Koozali.org: home of the SME Server

SFTP via VPN access to all the SME?

Offline Proxy

  • **
  • 28
  • +0/-0
SFTP via VPN access to all the SME?
« on: December 03, 2009, 07:09:25 AM »
Hi there,..

If you grant a normal user SFTP access to you system (v7.4) via VPN the user is able to see your hole SME directory.
With FTP access this is not the case.

This can't be normal or does it?

Best regards.
Proxy

Offline fpausp

  • *
  • 728
  • +0/-0
Re: SFTP via VPN access to all the SME?
« Reply #1 on: December 03, 2009, 08:02:33 AM »
Have you done the latest update 251109 ? There are problems with vpn, keyboard ...

Best
Viribus unitis

Offline Proxy

  • **
  • 28
  • +0/-0
Re: SFTP via VPN access to all the SME?
« Reply #2 on: December 03, 2009, 08:08:35 AM »
Yep, all updates are up-to-date

Offline Daniel B.

  • *
  • 1,700
  • +0/-0
    • Firewall Services, la sécurité des réseaux
Re: SFTP via VPN access to all the SME?
« Reply #3 on: December 03, 2009, 08:54:07 AM »
Yes, it's "normal". The version of OpenSSH included in SME doesn't support chroot. It's possible to configure some kinds of jails, but it's not very easy, nor practical.

Regards, Daniel
C'est la fin du monde !!! :lol:

Offline Proxy

  • **
  • 28
  • +0/-0
Re: SFTP via VPN access to all the SME?
« Reply #4 on: December 03, 2009, 09:05:48 AM »
Hi Daniel,

Can you tell me how i can give a normal user (from the internet) access to an ibay (HTML Dir) where he can up, download and modify things.
Whitout having access to all the SME.

Thanks in advance,
Proxy

Offline Daniel B.

  • *
  • 1,700
  • +0/-0
    • Firewall Services, la sécurité des réseaux
Re: SFTP via VPN access to all the SME?
« Reply #5 on: December 03, 2009, 09:20:35 AM »
In your first post, you're talking about SFTP inside a VPN. If you use a VPN, you can use what ever you want (FTP, samba, etc...).
If you don't want the VPN to be mandatory, I suggest to use webdav, as explained here:

http://wiki.contribs.org/DAV_Enabled_Ibays
C'est la fin du monde !!! :lol:

Offline Proxy

  • **
  • 28
  • +0/-0
Re: SFTP via VPN access to all the SME?
« Reply #6 on: December 03, 2009, 09:39:51 AM »
Thanks for your answer, i've take a look at it but its to complicated for me to do.
I'm just a simple SME user (and mirror)

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: SFTP via VPN access to all the SME?
« Reply #7 on: December 03, 2009, 11:31:51 AM »
Proxy

yum install --enablerepo=smecontribs smeserver-remoteuseraccess

then configure user access & specify user "jail" location in the newly added server manager panel
« Last Edit: December 03, 2009, 01:03:09 PM by mary »
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.

Offline Proxy

  • **
  • 28
  • +0/-0
Re: SFTP via VPN access to all the SME?
« Reply #8 on: December 03, 2009, 12:04:32 PM »
Thanks but did you check your link, its not working via Putty.

Offline janet

  • *****
  • 4,812
  • +0/-0
Re: SFTP via VPN access to all the SME?
« Reply #9 on: December 03, 2009, 01:05:13 PM »
Proxy

Corrected mispelling.
Please search before asking, an answer may already exist.
The Search & other links to useful information are at top of Forum.