PDA

View Full Version : sFTP setup, what's missing?



tonybarcelo
25-Oct-2012, 00:35
I installed a new virtual server, SLES 11.2 64bit to work as a sFTP server for a local community. But I've done something wrong and need help.

The server system is installed with LVM on both the OS disk and also a second disk where the /sftp is mounted.

sshd_config is edited with these lines:

Subsystem sftp internal-sftp

and on the last rows:

Match group sftpgroup
ForceCommand internal-sftp
ChrootDirectory /home/%u
AllowTCPForwarding no
X11Forwarding no

Reloaded sshd with rcsshd reload.

Then I created a group called "sftpgroup" and a folder structure for the chrooted sftp service.
mkdir -p /sftp/chroot
chmod 750 /sftp/chroot
chown root:sftpgroup /sftp/chroot

Created a user restricted to the group sftpgroup but without shell (/bin/false)

When I try to access the sftpserver with testuser@sftpserver I get:
"couldn't read packet: connection reset by peer"

the /var/log/messages on server says:
"fatal:bad ownership or modes for chroot directory /path"

What is missing/wrong?

Automatic reply
01-Nov-2012, 13:30
tonybarcelo,

It appears that in the past few days you have not received a response to your
posting. That concerns us, and has triggered this automated reply.

Has your issue been resolved? If not, you might try one of the following options:

- Visit http://www.suse.com/support and search the knowledgebase and/or check all
the other support options available.
- You could also try posting your message again. Make sure it is posted in the
correct newsgroup. (http://forums.suse.com)

Be sure to read the forum FAQ about what to expect in the way of responses:
http://forums.suse.com/faq.php

If this is a reply to a duplicate posting, please ignore and accept our apologies
and rest assured we will issue a stern reprimand to our posting bot.

Good luck!

Your SUSE Forums Team
http://forums.suse.com