How To Configure PureFTPd To Accept TLS Sessions On OpenSUSE 11.3
How To Configure PureFTPd To Accept TLS Sessions On OpenSUSE 11.3Version 1.0 FTP is a very insecure protocol because all passwords and all data are transferred in clear text. By using TLS, the whole communication can be encrypted, thus making FTP much more secure. This article explains how to configure PureFTPd to accept TLS sessions on an OpenSUSE 11.3 server. I do not issue any guarantee that this will work for you!
1 Preliminary NoteYou should have a working PureFTPd setup on your OpenSUSE 11.3 server, e.g. as shown in this tutorial: Virtual Hosting With PureFTPd And MySQL (Incl. Quota And Bandwidth Management) On OpenSUSE 11.3.
2 Installing OpenSSLOpenSSL is needed by TLS; to install OpenSSL, we simply run: yast2 -i openssl
3 Configuring PureFTPdOpen /etc/pure-ftpd/pure-ftpd.conf... vi /etc/pure-ftpd/pure-ftpd.conf If you want to allow FTP and TLS sessions, set TLS to 1:
If you want to accept TLS sessions only (no FTP), set TLS to 2:
To not allow TLS at all (only FTP), set TLS to 0:
4 Creating The SSL Certificate For TLSIn order to use TLS, we must create an SSL certificate. I create it in /etc/ssl/private/, therefore I create that directory first: mkdir -p /etc/ssl/private/ Afterwards, we can generate the SSL certificate as follows: openssl req -x509 -nodes -days 7300 -newkey rsa:2048 -keyout /etc/ssl/private/pure-ftpd.pem -out /etc/ssl/private/pure-ftpd.pem Country Name (2 letter code) [AU]: <-- Enter your Country Name (e.g., "DE"). Change the permissions of the SSL certificate: chmod 600 /etc/ssl/private/pure-ftpd.pem Finally restart PureFTPd: /etc/init.d/pure-ftpd restart That's it. You can now try to connect using your FTP client; however, you should configure your FTP client to use TLS - see the next chapter how to do this with FileZilla.
5 Configuring FileZilla For TLSIn order to use FTP with TLS, you need an FTP client that supports TLS, such as FileZilla. In FileZilla, open the Server Manager:
Select the server that uses PureFTPd with TLS; in the Server Type drop-down menu, select FTPES instead of normal FTP: Now you can connect to the server. If you do this for the first time, you must accept the server's new SSL certificate: If everything goes well, you should now be logged in on the server:
6 Links
|







Recent comments
1 day 10 hours ago
1 day 13 hours ago
1 day 14 hours ago
1 day 15 hours ago
1 day 17 hours ago
1 day 18 hours ago
1 day 20 hours ago
2 days 11 hours ago
2 days 12 hours ago
2 days 16 hours ago