|
From: Michael E. <mic...@st...> - 2011-04-01 07:28:16
|
Hi Stephan The login-wrapper.sh script is no longer needed: backup-01 bin # ls -al total 112 drwxr-xr-x 2 root root 28 2009-06-22 17:36 . drwxr-xr-x 4 root root 26 2008-04-28 14:30 .. -rwxr-xr-x 18 root root 66036 2009-06-22 17:36 quota -rwxr-xr-x 18 root root 43024 2007-10-25 17:11 scp backup-01 bin # Now the users have full ssh access to the chroot environment. The login-wrapper.sh script restricted the access to certain commands. I've updated the wiki. Regards, Michael On 31/03/11 22:58, Stephan Buys wrote: > Hi Michael, > > I am missing you're custom login-wrapper.sh script, can you please > update or send. > > Thanks > Stephan > > On 31/03/2011 16:44, Michael Eichenberger wrote: >> Hi Stephan >> >>> >>> A big thanks for you're quick responses, just want to confirm you >>> received the below mail on: >>> >>> "Can you please send me you're list of tools you added to skeleton" >> http://wiki.sepiola.org/index.php/chroot_Environment >> >>> >>> You can give me access to wiki if you want, copied most of commands >>> to txt document while setting up client/server and also want to do >>> further testing tonight. >> Access data sent off list. >> >>> >>> Few things I got stuck on. >>> - .ssh directory does not get auto created on server or client if >>> it doesn't exist at install >> Yes, see http://wiki.sepiola.org/index.php/chroot_Environment >> You'll also need a empty authorized_keys below the .ssh directory. >> >>> - the config file needs some notes on where and how directories and >>> files work that need to be set(I'll try and help you with that) >> Please feel free to add this to the wiki. You could also file a bug >> report under: >> http://sourceforge.net/tracker/?group_id=236877&atid=1101334 >> >> If you add a bug report, we would appreciate the comments we should add. >> >>> - Is it possible to schedule more than one schedule and how? >> No, this is currently not possible. >> >> If you would lilke this feature, please add it to the Feature-Request >> tracker: >> http://sourceforge.net/tracker/?group_id=236877&atid=1101337 >> >> Kind regards, Michael >> >>> >>> Cheers >>> Stephan Buys >>> >>> -------- Original Message -------- >>> Subject: Re: [Sepiola-users] Sepiola Installation >>> Date: Thu, 31 Mar 2011 10:25:19 +0200 >>> From: Stephan Buys <ps...@gm...> >>> To: Michael Eichenberger <mic...@st...> >>> >>> >>> >>> That was my idea as well, using Jailkit. Can you please send me >>> you're list of tools you added to skeleton. There is quite a few. >>> >>> Thanks >>> >>> On 31/03/2011 10:21, Michael Eichenberger wrote: >>>> Hi Stephan >>>> >>>> We work with chroot environments (Change root). These chroots act >>>> like a jail. The users can not leave the chroot environments. The >>>> setup depends on your Linux distribution. Some distributions offer >>>> tools to setup a chroot. >>>> >>>> We created a skeleton and added the tools (like ls, chmod, ...) >>>> with the corresponding libraries. For each new user we just >>>> hardlink all the files an edit /etc/passwd and /etc/group. >>>> >>>> Regards, Michael >>>> >>>> On 31/03/11 10:13, Stephan Buys wrote: >>>>> Hi There >>>>> >>>>> Thanks for you're help will impliment and send details you some >>>>> other snags I ran into. What do you use to keep user backup files >>>>> isolated and unreadable from other backup ssh users? >>>>> >>>>> Thanks >>>>> Stephan >>>>> >>>>> On 31/03/2011 09:14, Michael Eichenberger wrote: >>>>>> Hello Stephan >>>>>> >>>>>> The scripts are fairly simple. In most cases, the only >>>>>> information taken out of the ldap directory can be extracted with >>>>>> the following commands (uid stands for the user name, gid for the >>>>>> group name): >>>>>> >>>>>> * getent passwd uid >>>>>> * getent passwd gid >>>>>> >>>>>> With these commands, you can check the users home directory and >>>>>> retrieve any other user related information. >>>>>> >>>>>> I would be happy to give you write access to the sepiola wiki, so >>>>>> that you can publish you own scripts. >>>>>> >>>>>> Kind regards, Michael >>>>>> >>>>>> >>>>>> On 31/03/11 00:25, Stephan Buys wrote: >>>>>>> Hey again, can you please let me know how server side scripts >>>>>>> can be adapted for local users rather than ldap. >>>>>>> >>>>>>> Thanks again >>>>>>> Stephan >>>>>>> >>>>>>> On 30/03/2011 12:17, Michael Eichenberger wrote: >>>>>>>> Hi Stephan >>>>>>>> >>>>>>>> We've updated the documentation on the wiki for the >>>>>>>> configuration of Sepiola (Linux): >>>>>>>> http://wiki.sepiola.org/index.php?n=Sepiola.InstallationLinux?lang=en >>>>>>>> >>>>>>>> Please make sure, that puttygen is installed on the server (see >>>>>>>> the requirements section): >>>>>>>> http://wiki.sepiola.org/index.php?n=Sepiola.HowToBackupServerSetUp?lang=en >>>>>>>> >>>>>>>> Kind regards, Michael >>>>>>>> >>>>>>>> On 30/03/11 00:56, Stephan Buys wrote: >>>>>>>>> Hi There, >>>>>>>>> >>>>>>>>> Got everyhting installed and configured to connect to my ssh >>>>>>>>> server, keys fingerprints etc. >>>>>>>>> >>>>>>>>> ssh from the command line works fine but user can't authenticate. >>>>>>>>> >>>>>>>>> What do I have to change in config for custom setup? >>>>>>>>> >>>>>>>>> Like what I see in screenshots wanna give it a try! >>>>>>>>> >>>>>>>>> Thanks >>>>>>>>> Stephan Buys >>>>>>>>> >>>>>>>>> Linux + Windows >>>>>>>>> >>>>>>>>> >>>>>>>>> ------------------------------------------------------------------------------ >>>>>>>>> Enable your software for Intel(R) Active Management Technology to meet the >>>>>>>>> growing manageability and security demands of your customers. Businesses >>>>>>>>> are taking advantage of Intel(R) vPro (TM) technology - will your software >>>>>>>>> be a part of the solution? Download the Intel(R) Manageability Checker >>>>>>>>> today!http://p.sf.net/sfu/intel-dev2devmar >>>>>>>>> >>>>>>>>> >>>>>>>>> _______________________________________________ >>>>>>>>> Sepiola-users mailing list >>>>>>>>> Sep...@li... >>>>>>>>> https://lists.sourceforge.net/lists/listinfo/sepiola-users >>>>>>>> >>>>>>>> -- >>>>>>>> stepping stone GmbH >>>>>>>> Neufeldstrasse 9 >>>>>>>> CH-3012 Bern >>>>>>>> >>>>>>>> Telefon: +41 31 332 53 63 >>>>>>>> www.stepping-stone.ch >>>>>>>> mic...@st... >>>>>>> >>>>>> >>>>>> -- >>>>>> stepping stone GmbH >>>>>> Neufeldstrasse 9 >>>>>> CH-3012 Bern >>>>>> >>>>>> Telefon: +41 31 332 53 63 >>>>>> www.stepping-stone.ch >>>>>> mic...@st... >>>>> >>>> >>>> -- >>>> stepping stone GmbH >>>> Neufeldstrasse 9 >>>> CH-3012 Bern >>>> >>>> Telefon: +41 31 332 53 63 >>>> www.stepping-stone.ch >>>> mic...@st... >>> >> >> -- >> stepping stone GmbH >> Neufeldstrasse 9 >> CH-3012 Bern >> >> Telefon: +41 31 332 53 63 >> www.stepping-stone.ch >> mic...@st... > -- stepping stone GmbH Neufeldstrasse 9 CH-3012 Bern Telefon: +41 31 332 53 63 www.stepping-stone.ch mic...@st... |