Feature/sftp #111

Merged
merged 7 commits into from Feb 16, 2016

Conversation

Projects
None yet
2 participants
@jmara
Contributor

jmara commented Feb 6, 2016

Hi,

referring to #110 I've created the ability to enable SFTP.

Cheers,
Jan

@atomic111

This comment has been minimized.

Show comment
Hide comment
@atomic111

atomic111 Feb 12, 2016

Member

Hi jmara,
great work!!! Can you add some documentation lines to the README.md and please add somthing like

"This is a ChrootDirectory ownership problem. sshd will reject SFTP connections to accounts that are set to chroot into any directory that has ownership/permissions that sshd considers insecure. sshd's strict ownership/permissions requirements dictate that every directory in the chroot path must be owned by root and only writable by the owner. So, for example, if the chroot environment is /home must be owned by root. " see https://wiki.archlinux.org/index.php/SFTP_chroot

If you just enable it and create the group with a user then it is not working, because of the wrong ownership. Just to provide the user a hint.

Thanks

Member

atomic111 commented Feb 12, 2016

Hi jmara,
great work!!! Can you add some documentation lines to the README.md and please add somthing like

"This is a ChrootDirectory ownership problem. sshd will reject SFTP connections to accounts that are set to chroot into any directory that has ownership/permissions that sshd considers insecure. sshd's strict ownership/permissions requirements dictate that every directory in the chroot path must be owned by root and only writable by the owner. So, for example, if the chroot environment is /home must be owned by root. " see https://wiki.archlinux.org/index.php/SFTP_chroot

If you just enable it and create the group with a user then it is not working, because of the wrong ownership. Just to provide the user a hint.

Thanks

@jmara

This comment has been minimized.

Show comment
Hide comment
@jmara

jmara Feb 16, 2016

Contributor

Hey Patrick,

you're welcome. I've added a Section for SFTP, added your suggestion to the FAQ and described the attributes.

Cheers,
Jan

Contributor

jmara commented Feb 16, 2016

Hey Patrick,

you're welcome. I've added a Section for SFTP, added your suggestion to the FAQ and described the attributes.

Cheers,
Jan

@atomic111

This comment has been minimized.

Show comment
Hide comment
@atomic111

atomic111 Feb 16, 2016

Member

Hi,
awesome work!!! Thanks

Member

atomic111 commented Feb 16, 2016

Hi,
awesome work!!! Thanks

atomic111 added a commit that referenced this pull request Feb 16, 2016

@atomic111 atomic111 merged commit 1986bc0 into dev-sec:master Feb 16, 2016

2 checks passed

continuous-integration/travis-ci/pr The Travis CI build passed
Details
coverage/coveralls Coverage remained the same at 100.0%
Details

@atomic111 atomic111 referenced this pull request in dev-sec/ssh-baseline Feb 16, 2016

Open

Create Test for sftp #54

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment