Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, in fact I update every 6 months ever since I started using OpenBSD back in 1999. The problem isn't setting up OpenSSH to offer chrooted sftp access. My gripe is that the sftp subsystem for no solid reason requires that a user directory is root-owned in order to chroot even when the user account experiences a forced sftp response (that is, denying shell access, making it an sftp-only account).


the reason the directory must be root owned, is that the chroot directive is also used for normal ssh sessions, where a user owned chroot directory can mean that a user can break out.


Yeah I'm aware of that part. I submitted a number of design suggestions, as well as a patch, to the OBSD devs which disregarded the root ownership check if the SFTP subsystem was called by a connecting client, but no one bothered even discussing the topic. The whole /home/user/user/ directory nesting just rubs me the wrong way.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: