delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2008/12/02/04:08:45

X-Recipient: archive-cygwin AT delorie DOT com
X-Spam-Check-By: sourceware.org
References: <664060 DOT 6380 DOT qm AT web34704 DOT mail DOT mud DOT yahoo DOT com> <49341625 DOT 2090804 AT cygwin DOT com> <933558 DOT 98400 DOT qm AT web34705 DOT mail DOT mud DOT yahoo DOT com> <4934C530 DOT 9030405 AT byu DOT net>
Date: Tue, 2 Dec 2008 01:07:50 -0800 (PST)
From: TheO <idgajelas AT yahoo DOT com>
Subject: Re: Finally managed to create a jailed SFTP server, but how secure?
To: cygwin AT cygwin DOT com
MIME-Version: 1.0
Message-ID: <100011.88124.qm@web34705.mail.mud.yahoo.com>
X-IsSubscribed: yes
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

> 

> Did you verify whether DOS paths, such as c:\, were also blocked?
> 


No it's not blocked from Windows. if I log on locally, I can access /cygdrive/c without any problem. But I can't using jailed SFTP, even if I use my Administrator account.


> 
> To repeat what we have already told you multiple times: cygwin does NOT
> enforce the jail.  And without OS support to do so, we are not in a
> position to state that your jail is secure; so with security in mind, you
> must consider the SFTP connection, even in its chroot jail, to be only as
> secure as the restricted rights that you are able to enforce on the
> Windows user id in use when you make the SFTP connection.
> 

Please don't get me wrong here Eric. I am just trying to see the suitability of Cygwin as the ultimate SFTP server in Windows. SFTP is becoming more and more popular amongst our customers. In the last 6 months, I received 3 requests to build system with integrated SFTP server in it. To be honest with you, I have never come accross this word before that time.

Choosing full Unix based solution is for the time being, out of question for me as my programmers don't "speak" Unix at all.

If I know how to build a safe SFTP server with Cygwin, then I will share this experience with others. At least I can contribute to make Cygwin a little bit more popular.


      

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019