jailkit-users
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Jailkit-users] sftp chroot - Connection Closed


From: Michael Groves
Subject: RE: [Jailkit-users] sftp chroot - Connection Closed
Date: Mon, 5 Jun 2006 13:01:45 +0100

Oliver wrote:
>
> the output of the command shows you whether jk_socketd is running. If 
> you are not running it check the contents of
/etc/jailkit/jk_socketd.ini 
> and if that seems correct start the daemon `jk_socketd`
<snip>

As there was no output from running the command `ps ax|grep jk_socketd`
I assume jk_socketd is not running. I ran jk_socketd and nothing was
displayed. I ran ps ax|grep jk_socketd` and again nothing was diplayed.
My Jk_socketd.ini looks like this; is it correct?

[/home/jail/dev/log]
base=512
peek=2048
interval=10

I tried sftp address@hidden again and still get 'Connection Closed'
But this time I have an entry in /var/log/warn
Linux jk_lsh[5534] : WARNING: user mike (1003) tried to run
'/usr/lib/ssh/sftp-server', which is not allowed according to
/etc/jailkit/jk_lsh.ini

My /etc/jailkit/jk_lsh.ini looks like this;

[group users]
paths = /usr/bin
executables = /usr/bin/cvs
allow_word_expansion = 0
#
[mike]
paths= /usr/bin, usr/lib
executables= /usr/bin/scp, /usr/lib/sftp-server
allow_word_expansion = 0
umask = 002

Having to manually type this I just noticed that there is no spaces
before some of the '=' signs in the user section, is this correct?

--
Michael


ValueLink is a specialist service provider of financial data to the major UK 
and International centres. Our clients require reliable, accurate data with 
maximum coverage on a fixed time delayed basis. We work closely with each of 
our clients to provide a service which meets their specific requirements and 
maximises efficiency of their process. For further information visit our 
website @ www.valuelink.co.uk
CONFIDENTIALITY: The information in this e-mail and any attachment is 
confidential. It is intended only for the named recipient(s). If you are not a 
named recipient, please notify the sender immediately and do not read, use, 
copy or disseminate this information. ValueLink Information Services Ltd 
accepts no liability whatsoever for any direct or consequential loss arising 
from the use, or reliance on, this e-mail or it's contents.





reply via email to

[Prev in Thread] Current Thread [Next in Thread]