<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: scponly rpms with chroot enabled added for rhel4</title>
	<atom:link href="http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/</link>
	<description>Security, Linux, Development</description>
	<pubDate>Tue, 06 Jan 2009 03:06:47 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Chris</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/comment-page-1/#comment-630</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Fri, 03 Oct 2008 15:48:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.justinsamuel.com/linux/server-security/10/scponly-rpms-with-chroot-enabled-added-for-rhel4#comment-630</guid>
		<description>Hello Justin,

I installed this for EL5, and I cannot get it, in the logs I see the following:

Oct  3 10:47:32 storage scponly[5385]: chroot dir not owned by root: /home/test2
Oct  3 10:47:32 storage sshd[5382]: pam_unix(sshd:session): session closed for user test2

Any thoughts?

Thanks for your help in advance :)</description>
		<content:encoded><![CDATA[<p>Hello Justin,</p>
<p>I installed this for EL5, and I cannot get it, in the logs I see the following:</p>
<p>Oct  3 10:47:32 storage scponly[5385]: chroot dir not owned by root: /home/test2<br />
Oct  3 10:47:32 storage sshd[5382]: pam_unix(sshd:session): session closed for user test2</p>
<p>Any thoughts?</p>
<p>Thanks for your help in advance :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: justin</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/comment-page-1/#comment-548</link>
		<dc:creator>justin</dc:creator>
		<pubDate>Mon, 11 Feb 2008 23:24:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.justinsamuel.com/linux/server-security/10/scponly-rpms-with-chroot-enabled-added-for-rhel4#comment-548</guid>
		<description>There could be conflicts using the el5 rpms on el4, but I have el4 rpms available, also (I should have linked to both before).

Here are the el4 rpms, with scponly in there:

http://downloads.justinsamuel.com/rpms/redhat/el4/en/i386/RPMS.js/</description>
		<content:encoded><![CDATA[<p>There could be conflicts using the el5 rpms on el4, but I have el4 rpms available, also (I should have linked to both before).</p>
<p>Here are the el4 rpms, with scponly in there:</p>
<p><a href="http://downloads.justinsamuel.com/rpms/redhat/el4/en/i386/RPMS.js/" rel="nofollow">http://downloads.justinsamuel.com/rpms/redhat/el4/en/i386/RPMS.js/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom McManus</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/comment-page-1/#comment-547</link>
		<dc:creator>Tom McManus</dc:creator>
		<pubDate>Mon, 11 Feb 2008 21:26:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.justinsamuel.com/linux/server-security/10/scponly-rpms-with-chroot-enabled-added-for-rhel4#comment-547</guid>
		<description>Any chance the el5 repo rpms will conflict with el4?</description>
		<content:encoded><![CDATA[<p>Any chance the el5 repo rpms will conflict with el4?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: justin</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/comment-page-1/#comment-525</link>
		<dc:creator>justin</dc:creator>
		<pubDate>Tue, 15 Jan 2008 20:06:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.justinsamuel.com/linux/server-security/10/scponly-rpms-with-chroot-enabled-added-for-rhel4#comment-525</guid>
		<description>Tom, sorry for the slow reply. The rpms and srpms are at:

http://downloads.justinsamuel.com/rpms/redhat/el5/en/i386/</description>
		<content:encoded><![CDATA[<p>Tom, sorry for the slow reply. The rpms and srpms are at:</p>
<p><a href="http://downloads.justinsamuel.com/rpms/redhat/el5/en/i386/" rel="nofollow">http://downloads.justinsamuel.com/rpms/redhat/el5/en/i386/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom McManus</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/comment-page-1/#comment-479</link>
		<dc:creator>Tom McManus</dc:creator>
		<pubDate>Fri, 21 Dec 2007 16:08:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.justinsamuel.com/linux/server-security/10/scponly-rpms-with-chroot-enabled-added-for-rhel4#comment-479</guid>
		<description>Hi, thanks for the great work on this, could you post the rpms? I would like to look at it and may need to make some modifications for our system. Thanks.</description>
		<content:encoded><![CDATA[<p>Hi, thanks for the great work on this, could you post the rpms? I would like to look at it and may need to make some modifications for our system. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: justin</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/comment-page-1/#comment-18</link>
		<dc:creator>justin</dc:creator>
		<pubDate>Tue, 05 Sep 2006 04:31:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.justinsamuel.com/linux/server-security/10/scponly-rpms-with-chroot-enabled-added-for-rhel4#comment-18</guid>
		<description>Hi,

Try setting the debug level of scponly, such as:

echo 2 &gt; /etc/scponly/debuglevel

and then check /var/log/secure or possibly other logs after an attempt to to connect.

