delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2002/12/09/13:34:01

Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sources.redhat.com/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sources.redhat.com/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com
Date: Mon, 9 Dec 2002 10:57:47 +0100
From: Corinna Vinschen <corinna-cygwin AT cygwin DOT com>
To: "'cygwin AT cygwin DOT com'" <cygwin AT cygwin DOT com>
Subject: Re: OpenSSH and cygwin: let a user only connect via sftp.
Message-ID: <20021209105747.A7796@cygbert.vinschen.de>
Reply-To: cygwin AT cygwin DOT com
Mail-Followup-To: "'cygwin AT cygwin DOT com'" <cygwin AT cygwin DOT com>
References: <ED5638825509D4118F9D000102054B1C02226534 AT EXSRV-NES>
Mime-Version: 1.0
In-Reply-To: <ED5638825509D4118F9D000102054B1C02226534@EXSRV-NES>
User-Agent: Mutt/1.3.22.1i

On Thu, Dec 05, 2002 at 12:45:28PM +0100, Schonder, Matthias wrote:
> >Setting a user's shell to /bin/false might (and I repeat, *might* - this is
> >speculation) work.
> 
> Nope, this does not work :( Been there, done that. But when sftp tries to
> login connection will be closed immediately.
> But thanks for you help.
> 
> >Max.
> 
> >PS: This isn't really Cygwin specific.
> 
> Well, I would say it is, because in FreeBSD and IRIX it works fine... so....

Well, if it works on FreeBSD and IRIX then do it the same way in Cygwin
as you did on FreeBSD and IRIX.  For instance, I tried setting the login
shell on a linux box to /bin/false and guess what?  The connection is
closed immediately.  So in that example Cygwin's ssh works exactly as on
other systems.

What you missed somehow is to explain *how* it works on FreeBSD and IRIX
so that we have a chance to look if (and perhaps why) it doesn't work on
Cygwin using the same technique which would make it sort of a Cygwin
specific question.

OTOH, I know how to restrict a user to sftp only and I know that the same
technique works on Cygwin as well as on e. g. Linux so from my current
knowledge of the situation there isn't something Cygwin specific here...


Corinna

-- 
Corinna Vinschen                  Please, send mails regarding Cygwin to
Cygwin Developer                                mailto:cygwin AT cygwin DOT com
Red Hat, Inc.

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Bug reporting:         http://cygwin.com/bugs.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019