I tend to agree that zones are probably your best bet, but in the interest of 
providing other solutions you might also consider using the ChrootDirectory 
functioniality in sshd (you'll need OpenSolaris for this). You can then make 
user by user config changes to your sshd_config (it'll be annoying with lots of 
users) but it should do what you need.

Note that maintaining chroot environments is painful and often they're 
forgotten about when patching is done, leading to them being the security 
nightmare they're trying to solve.

Paul
-- 
This message posted from opensolaris.org
_______________________________________________
sysadmin-discuss mailing list
sysadmin-discuss@opensolaris.org
http://mail.opensolaris.org/mailman/listinfo/sysadmin-discuss

Reply via email to