Table of Contents
Isilon as FTP server
helpful page https://community.emc.com/message/844739
I've used the referenced KB and I'm able to do whatever I want (i.e.: chroot all except certain users, chroot only certain users, use custom config, etc)
However, please note when using a custom config, the filename must match your full username that you use to login. In my case I logged in with a user 'YFISI\tohill'. So my custom config file is called 'YFISI\tohill' and NOT tohill.
In my setup below, only user 'YFISI\tohill' gets chroot and the chroot directory is /ifs/home/scratch as defined in its custom config file. All details below.
ftp config
yfvm-7111-2# isi ftp list accept-timeout 60 allow-anon-access NO allow-anon-upload YES allow-dirlists YES allow-downloads YES allow-local-access YES allow-writes YES always-chdir-homedir YES anon-chown-username root anon-root-path /ifs/home/ftp anon-umask 077 ascii-mode off connect-timeout 60 data-timeout 300 dirlist-localtime NO dirlist-names hide file-create-perm 0666 local-root-path local user home directory local-umask 077 server-to-server NO session-support YES session-timeout 300 user-config-dir /ifs/vsftpd/user_config denied-user-list (none) limit-anon-passwords NO anon-password-list (disabled) chroot-local-mode Only chroot the local users in the exception list chroot-exception-list YFISI\tohill
Content of my '/ifs/vsftpd/user_config' dir and the custom file for 'YFISI\tohill'
yfvm-7111-2# pwd /ifs/vsftpd/user_config yfvm-7111-2# ls -l total 26 -rw-r--r-- 1 root wheel 51 Oct 22 08:55 YFISI\tohill yfvm-7111-2# cat YFISI\\tohill local_root=/ifs/home/scratch chroot_local_user=yes
Permissions on the /ifs/home/scratch directory:
yfvm-7111-2# pwd /ifs/home yfvm-7111-2# ls -led scratch drwxrwxr-x + 2 root YFISI\domain use 26 Oct 22 09:21 scratch OWNER: user:root GROUP: group:YFISI\domain users 0: user:root allow dir_gen_read,dir_gen_write,dir_gen_execute,std_write_dac,delete_child 1: group:YFISI\domain users allow dir_gen_read,dir_gen_write,dir_gen_execute,delete_child 2: everyone allow dir_gen_read,dir_gen_execute
When I login with the 'YFISI\tohill' user, this is what I get:
Name (192.168.32.222:xxxxx): YFISI\tohill 331 Please specify the password. Password: 230 Login successful. Remote system type is UNIX. Using binary mode to transfer files. ftp> pwd Remote directory: / ftp> dir 229 Entering Extended Passive Mode (|||27988|). 150 Here comes the directory listing. -rw------- 1 ftp ftp 373 Oct 22 13:21 test.txt 226 Directory send OK.
This is basically the content of the '/ifs/home/scratch' directory.
Force users into correct folder
remove home directory
rm -rf /ifs/data/sdi/
create subdirectory in new location if required
mkdir /ifs/data/sony/sdi
create symlink to new location
ln -s /ifs/data/sony/sdi/ /ifs/data/sdi
re own folder
chown -R sony:ftp_users /ifs/data/sony/
Cron jobs
A few points to keep in minds:
- of course your jobs will be light-weighted and do no harm to the cluster…
- the crontab might get wiped when installing OneFS updates (even minor ones)
- you can't execute files from /ifs
- - but you can execute scripts as /bin/bash /ifs/path/to/my/script
- - if you put scripts or executables under a node's / or /var: these are small! and may get wiped, too.
- any node would do, but if it goes offline, there is no automated failover to another node (crontab is a basic UNIX thing)
Refer to this doc https://community.emc.com/docs/DOC-48465 for running CRON successfully on one node only
Configure a custom email quota notification template
If email notifications are enabled, you can configure custom templates for email notifications.
If the default email notification templates do not meet your needs, you can configure your own custom email notification templates using a combination of text and SmartQuotas variables.
Procedure
- Open a text editor and create a .txt file that includes any combination of text and OneFS email notification variables. -Save the template file as ASCII text or in ISO-8859-1 format. - Upload the file to an appropriate directory on the Isilon cluster. For example, /ifs/templates.
Example 1 Example of a custom quota email notification text file
The following example illustrates a custom email template to notify recipients about an exceeded quota.
Text-file contents with variables
The disk quota on directory <ISI_QUOTA_PATH> owned by <ISI_QUOTA_OWNER> was exceeded. The <ISI_QUOTA_TYPE> quota limit is <ISI_QUOTA_THRESHOLD>, and SmartQuotas </Q>
Map an email notification rule for a quota 325
Example 1 Example of a custom quota email notification text file (continued)
<ISI_QUOTA_USAGE> is in use. Please free some disk space by deleting unnecessary files. For more information, contact Jane Anderson in IT.
Email contents with resolved variables
The disk quota on directory /ifs/data/sales_tools/collateral owned by jsmith was exceeded. The hard quota limit is 10 GB, and 11 GB is in use. Please free some disk space by deleting unnecessary files. For more information, contact Jane Anderson in IT.
After you finish
To use the custom template, click Cluster Managements > General Settings > Email Settings, and select the custom template in the Event Notification Settings area.
Sync folder
rsync -av root@172.16.188.115:/ftp/flipfactory/nbcu /ifs/data/
Copy isilon node 1 into remote authorised keys
cat ~/.ssh/id_rsa.pub | ssh root@172.16.188.115 "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
Provision home directories with dot files
You can provision home directories.
Before you begin
To perform most configuration tasks, you must log on as a member of the SecurityAdmin role.
The skeleton directory, which is located at /usr/share/skel by default, contains a set of files that are copied to the user's home directory when a local user is created or when a user home directory is dynamically created during login. Files in the skeleton directory that begin with dot. are renamed to remove the dot prefix when they are copied to the user's home directory. For example, dot.cshrc is copied to the user's home directory as .cshrc. This format enables dot files in the skeleton directory to be viewable through the command-line interface without requiring the ls -a command.
For SMB shares that might use home directories that were provisioned with dot files, you can set an option to prevent users who connect to the share through SMB from viewing the dot files.
Setting home directories
isi auth users modify –user=bb
Command requires at least one argument.
Usage:
isi auth users modify { <user> | –uid <id> | –sid <sid> }
[--enabled <boolean>]
[{--expiry | -x} <timestamp>]
[--locked <boolean>]
[--email <string>]
[--gecos <string>]
[--home-directory <string>]
[--password <string>]
[--password-expires <boolean>]
[--primary-group <name> | --primary-group-gid <id> | --primary-group-sid <sid>]
[--prompt-password-change <boolean>]
[--shell <string>]
[--new-uid <integer>]
[--zone <string>]
[--add-group <name>]
[--add-gid <id>]
[--remove-group <name>]
[--remove-gid <id>]
[--provider <string>]
[--set-password]
[{--verbose | -v}]
[{--force | -f}]
[{--help | -h}]
See 'isi auth users modify --help' for more information.
Stop / Restart FTP
isi services vsftpd disable isi services vsftpd enable
