Site Tools


arqiva:isilon_as_ftp_server

This is an old revision of the document!


Isilon as FTP server

helpful page https://community.emc.com/message/844739

I've used the referenced KB and I'm able to do whatever I want (i.e.: chroot all except certain users, chroot only certain users, use custom config, etc)

However, please note when using a custom config, the filename must match your full username that you use to login. In my case I logged in with a user 'YFISI\tohill'. So my custom config file is called 'YFISI\tohill' and NOT tohill.

In my setup below, only user 'YFISI\tohill' gets chroot and the chroot directory is /ifs/home/scratch as defined in its custom config file. All details below.

ftp config

  yfvm-7111-2# isi ftp list  
  accept-timeout         60  
  allow-anon-access      NO  
  allow-anon-upload      YES  
  allow-dirlists         YES  
  allow-downloads        YES  
  allow-local-access     YES  
  allow-writes           YES  
  always-chdir-homedir   YES  
  anon-chown-username    root  
  anon-root-path         /ifs/home/ftp  
  anon-umask             077  
  ascii-mode             off  
  connect-timeout        60  
  data-timeout           300  
  dirlist-localtime      NO  
  dirlist-names          hide  
  file-create-perm       0666  
  local-root-path        local user home directory  
  local-umask            077  
  server-to-server       NO  
  session-support        YES  
  session-timeout        300  
  user-config-dir        /ifs/vsftpd/user_config  
  
  denied-user-list       (none)  

  limit-anon-passwords   NO  
  anon-password-list     (disabled)  

  chroot-local-mode      Only chroot the local users in the exception list  
  chroot-exception-list  YFISI\tohill  

Content of my '/ifs/vsftpd/user_config' dir and the custom file for 'YFISI\tohill'

  yfvm-7111-2# pwd  
  /ifs/vsftpd/user_config  
  yfvm-7111-2# ls -l  
  total 26  
  -rw-r--r--    1 root  wheel  51 Oct 22 08:55 YFISI\tohill  
  yfvm-7111-2# cat YFISI\\tohill  
  local_root=/ifs/home/scratch  
  chroot_local_user=yes  

Permissions on the /ifs/home/scratch directory:

  yfvm-7111-2# pwd  
  /ifs/home  
  yfvm-7111-2# ls -led scratch  
  drwxrwxr-x +  2 root  YFISI\domain use  26 Oct 22 09:21 scratch  
   OWNER: user:root  
   GROUP: group:YFISI\domain users  
   0: user:root allow dir_gen_read,dir_gen_write,dir_gen_execute,std_write_dac,delete_child  
   1: group:YFISI\domain users allow dir_gen_read,dir_gen_write,dir_gen_execute,delete_child  
   2: everyone allow dir_gen_read,dir_gen_execute  

When I login with the 'YFISI\tohill' user, this is what I get:

  Name (192.168.32.222:xxxxx): YFISI\tohill  
  331 Please specify the password.  
  Password:  
  230 Login successful.  
  Remote system type is UNIX.  
  Using binary mode to transfer files.  
  ftp> pwd  
  Remote directory: /  
  ftp> dir  
  229 Entering Extended Passive Mode (|||27988|).  
  150 Here comes the directory listing.  
  -rw-------    1 ftp      ftp           373 Oct 22 13:21 test.txt  
  226 Directory send OK.  

This is basically the content of the '/ifs/home/scratch' directory.

arqiva/isilon_as_ftp_server.1450009709.txt.gz · Last modified: (external edit) · Currently locked by: 216.73.216.236,192.168.2.28