1 |
So I'm slowly getting my gentoo server in shape... and adding my first |
2 |
virtual host client (heh, my cousin's DJ business website). I've set up |
3 |
a vhost mapping in apache for her doc root and I've added her domain to |
4 |
vpopmail. All is going well... |
5 |
|
6 |
Except, it has occured to me that I would like to give her ssh/sftp |
7 |
access (I don't want to be making changes for her every other day). I've |
8 |
set up a user on the machine, but it makes me a little nervous. Not that |
9 |
I'm worried about my cousin, but she's been known to give her password |
10 |
to techie friends so that they can "help". |
11 |
|
12 |
So, my question is, is there a way to restrict her user's movements in |
13 |
the file system? It would be nice if she were only able to work within |
14 |
her home directory. |
15 |
|
16 |
When I log into my account with my old hosting company, I can cd up to |
17 |
"/", but it's obviously not the machine's "/"... there's only about ten |
18 |
commands under /bin and only our users under /home. Is this a UML setup? |
19 |
Is there some other way to restrict movement? |
20 |
|
21 |
Or maybe I should start making all sensitive files chown root and chmod 700? |
22 |
|
23 |
Any all thoughts much appreciated... |
24 |
|
25 |
Ben |