Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Our Archives > General Archives > Servers > SSH secured connections w/o a shell on the server?

 
SSH secured connections w/o a shell on the server?
Thread Tools
Mac Elite
Join Date: Aug 2001
Location: Madison, WI
Status: Offline
Oct 30, 2003, 01:48 PM
 
I'm fortunate enough to have an Xserve as my company file server. Since I'd like to open it up to access from the WAN, I'd prefer server connections to be done over SSH instead of AFP.

I'd rather not give command line access to my user's accounts, just because they don't need it, and it's one more place a hacker could hack at to have their fun. However, if I disable their shells, they can't mount the file server over SSH.

Is there a way I can allow SSH exclusively for file access from the Finder, and not as an interactive shell? Jag seems to have been going through the motions when asking for a SSH connection- if refused, it fell back to AFP silently. Panther just up and says login refused. On the server console it explains "user not allowed because shell dev/null is not executable".
OS X: Where software installation doesn't require wizards with shields.
     
Grizzled Veteran
Join Date: Nov 2001
Location: Oregon
Status: Offline
Nov 1, 2003, 04:03 PM
 
Is there a way I can allow SSH exclusively for file access from the Finder, and not as an interactive shell?
It is possible to limit ssh to certain commands (or to block certain commands, however this is less secure). man ssh_config has some info, although it doesn't seem to get into the nitty gritty of it. I suggest Googling around a bit. Also, some books on ssh talk about how to go about this, and raise some security concerns you might not have thought about.
     
 
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 07:15 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2