Lock down SFTP access on OpenSolaris

Posted by Simon on Server Fault See other posts from Server Fault or by Simon
Published on 2010-04-29T14:17:46Z Indexed on 2010/04/29 14:27 UTC
Read the original article Hit count: 526

Filed under:
|
|

Hi all,

I have an OpenSolaris 2009.06 server and I'd like to enable a user to remotely change files in a specific directory, ideally via SFTP or FTP-via-SSH. This user does not yet have an account on the machine and I'd like to create it so it's as restricted as possible. Is there a canonical way of doing this? I know about OpenSolaris' role-based access control and authorizations model, but I figure it's a lot of work (i.e., a lot I can mess up) to really lock down a full-blown user account (prevent fork bombs, make sure there's really no other file in the file system which can be written to...). Any hint is greatly appreciated.

Thanks, Simon

© Server Fault or respective owner

Related posts about opensolaris

Related posts about server-security