled (sh, bash, dash, rssh)?

Thank you!
Top

imperio
VestaCP Team
Posts: 7000
Joined: Sat Dec 01, 2012 12:37 pm
Contact:
Contact imperio
Website

Re: How to enable SSH access for users only for file transfe
  • Quote

Post by imperio » Thu Sep 04, 2014 3:59 pm

Maybe they can read files on server, but they cant edit and change server files
It normal for Linux
Top

LightPeak
Posts: 12
Joined: Tue Sep 02, 2014 3:03 am

Re: How to enable SSH access for users only for file transfe
  • Quote

Post by LightPeak » Fri Sep 05, 2014 1:48 pm

I've checked; yes, users are able to access sensitive system files including php.ini, httpd.ini, etc.
Is there a way to jail them to their home directory only?
Top

Steve
Posts: 2
Joined: Tue Nov 11, 2014 10:54 pm

Re: How to enable SSH access for users only for file transfe
  • Quote

Post by Steve » Tue Nov 11, 2014 10:58 pm

Is there any update to this?

I would like to allow SHH acess for my users but have them access files in their own account only. Currently, allowing SSH access on an account grants access to ALL server files.

Thanks for any help.
Top

Trentor
Posts: 84
Joined: Fri Apr 25, 2014 6:42 pm

Re: How to enable SSH access for users only for file transfe
  • Quote

Post by Trentor » Tue Nov 11, 2014 11:30 pm

The solution is jailing every user in their jail: Creating a Chroot Jail for SSH Access
Top

Steve
Posts: 2
Joined: Tue Nov 11, 2014 10:54 pm

Re: How to enable SSH access for users only for file transfe
  • Quote

Post by Steve » Tue Nov 11, 2014 11:40 pm

Hi Trentor,

Thanks very much for the reply, it's really appreciated.

I've looked over the link and it's way too complicated for me to follow, sorry. I was hoping there was a way to carry this option easily in VestaCP (selecting a jailed SSH option?) but this doesn't appear to be the case...

Is there a step by step guide anywhere you know of that shows how best to achieve this in VestaCP at all?

Thanks again.
Top

Trentor
Posts: 84
Joined: Fri Apr 25, 2014 6:42 pm

Re: How to enable SSH access for users only for file transfe
  • Quote

Post by Trentor » Wed Nov 12, 2014 12:01 am

Hi Steve,

No, you can't do that directly under Vesta, you need to do it manually, but it's no so hard, there are a lots of manuals on Internet (check out for Jailkit, useful to create SSH jails): Jail SSH

If you don't want to do it manually, the imperio's solution is the best one; your users will have access to list files outside their directories but they will not be able to edit, delete or download that files.

Otherwise, the best solution for me it's try to configure properly the firewall and use a FTP server.

Good luck!!
Top


Post Reply
  • Print view

9 posts • Page 1 of 1

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password