Re: Useradd command/Encrypted Putty Session (SSH Client)
Erich Titl <[email protected]>
| Newsgroups | gmane.linux.leaf.user |
|---|---|
| Message-ID | <[email protected]> |
Hi
Am 02.10.2020 um 19:37 schrieb Mansoor Ahmad:
> Forgive me if this question is too mediocre for this list but my
> question involved a secure session spanning from putty to our leaf 6x box.
There are no stupis questions, just stupid answers.
>
> Is there a way to:
>
> A: Create a limited non-root user in leaf
there is an adduser command in busybox
leaftester# adduser
BusyBox v1.32.0 (2020-06-27 05:36:34 CEST) multi-call binary.
Usage: adduser [OPTIONS] USER [GROUP]
Create new user, or add USER to GROUP
-h DIR Home directory
-g GECOS GECOS field
-s SHELL Login shell
-G GRP Group
-S Create a system user
-D Don't assign a password
-H Don't create home directory
-u UID User id
-k SKEL Skeleton directory (/etc/skel)
>
> B: Create a open port for an RDP session to a terminal server(I got this
> portion, but just wanted to mention it as a point of reference!)
Mhhhh, most users use shorewall to manage their firewall. I _guess_ it
should be possible there, just go over to shorewall.org for specifics.
>
> C: *The big one* Limit the user and/or putty session so the connecting
> user can't make any changes to the firewall.
Once a user has a terminal connection to the LEAF box everything is
governed by the permissions on the box itself. I am pretty sure there
must be caveats as in every distribution.
>
> I'm trying to create something similar to a VPN client. Unless you
> awesome individuals can offer a better tool for what I'm trying to
> do.....? :-)
Why don't you use a VPN to achieve this?
cheers
ET
--
Diese E-Mail wurde von AVG auf Viren geprüft.
http://www.avg.com
------------------------------------------------------------------------
leaf-user mailing list: [email protected]
https://lists.sourceforge.net/lists/listinfo/leaf-user
Support Request -- http://leaf-project.org/