View source for Linux User & File Management
Jump to:
navigation
,
search
[[Category:Linux]] [[File:linux.png|thumb|350px]] == Basic Overview == When creating users on your server you may want to restrict their access on the server & its files. By default creating a user will also give them access to use SSH & FTP, yet this can be turned off / restricted by following the guide below. To Create a user you would normally use command (Which is fine as we can limit there access later on) useradd newuser === Setting a user to have admin permissions === After you have created a new user account you will want to add them to the "sudoer" file, this will give them full admin permissions like the root account (Only do this if you really want to / trust them) use nano to edit the file & add their account name (like the example screenshot below, but change newuser to their account name) nano /etc/sudoers [[File:sudoers.png|500px]] After you have finished adding the new account you will need to save the file "Ctrl + X" (To exit) it will then ask to save "y = yes" - "n = no" If you wish to fine tune the sudoers file visit here for advance uses - http://linux.die.net/man/5/sudoers &nbps &nbps === Restricting SSH access === To restric access to SSH for a user is very simple all you have to do is edit the "/etc/passwd" file nano /etc/passwd Once your are editing the file, you should notice the user you recently created is near or at the bottom of the list (Example line below) newuser:x:1008:1008::/home/newuser:/bin/false *The first part is the username, in this case "newuser" *The "x" means a password is set for the user *The two numbers have different meanings, the first number "1008" in this case is the User ID. The second number is the Group ID (Stored in /etc/group) *The "/home/newuser" is the users current home directory (We will cover more about this in the FTP part below) *The last part is the most important to this step "/bin/false" means they have "No" SSH access, it will be "/bin/sh" by default (Meaning they have SSH access), so change this from "/bin/sh" > "/bin/false" to disable SSH access for that user. &nbps &nbps == Users & FTP Access == By default we normally install ProFTPD as an FTP Server (The other common one is VSFTP) The config files for ProFTPD are in /etc/proftpd In this folder you will find the main config file "proftpd.conf" This file is easy to navigate wrong, in here you can set things such as * FTP Port * FTP Hostname + Welcome Message * Default Login Root Folder (Set to ~ if you wish to use Folder Jail (As mentioned below) * How many users can connect at one time * How many times they can try to connect (wrong password lockout) * Who has access * & many more There is also a file in /etc called "ftpusers" - This file is a list of users that are "NOT" allowed FTP access, feel free to edit this file & add users you wish not to have FTP access to your server nano /etc/ftpusers === Jailing Users in a folder === Jailing users in a folder is a very common technique for server sharing like web hosting, you can give users access to only their folder & they cannot get out of their folder. (Please read some of the points above if you wish to do this) You will have to edit your "proftpd.conf" file (or the vsftpd.conf file if you are using vsftpd instead) within that file you will see an option for default login root folder (If it is hashed out "#" unhash it & set it as "DefaultRoot ~" Now if you have already created your user great, if not see the steps above on creating a user (useradd username), Once you have created a user edit the "/etc/passwd" file & edit the home directory to the folder location you want e.g. /home/newuser (Make sure that user has permission on that folder, otherwise they wont be able to login (because they dont have access to that folder) You can check folder permissions either on PuTTy using "ls -l" or the GUI / easier way in WinSCP When you are connected via WinSCP you can right click on a folder & it will give you an option to enter a UID (User ID, as spoken about above) enter the users id to view/set their permissions on the folder, they will need at least Read & Execute on the folder in order for them to access the folder (You can set them the owner if you want to) [[File:winscpuserperm.png|350px]] ==== Folders & Group Access ==== As you see in the screenshot above, there are two permission types you can set on each file/folder, You can give groups access to folders you want e.g. a "TF2_Server" you want your "TF2Admins" to have access to, all you would do is create a group & add the users you want to be in that group to it. You then set the permissions on that folder e.g. "TF2Admins" as owner of the "TF2_Server" folder, then anyone in your "TF2Admins" group will have the access they should. use these commands to add a group & add users into that group groupadd TF2Admins usermod -a -G TF2Admins newuser
Return to
Linux User & File Management
.
Personal tools
Log in
Namespaces
Page
Discussion
Variants
Views
Read
View source
View history
Actions
Search
Navigation
Main page
Recent changes
Random page
Help
Categories
Linux
Windows
Source Based Servers
HLDS Based Servers
Minecraft
2047Servers Control Panel