Modify

Ticket #4573 (closed defect: wontfix)

Opened 12 months ago

Last modified 11 months ago

FTP access error

Reported by: papp.gyula@… Owned by: jamor@…
Milestone: 2.2.X Component: ftp
Severity: normal Keywords: ftp assess error
Cc:

Description

Dear Support! I find that the FTP access I set as follows: 1) The user only has access to your home directory 2) The user can access the samba shares and all other users folder, at least read permissions.

I think this is not in compliance. The good solutions: 1) The user's home directory of the FTP protocol, only to gain access. 2) The user of the FTP protocol to share Zentyalban allowed to access the card is set to be authorized.

Attachments

FTP_Setup.png Download (143.0 KB) - added by papp.gyula@… 12 months ago.
FTP setup screen shot
tiszacash.zentyal.log.tar Download (36.0 KB) - added by papp.gyula@… 12 months ago.
zentyal log for FTP permission problems

Change History

Changed 12 months ago by papp.gyula@…

FTP setup screen shot

Changed 12 months ago by papp.gyula@…

zentyal log for FTP permission problems

comment:1 Changed 12 months ago by jamor@…

  • Status changed from new to accepted

comment:2 Changed 12 months ago by jamor@…

  • Status changed from accepted to closed
  • Resolution set to invalid
The user can access the samba shares and all other users folder, at least read permissions. 

This is normal, ftp access works though filesystem permissions. Samba shares have the permissions you give them, so if in the acls you allow the ftp user access, it can access. The same for the user directories, the user (through ftp or by shell) will have the access granted by the file permissions.

Regards,

Javier

comment:3 Changed 12 months ago by papp.gyula@…

  • Status changed from closed to reopened
  • Resolution invalid deleted

Dear Javier! I understand that I think that's okay, but then what good is the FTP service? Do you think that the cases it is sufficient that only the user's home directory, you can use FTP access? I understand there is no other solution if you do not want the user to other library sites otherwise prohibited to access the FTP service. The solution is used to access the home and the rights granted by libraries. The current solution to each directory eg average user can access semi certainly not a good solution. Gyula

comment:4 Changed 11 months ago by jamor@…

  • Status changed from reopened to closed
  • Resolution set to wontfix

If you want to limit the ftp user you can use the option for chroot to the user home. However I warn you that in zentyal-ftp 2.3 is not longer available, due that the new version vsftpd ahs removed this feature.

View

Add a comment

Modify Ticket

Change Properties
<Author field>
Action
as closed
The resolution will be deleted. Next status will be 'reopened'
Author


E-mail address and user name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.