<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments for Justin Samuel</title>
	<link>http://www.justinsamuel.com</link>
	<description>Security, Linux, Development</description>
	<pubDate>Fri, 21 Nov 2008 10:59:38 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>Comment on scponly rpms with chroot enabled added for rhel4 by justin</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-548</link>
		<dc:creator>justin</dc:creator>
		<pubDate>Mon, 11 Feb 2008 23:24:22 +0000</pubDate>
		<guid>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-548</guid>
		<description>There could be conflicts using the el5 rpms on el4, but I have el4 rpms available, also (I should have linked to both before).

Here are the el4 rpms, with scponly in there:

http://downloads.justinsamuel.com/rpms/redhat/el4/en/i386/RPMS.js/</description>
		<content:encoded><![CDATA[<p>There could be conflicts using the el5 rpms on el4, but I have el4 rpms available, also (I should have linked to both before).</p>
<p>Here are the el4 rpms, with scponly in there:</p>
<p><a href="http://downloads.justinsamuel.com/rpms/redhat/el4/en/i386/RPMS.js/" rel="nofollow">http://downloads.justinsamuel.com/rpms/redhat/el4/en/i386/RPMS.js/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on scponly rpms with chroot enabled added for rhel4 by Tom McManus</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-547</link>
		<dc:creator>Tom McManus</dc:creator>
		<pubDate>Mon, 11 Feb 2008 21:26:33 +0000</pubDate>
		<guid>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-547</guid>
		<description>Any chance the el5 repo rpms will conflict with el4?</description>
		<content:encoded><![CDATA[<p>Any chance the el5 repo rpms will conflict with el4?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on scponly rpms with chroot enabled added for rhel4 by justin</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-525</link>
		<dc:creator>justin</dc:creator>
		<pubDate>Tue, 15 Jan 2008 20:06:36 +0000</pubDate>
		<guid>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-525</guid>
		<description>Tom, sorry for the slow reply. The rpms and srpms are at:

http://downloads.justinsamuel.com/rpms/redhat/el5/en/i386/</description>
		<content:encoded><![CDATA[<p>Tom, sorry for the slow reply. The rpms and srpms are at:</p>
<p><a href="http://downloads.justinsamuel.com/rpms/redhat/el5/en/i386/" rel="nofollow">http://downloads.justinsamuel.com/rpms/redhat/el5/en/i386/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on scponly rpms with chroot enabled added for rhel4 by Tom McManus</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-479</link>
		<dc:creator>Tom McManus</dc:creator>
		<pubDate>Fri, 21 Dec 2007 16:08:54 +0000</pubDate>
		<guid>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-479</guid>
		<description>Hi, thanks for the great work on this, could you post the rpms? I would like to look at it and may need to make some modifications for our system. Thanks.</description>
		<content:encoded><![CDATA[<p>Hi, thanks for the great work on this, could you post the rpms? I would like to look at it and may need to make some modifications for our system. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on HOWTO: Setup SSL certificates for mail services (pop3s, imaps, smtps) on Plesk / Courier-Imap / Qmail by joshua</title>
		<link>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/#comment-399</link>
		<dc:creator>joshua</dc:creator>
		<pubDate>Sat, 01 Dec 2007 22:20:41 +0000</pubDate>
		<guid>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/#comment-399</guid>
		<description>Hallo Justin

Thank you for your work and this site.
regards,
joshua</description>
		<content:encoded><![CDATA[<p>Hallo Justin</p>
<p>Thank you for your work and this site.<br />
regards,<br />
joshua</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on HOWTO: Setup SSL certificates for mail services (pop3s, imaps, smtps) on Plesk / Courier-Imap / Qmail by noman</title>
		<link>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/#comment-395</link>
		<dc:creator>noman</dc:creator>
		<pubDate>Thu, 29 Nov 2007 18:27:22 +0000</pubDate>
		<guid>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/#comment-395</guid>
		<description>I did not get the pop3s and imaps part to work i get the following error, any suggestions: 

CONNECTED(00000003)
write:errno=54</description>
		<content:encoded><![CDATA[<p>I did not get the pop3s and imaps part to work i get the following error, any suggestions: </p>
<p>CONNECTED(00000003)<br />
write:errno=54</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on HOWTO: Setup SSL certificates for mail services (pop3s, imaps, smtps) on Plesk / Courier-Imap / Qmail by David</title>
		<link>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/#comment-48</link>
		<dc:creator>David</dc:creator>
		<pubDate>Mon, 20 Aug 2007 22:06:49 +0000</pubDate>
		<guid>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/#comment-48</guid>
		<description>Thanks for the walk through that is a great help.</description>
		<content:encoded><![CDATA[<p>Thanks for the walk through that is a great help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on scponly rpms with chroot enabled added for rhel4 by justin</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-18</link>
		<dc:creator>justin</dc:creator>
		<pubDate>Tue, 05 Sep 2006 04:31:07 +0000</pubDate>
		<guid>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-18</guid>
		<description>Hi,

Try setting the debug level of scponly, such as:

echo 2 &gt; /etc/scponly/debuglevel

and then check /var/log/secure or possibly other logs after an attempt to to connect.

