RE: Solaris 9 sftp-server

[email protected] (Wilfred Spiegelenburg)
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>
BAUMLER Julie L <[email protected]> wrote:

>We're using Sun's ssh sftp server on Solaris 9 for some (internal) 
>customer file tranfers.  But, we don't want to allow these people to login
>or run commands with ssh.  The usual methods to restrict login 
>(/bin/false, "exit" in shell profile files, ...) block both or don't work.
>We need to be able to track file reads and writes, so we need the BSM 
>support of the Solaris version of ssh.  Has anyone else run across this?

Yes we did have the same problem. We were using OpenSSH as our server but as far as I can tell the same should work for you. Just try replacing the shell in /etc/passwd with the sftp subsystem of the server. 

So the line for a user would be something like:
user:x:200:200:Sftp User:/home/user:/opt/SUNWdm/libexec/sftp-server

The sftp implementation on the server is a subsystem of the ssh daemon. I'm not sure about the exact path of the sftp subsystem but it should be something like mentioned.

Hope this helps,
Wilfred
-- 
Wilfred Spiegelenburg
22 Zeal Street, West Brunswick, Victoria 3055, Australia
home: +61 3 9386 5283
mob: +61 403 990374
---
Ziggy (by Tom Wilson)
 ...The last time I tried to get a grip on reality..
 ...it got me in a full-nelson !!


__________________________________________________________________
Try AOL and get 1045 hours FREE for 45 days!
http://free.aol.com/tryaolfree/index.adp?375380

Get AOL Instant Messenger 5.1 for FREE! Download Now!
http://aim.aol.com/aimnew/Aim/register.adp?promo=380455
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.