HowtoForge Forums | HowtoForge - Linux Howtos and Tutorials

HowtoForge Forums | HowtoForge - Linux Howtos and Tutorials (http://www.howtoforge.com/forums/index.php)
-   General (http://www.howtoforge.com/forums/forumdisplay.php?f=25)
-   -   Jailkit SSH user not chrooted...buy why? (http://www.howtoforge.com/forums/showthread.php?t=54584)

LTxda 20th October 2011 08:31

Jailkit SSH user not chrooted...buy why?
 
I'm learning how to use ISPConfig3 and am having a problem with setting up a chrooted ssh user. Not sure if I've done something wrong, missed something or something is broken.

Here are the steps I've taken:

- Created a new client
- Created a new website and associated it with the client created
- Created an ssh user and specified Chroot Shell for the account as "Jailkit".

I'm able to ssh into the server but am not chrooted. I'm able to traverse the entire file system.

I've done some searching and it seems that there might be a bug where the shell isn't being setup correctly in /etc/passwd.

web4:x:5004:5006::/var/www/clients/client2/web4:/bin/false
lt0001sshuser1:x:5004:5006::/var/www/clients/client2/web4:/bin/bash

Is it safe to assume that the two lines extracted from the passwd file are incorrect and should reflect as follows for this to work properly?...

web4:x:5004:5006::/var/www/clients/client2/web4:/bin/false
lt0001sshuser1:x:5004:5006::/var/www/clients/client2/web4:/usr/sbin/jk_chrootsh

Thank you in advance for any help. I don't want to start experimenting at this stage by changing things around...especially since this is my first experience with ISPConfig.

till 20th October 2011 10:17

Your guess is right, the line in /etc/passwd is wrong as it contains the wrong shell. Please try to deactivate the shell user and then activate it again and check /etc/passwd after a few minutes if the shell is correct then.

LTxda 20th October 2011 18:34

Thank you. That did the trick.

I'll try to remember to test every shell user setup to ensure chroot was properly initiated.

till 20th October 2011 18:40

Most likely this has been fixed already in 3.0.4 beta, as there was a similar problem that we adressed. If you encounter that problem again with 3.0.4 final, please make a post in the bugtracker so we can check that again.

LTxda 20th October 2011 18:43

Understood and will do. I'll be using this feature a lot and will expand my usage into other features. Once the next update is released I'll continue testing. Thank you again.


All times are GMT +2. The time now is 19:49.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2014, vBulletin Solutions, Inc.