the best approach would bet using sftp everywhere an totally disable ftp as pointed MMccarn the tls protocol available on SME9 is not considered secure.
Whether you are on the lan or over the internet, with FTP your password is sent in clear, so could be taken.
Hi Jean-Philippe,
Yes. I couldn't agree more. I'm more than happy to disable insecure FTP entirely inside & outside.
I think I was just comparing it to the existing mail "server access" settings in the configuration/email GUI in SME 9.2
It specifies secure for external, but makes no mention of it for internal. I'd be happy with secure both sides.
I'm not actually using FTP internally (to this server), so it never crossed my mind.
I'm so paranoid I run secure SSL IMAP down a 6 foot cable I can see both ends of across my office!
As pointed by Mmccarn install remoteuseraccess and usermanager so each user could enable and set its own rsa ssh key.
In term of software, filezilla could be used for scp /sftp but I would prefer winscp on windows.
Yes. This is something I'm going to have to research a little more now that I've confirmed the direction I need to take.
If you are in need to make a chroot, some extra work need to be done, but this would be to make it more convenient than more secure. If your user has not right to access an ibay or any folder, being able to list it will change nothing.
Understood. At the moment I'm happy for them to upload to a useraccount, and I can then write some scripts to move things around from there, rather than (potentially) exposing more of the filesystem to the world, so that if it was hacked, the damage would at least be limited.
Thanks for all the help. Time to digest and come up with a plan.
I appreciate the help from you all. It's been top-notch and helpful. It makes a refreshing change from some of the "assistance" I've seen elsewhere lately.