Gentoo Archives: gentoo-user-es

From: krs <krs@×××××××××.org>
To: gentoo-user-es@l.g.o
Subject: Re: [gentoo-user-es] evitar que usuario acceda a shell, permitirle cvs
Date: Sun, 18 Apr 2004 18:02:41
Message-Id: 200404181959.13181.krs@logicmind.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Prueba con añadir a tu fichero /etc/ssh/sshd_config una linea que ponga
5 DenyUsers y la lista de usuarios que no quieres que accedan por ssh separados
6 por espacios, supongo que eso servirá.
7
8 - -
9 DenyUsers
10 This keyword can be followed by a list of user name patterns,
11 separated by spaces. Login is disallowed for user names that match one of
12 the patterns. `*' and `?' can be used as wildcards in the patterns. Only
13 user names are valid; a numerical user ID is not recognized. By default,
14 login is allowed for all users. If the pattern takes the form USER@HOST then
15 USER and HOST are separately checked, restricting logins to particular users
16 from particular hosts.
17 - -
18 Sacado de man sshd_config :)
19
20 Saludos
21
22
23 El Sábado, 17 de Abril de 2004 19:29, d2clon@×××××××××××××××.org escribió:
24 > nada gente..
25 > he hecho lo que me comentais
26 > le he definido como shell -> /bin/false
27 > y he creado la entrada en /etc/shells
28 >
29 > y en efecto no consigue acceder a la shell
30 > =======================================0
31 > trucha@biit tmp $ ssh -lotoanonimo susana
32 > otoanonimo@susana's password:
33 > Last login: Mon Jan 17 17:48:34 2005 from 10.0.0.5
34 > Connection to susana closed.
35 > =======================================0
36 >
37 > pero .. :
38 > =======================================0
39 > trucha@biit tmp $ export CVSROOT="otoanonimo@susana:/home/cvs/rep"
40 > trucha@biit tmp $ cvs co oto
41 > otoanonimo@susana's password:
42 > cvs [checkout aborted]: end of file from server (consult above messages if
43 > any)
44 > =======================================0
45 >
46 > ya veis.. no consigue conectarse para checkout el módulo
47 > pone que consulte noseque mensajes.. pero no se a que log se refiere
48 > me he fijado que en el servidor no hay ningun log del cvs :/
49 >
50 > d2clon
51 >
52 > On Saturday 17 April 2004 17:33, Alberto Garcia Hierro wrote:
53 > > -----BEGIN PGP SIGNED MESSAGE-----
54 > > Hash: SHA1
55 > >
56 > > El Sábado 17 Abril 2004 16:39, Alberto F. Capel escribió:
57 > > > podrías ponerles de shell /bin/false en /etc/passwd.
58 > > >
59 > > > Espero que funcione.
60 > >
61 > > y añadir /bin/false en /etc/shells
62 > >
63 > > - --
64 > > /* Alberto García Hierro (Skyhusker) */
65 > > -----BEGIN PGP SIGNATURE-----
66 > > Version: GnuPG v1.2.4 (GNU/Linux)
67 > >
68 > > iD8DBQFAgU5S4O6JklHkL2cRAi0hAJ9gspJkwPBN/lGFul2ocUb+cneMRwCgigSf
69 > > 2NOWruxPNuIHbcf7YKBjZd4=
70 > > =XrG4
71 > > -----END PGP SIGNATURE-----
72 >
73 > --
74 > gentoo-user-es@g.o mailing list
75
76 - --
77 ####################################
78 # http://logicmind.org #
79 # Usuario Linux registrado #303351 #
80 # Clave publica PGP disponible en: #
81 # http://krs.logicmind.org/krs.asc #
82 ####################################
83 -----BEGIN PGP SIGNATURE-----
84 Version: GnuPG v1.2.4 (GNU/Linux)
85
86 iD8DBQFAgsHukXEYdwsx9VURAhFJAJ9rMT46vZcMoEb+Li0RsicBMzIIFACeP0VD
87 uqr6LrmnVf1jhnpmBn0w/6Y=
88 =X3Oe
89 -----END PGP SIGNATURE-----
90
91 --
92 gentoo-user-es@g.o mailing list

Replies

Subject Author
Re: [gentoo-user-es] evitar que usuario acceda a shell, permitirle cvs "d2clon@×××××××××××××××.org" <d2clon@×××××××××××××××.org>