delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2004/05/03/17:50:44

Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sources.redhat.com/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sources.redhat.com/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com
Message-Id: <6.0.3.0.2.20040503144204.05e5d818@mail.sdsu.edu>
Date: Mon, 03 May 2004 14:50:06 -0700
To: Cygwin List <cygwin AT cygwin DOT com>
From: Stephen Treger <streger AT mail DOT sdsu DOT edu>
Subject: Windows 2003 and sshd
In-Reply-To: <6.1.0.6.0.20040503112607.03090a50@127.0.0.1>
References: <200405031601 DOT 12828 DOT mauro DOT migliorati AT uniroma1 DOT it> <6 DOT 1 DOT 0 DOT 6 DOT 0 DOT 20040503112607 DOT 03090a50 AT 127 DOT 0 DOT 0 DOT 1>
Mime-Version: 1.0
X-MailScanner-Information: http://security.sdsu.edu/
X-TNS-MailScanner: Found to be clean (mailgw2)
X-MailScanner-SpamCheck:
X-IsSubscribed: yes

Hello,

I had a RedHat box, the sole purpose was to be the intermediate between a 
secure host and public for moving data files in/out. Obviously this was 
done solely upon ssh (scp/sftp). For numerous reasons we decided to 
reconfigure as Windows 2003 Server with CygWin and openssh.

I took a XP workstation, loaded CygWin with the required openssh and 
openssl components, populated the passwd and group files from our AD using 
the -d options on mkpasswd and mkgroup respectively and then installed sshd 
as a service.

It was the coolest thing, I would ssh in as a user listed in the passwd 
file, but never having logged into the box before, and it automatically 
created a home directory and populated it with the skeleton files. First 
login produced some warnings, but after that the directory was set up 
properly and everything worked.

So I duplicate on the Windows 2003 box. Hmm, if I don't create the home 
directories manually users are instantly rejected. Some users out there 
claimed I must run a script (fixperms.sh) for it all to work properly and 
securely; I did and now am worse off than before. I get errors reprting no 
rights to the shell (though the user does have rx to the various shells).

So I thought I would start over with CygWin on the 2003 box, but when I 
deleted and reinstalled all the weird permissions still existed.

Anybody got a really good HOW-TO on this?
I need multiple users to have their own secure home directories, a couple 
of additional logins that are in a "admin" group and can control those 
directories. If I need to jail them, how do you do that under cygwin and is 
it feasible?


--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019