This is an old revision of the document!
Isilon as FTP server
helpful page https://community.emc.com/message/844739
I've used the referenced KB and I'm able to do whatever I want (i.e.: chroot all except certain users, chroot only certain users, use custom config, etc)
However, please note when using a custom config, the filename must match your full username that you use to login. In my case I logged in with a user 'YFISI\tohill'. So my custom config file is called 'YFISI\tohill' and NOT tohill.
In my setup below, only user 'YFISI\tohill' gets chroot and the chroot directory is /ifs/home/scratch as defined in its custom config file. All details below.
ftp config
yfvm-7111-2# isi ftp list accept-timeout 60 allow-anon-access NO allow-anon-upload YES allow-dirlists YES allow-downloads YES allow-local-access YES allow-writes YES always-chdir-homedir YES anon-chown-username root anon-root-path /ifs/home/ftp anon-umask 077 ascii-mode off connect-timeout 60 data-timeout 300 dirlist-localtime NO dirlist-names hide file-create-perm 0666 local-root-path local user home directory local-umask 077 server-to-server NO session-support YES session-timeout 300 user-config-dir /ifs/vsftpd/user_config denied-user-list (none) limit-anon-passwords NO anon-password-list (disabled) chroot-local-mode Only chroot the local users in the exception list chroot-exception-list YFISI\tohill
Content of my '/ifs/vsftpd/user_config' dir and the custom file for 'YFISI\tohill'
yfvm-7111-2# pwd /ifs/vsftpd/user_config yfvm-7111-2# ls -l total 26 -rw-r--r-- 1 root wheel 51 Oct 22 08:55 YFISI\tohill yfvm-7111-2# cat YFISI\\tohill local_root=/ifs/home/scratch chroot_local_user=yes
Permissions on the /ifs/home/scratch directory:
yfvm-7111-2# pwd /ifs/home yfvm-7111-2# ls -led scratch drwxrwxr-x + 2 root YFISI\domain use 26 Oct 22 09:21 scratch OWNER: user:root GROUP: group:YFISI\domain users 0: user:root allow dir_gen_read,dir_gen_write,dir_gen_execute,std_write_dac,delete_child 1: group:YFISI\domain users allow dir_gen_read,dir_gen_write,dir_gen_execute,delete_child 2: everyone allow dir_gen_read,dir_gen_execute
When I login with the 'YFISI\tohill' user, this is what I get:
Name (192.168.32.222:xxxxx): YFISI\tohill 331 Please specify the password. Password: 230 Login successful. Remote system type is UNIX. Using binary mode to transfer files. ftp> pwd Remote directory: / ftp> dir 229 Entering Extended Passive Mode (|||27988|). 150 Here comes the directory listing. -rw------- 1 ftp ftp 373 Oct 22 13:21 test.txt 226 Directory send OK.
This is basically the content of the '/ifs/home/scratch' directory.
