Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > Mac OS X > Turn on Remote Login for certain users only?

Turn on Remote Login for certain users only?
Thread Tools
Addicted to MacNN
Join Date: Nov 2002
Location: Seattle, WA
Status: Offline
Reply With Quote
Aug 5, 2003, 10:05 PM
 
I'd like to have Remote Login turned on for myself, but off for everyone else. And I'd like to have ftp access turned on for everyone else. Is this possible?
     
Xeo
Moderator Emeritus
Join Date: Mar 2001
Location: Austin, MN, USA
Status: Offline
Reply With Quote
Aug 6, 2003, 04:07 AM
 
You should be able to use Netinfo Manager to set their default shells to /sbin/nologin and they won't be able to SSH in. They should still be able to use Terminal. I'm not sure how the default login script works though so you may need to manually change their Terminal preferences to use tcsh or something.
     
Addicted to MacNN
Join Date: Nov 2002
Location: Seattle, WA
Status: Offline
Reply With Quote
Aug 6, 2003, 10:27 AM
 
I did that and now the other user can't login with either ftp or remote login. Any other ideas?
     
Professional Poster
Join Date: Nov 2000
Location: Tasmania, Australia
Status: Offline
Reply With Quote
Aug 6, 2003, 06:23 PM
 
Install tcpwrappers. This is the BEST security software for any TCP/IP services. You can specify exactly which users and which IP addresses and which DNS hosts can do which TCP protocols to your machine.

I've not used it on Mac OS X, but we use it on all our Solaris machines here. It is excellent!

BTW - it is free.

But you'll need to use the terminal and configure text files.
     
Admin Emeritus
Join Date: Nov 2000
Location: New Yawk
Status: Offline
Reply With Quote
Aug 6, 2003, 08:53 PM
 
Originally posted by Brass:
Install tcpwrappers. This is the BEST security software for any TCP/IP services. You can specify exactly which users and which IP addresses and which DNS hosts can do which TCP protocols to your machine.

I've not used it on Mac OS X, but we use it on all our Solaris machines here. It is excellent!

BTW - it is free.

But you'll need to use the terminal and configure text files.
Sounds like neat software, I'm going to take a look at it...thanks!
"Do not be too positive about things. You may be in error." (C. F. Lawlor, The Mixicologist)
     
Addicted to MacNN
Join Date: Nov 2002
Location: Seattle, WA
Status: Offline
Reply With Quote
Aug 6, 2003, 11:56 PM
 
ok, I'm cool with following directions, but I have to have some direction first

is there a guide or something for tcpwrappers (also maybe a compiled version)?
     
Forum Regular
Join Date: Mar 2001
Location: San Diego
Status: Offline
Reply With Quote
Aug 7, 2003, 02:43 AM
 
Just a note: TCP wrappers do not work on everything like AFP. For some reason Apple hasn't added it. So any service not wrapped will still be open. A workaround is to add rules to ipfw. I'm hopping apple adds TCPwrappers to AFP and also upgrades ipfw to version 2.
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 08:31 PM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2