Likely things that can go wrong include:

a) not having a minimally-working chroot for the user you are trying to scp with.

b) having the user's chroot directory writable by the user and/or not owned by root (security issue, scponlyc will intentionally fail in order to protect you when it detects an insecure chroot setup for using it).

c) not having scp located at /usr/bin/scp inside the user's chroot -- you'd need to rebuild the rpm on a differently-configured system to change this.  By default I believe it's looking in the same location in the user's chroot for scp as the binary resides on the system it was compiled on.  For Red Hat, which is what the rpm was compiled on, this will be /usr/bin/scp.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Try setting the debug level of scponly, such as:</p>
<p>echo 2 > /etc/scponly/debuglevel</p>
<p>and then check /var/log/secure or possibly other logs after an attempt to to connect.</p>
<p>Likely things that can go wrong include:</p>
<p>a) not having a minimally-working chroot for the user you are trying to scp with.</p>
<p>b) having the user&#8217;s chroot directory writable by the user and/or not owned by root (security issue, scponlyc will intentionally fail in order to protect you when it detects an insecure chroot setup for using it).</p>
<p>c) not having scp located at /usr/bin/scp inside the user&#8217;s chroot &#8212; you&#8217;d need to rebuild the rpm on a differently-configured system to change this.  By default I believe it&#8217;s looking in the same location in the user&#8217;s chroot for scp as the binary resides on the system it was compiled on.  For Red Hat, which is what the rpm was compiled on, this will be /usr/bin/scp.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on scponly rpms with chroot enabled added for rhel4 by Christopher</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-17</link>
		<dc:creator>Christopher</dc:creator>
		<pubDate>Tue, 05 Sep 2006 03:07:42 +0000</pubDate>
		<guid>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comment-17</guid>
		<description>Hello,

we have tested your SCPOnly RPM on our RHE4 box but it does not seem to work. Using WSFTP, connecting to our SSH port, 2222 we get the following error from WSFTP:

Error 842c0000 receiving sftp packet
error 842c0000 initializing sftp protocol
Sending channel close message for channel 0760a2ce
SSH Transport closed.

And our server logs show:

Sep  5 10:04:35 s1 sshd[9771]: subsystem request for sftp
Sep  5 03:04:35 s1 scponly[9772]: running: /usr/libexec/openssh/sftp-server (username: s1(10001), IP/port:  6939 2222)
Sep  5 03:04:35 s1 scponly[9772]: failed: /usr/libexec/openssh/sftp-server with error No such file or directory(2) (username: s1(10001), IP/port:  6939 2222)

Any ideas?</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>we have tested your SCPOnly RPM on our RHE4 box but it does not seem to work. Using WSFTP, connecting to our SSH port, 2222 we get the following error from WSFTP:</p>
<p>Error 842c0000 receiving sftp packet<br />
error 842c0000 initializing sftp protocol<br />
Sending channel close message for channel 0760a2ce<br />
SSH Transport closed.</p>
<p>And our server logs show:</p>
<p>Sep  5 10:04:35 s1 sshd[9771]: subsystem request for sftp<br />
Sep  5 03:04:35 s1 scponly[9772]: running: /usr/libexec/openssh/sftp-server (username: s1(10001), IP/port:  6939 2222)<br />
Sep  5 03:04:35 s1 scponly[9772]: failed: /usr/libexec/openssh/sftp-server with error No such file or directory(2) (username: s1(10001), IP/port:  6939 2222)</p>
<p>Any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on HOWTO: Setup SSL certificates for mail services (pop3s, imaps, smtps) on Plesk / Courier-Imap / Qmail by neo</title>
		<link>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/#comment-5</link>
		<dc:creator>neo</dc:creator>
		<pubDate>Mon, 12 Jun 2006 02:09:51 +0000</pubDate>
		<guid>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/#comment-5</guid>
		<description>Hi :

   About the pop3s for plesk, i was still not run ok!
   do you have detail step can offer?
 
   Thanks!
   Neo</description>
		<content:encoded><![CDATA[<p>Hi :</p>
<p>   About the pop3s for plesk, i was still not run ok!<br />
   do you have detail step can offer?</p>
<p>   Thanks!<br />
   Neo</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.288 seconds -->