Likely things that can go wrong include:

a) not having a minimally-working chroot for the user you are trying to scp with.

b) having the user's chroot directory writable by the user and/or not owned by root (security issue, scponlyc will intentionally fail in order to protect you when it detects an insecure chroot setup for using it).

c) not having scp located at /usr/bin/scp inside the user's chroot -- you'd need to rebuild the rpm on a differently-configured system to change this.  By default I believe it's looking in the same location in the user's chroot for scp as the binary resides on the system it was compiled on.  For Red Hat, which is what the rpm was compiled on, this will be /usr/bin/scp.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Try setting the debug level of scponly, such as:</p>
<p>echo 2 > /etc/scponly/debuglevel</p>
<p>and then check /var/log/secure or possibly other logs after an attempt to to connect.</p>
<p>Likely things that can go wrong include:</p>
<p>a) not having a minimally-working chroot for the user you are trying to scp with.</p>
<p>b) having the user&#8217;s chroot directory writable by the user and/or not owned by root (security issue, scponlyc will intentionally fail in order to protect you when it detects an insecure chroot setup for using it).</p>
<p>c) not having scp located at /usr/bin/scp inside the user&#8217;s chroot &#8212; you&#8217;d need to rebuild the rpm on a differently-configured system to change this.  By default I believe it&#8217;s looking in the same location in the user&#8217;s chroot for scp as the binary resides on the system it was compiled on.  For Red Hat, which is what the rpm was compiled on, this will be /usr/bin/scp.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christopher</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/comment-page-1/#comment-17</link>
		<dc:creator>Christopher</dc:creator>
		<pubDate>Tue, 05 Sep 2006 03:07:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.justinsamuel.com/linux/server-security/10/scponly-rpms-with-chroot-enabled-added-for-rhel4#comment-17</guid>
		<description>Hello,

we have tested your SCPOnly RPM on our RHE4 box but it does not seem to work. Using WSFTP, connecting to our SSH port, 2222 we get the following error from WSFTP:

Error 842c0000 receiving sftp packet
error 842c0000 initializing sftp protocol
Sending channel close message for channel 0760a2ce
SSH Transport closed.

And our server logs show:

Sep  5 10:04:35 s1 sshd[9771]: subsystem request for sftp
Sep  5 03:04:35 s1 scponly[9772]: running: /usr/libexec/openssh/sftp-server (username: s1(10001), IP/port:  6939 2222)
Sep  5 03:04:35 s1 scponly[9772]: failed: /usr/libexec/openssh/sftp-server with error No such file or directory(2) (username: s1(10001), IP/port:  6939 2222)

Any ideas?</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>we have tested your SCPOnly RPM on our RHE4 box but it does not seem to work. Using WSFTP, connecting to our SSH port, 2222 we get the following error from WSFTP:</p>
<p>Error 842c0000 receiving sftp packet<br />
error 842c0000 initializing sftp protocol<br />
Sending channel close message for channel 0760a2ce<br />
SSH Transport closed.</p>
<p>And our server logs show:</p>
<p>Sep  5 10:04:35 s1 sshd[9771]: subsystem request for sftp<br />
Sep  5 03:04:35 s1 scponly[9772]: running: /usr/libexec/openssh/sftp-server (username: s1(10001), IP/port:  6939 2222)<br />
Sep  5 03:04:35 s1 scponly[9772]: failed: /usr/libexec/openssh/sftp-server with error No such file or directory(2) (username: s1(10001), IP/port:  6939 2222)</p>
<p>Any ideas?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
