Re: Need advise aobut allowing only sftp on woody

2003-10-15 Thread Haim Ashkenazi
Dariush Pietrzak wrote: >> > Can't SSH run in chroot ? >> sorry, I made a mistake... I've meant that it allows shell login while I >> wanted to disable it. > Well... if you don't want shell logins you can't use hacks like scp/sftp, > but you can use restricted shell like scponly. > I'd recommend

Re: Need advise aobut allowing only sftp on woody

2003-10-15 Thread Haim Ashkenazi
Dariush Pietrzak wrote: >> > Can't SSH run in chroot ? >> sorry, I made a mistake... I've meant that it allows shell login while I >> wanted to disable it. > Well... if you don't want shell logins you can't use hacks like scp/sftp, > but you can use restricted shell like scponly. > I'd recommend

Re: Need advise aobut allowing only sftp on woody

2003-10-15 Thread Dariush Pietrzak
> > Can't SSH run in chroot ? > sorry, I made a mistake... I've meant that it allows shell login while I > wanted to disable it. Well... if you don't want shell logins you can't use hacks like scp/sftp, but you can use restricted shell like scponly. I'd recommend proftpd with tls, but it does no

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Dariush Pietrzak
> > Can't SSH run in chroot ? > sorry, I made a mistake... I've meant that it allows shell login while I > wanted to disable it. Well... if you don't want shell logins you can't use hacks like scp/sftp, but you can use restricted shell like scponly. I'd recommend proftpd with tls, but it does no

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Haim Ashkenazi
Yogesh Sharma wrote: > Can't SSH run in chroot ? sorry, I made a mistake... I've meant that it allows shell login while I wanted to disable it. Bye -- Haim

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Haim Ashkenazi
Yogesh Sharma wrote: > Can't SSH run in chroot ? sorry, I made a mistake... I've meant that it allows shell login while I wanted to disable it. Bye -- Haim -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Sean McAvoy
Hello, I have sshd running on a woody box in a chroot environment. It's not my running for remote access, but for data collection so. Just got to make sure to keep up with openssh security holes. I downloaded the sources and compiled it myself. I have privilege seperation disabled. On Tue, 2003

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Dariush Pietrzak
On Tue, Oct 14, 2003 at 11:31:10AM -0700, Yogesh Sharma wrote: > Can't SSH run in chroot ? not easily with priviliege separation turned on? -- Dariush Pietrzak, Key fingerprint = 40D0 9FFB 9939 7320 8294 05E0 BCC7 02C4 75CC 50D9

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Yogesh Sharma
Can't SSH run in chroot ? Haim Ashkenazi wrote: this is a good setup, but I want chroot enviroment. thanx -- Haim

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Sean McAvoy
Hello, I have sshd running on a woody box in a chroot environment. It's not my running for remote access, but for data collection so. Just got to make sure to keep up with openssh security holes. I downloaded the sources and compiled it myself. I have privilege seperation disabled. On Tue, 2003

Re: Need advise aobut allowing only sftp on woody - THANX

2003-10-14 Thread Haim Ashkenazi
thanx, everyone. I've downloaded and compiled scponly from unstable and it looks very nice. Bye -- Haim Haim Ashkenazi wrote: > Hi > > I want to allow a lot of users to be able to upload/download fies, with > the following restrictions: > > 1. encrypted (ssh/ssl) > 2. key based authentication

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Haim Ashkenazi
Yogesh Sharma wrote: > Hi, > > I am not if I got your question correct but here how my setup is: > > FTP access disabled > Running sshd which only supports certificate based auth > I copied my public certificate in my home dir > Now I can do sftp using certificates. So I don't have to type passw

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Dariush Pietrzak
On Tue, Oct 14, 2003 at 11:31:10AM -0700, Yogesh Sharma wrote: > Can't SSH run in chroot ? not easily with priviliege separation turned on? -- Dariush Pietrzak, Key fingerprint = 40D0 9FFB 9939 7320 8294 05E0 BCC7 02C4 75CC 50D9 -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Yogesh Sharma
Can't SSH run in chroot ? Haim Ashkenazi wrote: this is a good setup, but I want chroot enviroment. thanx -- Haim -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Yogesh Sharma
Hi, I am not if I got your question correct but here how my setup is: FTP access disabled Running sshd which only supports certificate based auth I copied my public certificate in my home dir Now I can do sftp using certificates. So I don't have to type password (if my certificate was created w

Re: Need advise aobut allowing only sftp on woody - THANX

2003-10-14 Thread Haim Ashkenazi
thanx, everyone. I've downloaded and compiled scponly from unstable and it looks very nice. Bye -- Haim Haim Ashkenazi wrote: > Hi > > I want to allow a lot of users to be able to upload/download fies, with > the following restrictions: > > 1. encrypted (ssh/ssl) > 2. key based authentication

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Haim Ashkenazi
Yogesh Sharma wrote: > Hi, > > I am not if I got your question correct but here how my setup is: > > FTP access disabled > Running sshd which only supports certificate based auth > I copied my public certificate in my home dir > Now I can do sftp using certificates. So I don't have to type passw

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Dariush Pietrzak
Hi, > 1. encrypted (ssh/ssl) proftpd can do that. > 2. key based authentication, no password!!! that's trickier, there are FTP/TLS servers with that capability, but I doubt you'll find anything in woody that can do that besides ssh. > 3. preferebly without the option for login (if used with

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Moti Levy
I've used scponly and liked it ... http://www.sublimation.org/scponly/ - Original Message - From: "Haim Ashkenazi" <[EMAIL PROTECTED]> To: Sent: Tuesday, October 14, 2003 10:08 AM Subject: Need advise aobut allowing only sftp on woody > Hi > > I want to a

Need advise aobut allowing only sftp on woody

2003-10-14 Thread Haim Ashkenazi
Hi I want to allow a lot of users to be able to upload/download fies, with the following restrictions: 1. encrypted (ssh/ssl) 2. key based authentication, no password!!! 3. preferebly without the option for login (if used with scp, sftp) 4. chroot The obvious way was using sftp, but woody doesn'

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Yogesh Sharma
Hi, I am not if I got your question correct but here how my setup is: FTP access disabled Running sshd which only supports certificate based auth I copied my public certificate in my home dir Now I can do sftp using certificates. So I don't have to type password (if my certificate was created wi

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Dariush Pietrzak
Hi, > 1. encrypted (ssh/ssl) proftpd can do that. > 2. key based authentication, no password!!! that's trickier, there are FTP/TLS servers with that capability, but I doubt you'll find anything in woody that can do that besides ssh. > 3. preferebly without the option for login (if used with

Re: Need advise aobut allowing only sftp on woody

2003-10-14 Thread Moti Levy
I've used scponly and liked it ... http://www.sublimation.org/scponly/ - Original Message - From: "Haim Ashkenazi" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, October 14, 2003 10:08 AM Subject: Need advise aobut allowing only sftp on woody >

Need advise aobut allowing only sftp on woody

2003-10-14 Thread Haim Ashkenazi
Hi I want to allow a lot of users to be able to upload/download fies, with the following restrictions: 1. encrypted (ssh/ssl) 2. key based authentication, no password!!! 3. preferebly without the option for login (if used with scp, sftp) 4. chroot The obvious way was using sftp, but woody doesn'