Linux User & File Management
From 2047Servers Support
| Line 46: | Line 46: | ||
*The first part is the username, in this case "newuser" | *The first part is the username, in this case "newuser" | ||
*The "x" means a password is set for the user | *The "x" means a password is set for the user | ||
| − | The two numbers have different meanings, the first number "1008" in this case is the User ID. The second number is the Group ID (Stored in /etc/group) | + | *The two numbers have different meanings, the first number "1008" in this case is the User ID. The second number is the Group ID (Stored in /etc/group) |
| − | The "/home/newuser" is the users current home directory (We will cover more about this in the FTP part below) | + | *The "/home/newuser" is the users current home directory (We will cover more about this in the FTP part below) |
| − | The last part is the most important to this step "/bin/false" means they have "No" SSH access, it will be "/bin/sh" by default (Meaning they have SSH access), so change this from "/bin/sh" > "/bin/false" to disable SSH access for that user. | + | *The last part is the most important to this step "/bin/false" means they have "No" SSH access, it will be "/bin/sh" by default (Meaning they have SSH access), so change this from "/bin/sh" > "/bin/false" to disable SSH access for that user. |
| Line 55: | Line 55: | ||
== Users & FTP Access == | == Users & FTP Access == | ||
| + | |||
| + | By default we normally install ProFTPD as an FTP Server (The other common one is VSFTP) | ||
| + | |||
| + | The config files for ProFTPD are in /etc/proftpd | ||
| + | |||
| + | In this folder you will find the main config file "proftpd.conf" | ||
| + | |||
| + | This file is easy to navigate wrong, in here you can set things such as | ||
| + | |||
| + | * FTP Port | ||
| + | * FTP Hostname + Welcome Message | ||
| + | * Default Login Root Folder (Set to ~ if you wish to use Folder Jail (As mentioned below) | ||
| + | * How many users can connect at one time | ||
| + | * How many times they can try to connect (wrong password lockout) | ||
| + | * Who has access | ||
| + | * & many more | ||
| + | |||
| + | There is also a file in /etc called "ftpusers" - This file is a list of users that are "NOT" allowed FTP access, feel free to edit this file & add users you wish not to have FTP access to your server | ||
| + | |||
| + | nano /etc/ftpusers | ||
| + | |||
| + | === Jailing Users in a folder === | ||
| + | |||
| + | Jailing users in a folder is a very common technique for server sharing like web hosting, you can give users access to only their folder & they cannot get out of their folder. (Please read some of the points above if you wish to do this) | ||
| + | |||
| + | You will have to edit your "proftpd.conf" file (other vsftpd.conf file if you are using vsftpd instead) within that file you will see an option for default login root folder (If it is hashed out "#" unhash it & set it as "DefaultRoot ~" | ||
| + | |||
| + | Now if you have already created your user great, if not see the steps above on creating a user (useradd username), Once you have created a user edit the "/etc/passwd" file & edit the home directory to the folder location you want e.g. /home/newuser (Make sure that user has permission on that folder, otherwise they wont be able to login (because they dont have access to that folder) | ||
| + | |||
| + | You can check folder permissions either on PuTTy using "ls -l" or the GUI / easier way in WinSCP | ||
| + | |||
| + | When you are connected via WinSCP you can right click on a folder & it will give you an option to enter a UID (User ID, as spoken about above) enter the users id to view/set their permissions on the folder, they will need at least Read & Execute on the folder in order for them to access the folder (You can set them the owner if you want to) | ||
| + | |||
| + | [[File:winscpuserperm.png|thumb|350px]] | ||