Koozali.org: home of the SME Server

Obsolete Releases => SME Server 7.x => Topic started by: Proxy on December 03, 2009, 07:09:25 AM

Title: SFTP via VPN access to all the SME?
Post by: Proxy on December 03, 2009, 07:09:25 AM
Hi there,..

If you grant a normal user SFTP access to you system (v7.4) via VPN the user is able to see your hole SME directory.
With FTP access this is not the case.

This can't be normal or does it?

Best regards.
Proxy
Title: Re: SFTP via VPN access to all the SME?
Post by: fpausp on December 03, 2009, 08:02:33 AM
Have you done the latest update 251109 ? There are problems with vpn, keyboard ...

Best
Title: Re: SFTP via VPN access to all the SME?
Post by: Proxy on December 03, 2009, 08:08:35 AM
Yep, all updates are up-to-date
Title: Re: SFTP via VPN access to all the SME?
Post by: Daniel B. on December 03, 2009, 08:54:07 AM
Yes, it's "normal". The version of OpenSSH included in SME doesn't support chroot. It's possible to configure some kinds of jails, but it's not very easy, nor practical.

Regards, Daniel
Title: Re: SFTP via VPN access to all the SME?
Post by: Proxy on December 03, 2009, 09:05:48 AM
Hi Daniel,

Can you tell me how i can give a normal user (from the internet) access to an ibay (HTML Dir) where he can up, download and modify things.
Whitout having access to all the SME.

Thanks in advance,
Proxy
Title: Re: SFTP via VPN access to all the SME?
Post by: Daniel B. on December 03, 2009, 09:20:35 AM
In your first post, you're talking about SFTP inside a VPN. If you use a VPN, you can use what ever you want (FTP, samba, etc...).
If you don't want the VPN to be mandatory, I suggest to use webdav, as explained here:

http://wiki.contribs.org/DAV_Enabled_Ibays
Title: Re: SFTP via VPN access to all the SME?
Post by: Proxy on December 03, 2009, 09:39:51 AM
Thanks for your answer, i've take a look at it but its to complicated for me to do.
I'm just a simple SME user (and mirror)
Title: Re: SFTP via VPN access to all the SME?
Post by: janet on December 03, 2009, 11:31:51 AM
Proxy

yum install --enablerepo=smecontribs smeserver-remoteuseraccess

then configure user access & specify user "jail" location in the newly added server manager panel
Title: Re: SFTP via VPN access to all the SME?
Post by: Proxy on December 03, 2009, 12:04:32 PM
Thanks but did you check your link, its not working via Putty.
Title: Re: SFTP via VPN access to all the SME?
Post by: janet on December 03, 2009, 01:05:13 PM
Proxy

Corrected mispelling.