Re: How to setup an read-only user account for a whole server with useradd ?



Nico <nkadel@xxxxxxxxx>:
On 20 Sep, 01:24, "s. keeling" <keel...@xxxxxxxxxxx> wrote:
s. keeling <keel...@xxxxxxxxxxx>:

Carsten Eishold <bu...@xxxxxxxx>:
I want to setup an user SSH/telnet account with useradd. The user should have

- read-only permissions for ALL files on the server beginning with the root directory.

Frankly, that's a silly requirement. Re-think it.

For safe, restricted read-only access, don't use SSH. Seriously.

Please explain. This is contrary to my experience.

Rsync works well for read-only, NFS for browising in read-only if you
don't care about security, OpenAFS for more sophisticated
authentication. But SSH is an encrypted way to do logins, with hooks
to do file copies on top of that. As what is primarily a log-in
server, what you ask for is not a good fit.

What? He only needs su or sudo.


--
Any technology distinguishable from magic is insufficiently advanced.
(*) http://blinkynet.net/comp/uip5.html Linux Counter #80292
- - http://www.faqs.org/rfcs/rfc1855.html Please, don't Cc: me.
.



Relevant Pages

  • Re: [fw-wiz] Do you permit X11 via proxy firewall?
    ... that's what 'ssh -X' is for. ... At least does it better as packet filtering rules are static. ... remember, just becouse everyone is doing it, it may not be safe. ... tunnel it through SSH then it's safe' ...
    (Firewall-Wizards)
  • Re: Intruders good job -- Change my root password
    ... there is no way to be sure you are safe. ... >> ftp isn't too bad, if you set it up in a chroot jail, but they can be ... >ssh may the better to sftp, but I don't know how to use it. ... scp and sftp. ...
    (comp.os.linux.security)
  • Re: Firewall security: Re: Problems with simple Samba file share
    ... Then why bother allowing ssh? ... For the time you have to go to china at a moment's notice (hey, ... Ssh is safe - that's the whole point of it. ... Refusing to use a safe thing sometimes is silly. ...
    (comp.os.linux.misc)
  • Re: Security basics
    ... can detect ssh implementations since they normally self-identify. ... if you're running ssh on the normal port, ... If you're the only one who ever SSHes into your system, set it up to use public key authentication only and always walk around with a thumbdrive that has your private key on it. ... yes, if you have "passwords that are safe for an hour," your computer is safe -- for 1 hour. ...
    (Fedora)
  • Re: ssh with no encryption ?
    ... > but it's a problem in some cases, and the various ssh authors are ... > trying to keep us safe, even from ourselves -- a pain, true, but if ... was a Sparc5 and encryption really slowed things down (X11 ...
    (comp.security.ssh)