This is an old revision of the document!
Table of Contents
Isilon as FTP server
helpful page https://community.emc.com/message/844739
I've used the referenced KB and I'm able to do whatever I want (i.e.: chroot all except certain users, chroot only certain users, use custom config, etc)
However, please note when using a custom config, the filename must match your full username that you use to login. In my case I logged in with a user 'YFISI\tohill'. So my custom config file is called 'YFISI\tohill' and NOT tohill.
In my setup below, only user 'YFISI\tohill' gets chroot and the chroot directory is /ifs/home/scratch as defined in its custom config file. All details below.
ftp config
yfvm-7111-2# isi ftp list accept-timeout 60 allow-anon-access NO allow-anon-upload YES allow-dirlists YES allow-downloads YES allow-local-access YES allow-writes YES always-chdir-homedir YES anon-chown-username root anon-root-path /ifs/home/ftp anon-umask 077 ascii-mode off connect-timeout 60 data-timeout 300 dirlist-localtime NO dirlist-names hide file-create-perm 0666 local-root-path local user home directory local-umask 077 server-to-server NO session-support YES session-timeout 300 user-config-dir /ifs/vsftpd/user_config denied-user-list (none) limit-anon-passwords NO anon-password-list (disabled) chroot-local-mode Only chroot the local users in the exception list chroot-exception-list YFISI\tohill
Content of my '/ifs/vsftpd/user_config' dir and the custom file for 'YFISI\tohill'
yfvm-7111-2# pwd /ifs/vsftpd/user_config yfvm-7111-2# ls -l total 26 -rw-r--r-- 1 root wheel 51 Oct 22 08:55 YFISI\tohill yfvm-7111-2# cat YFISI\\tohill local_root=/ifs/home/scratch chroot_local_user=yes
Permissions on the /ifs/home/scratch directory:
yfvm-7111-2# pwd /ifs/home yfvm-7111-2# ls -led scratch drwxrwxr-x + 2 root YFISI\domain use 26 Oct 22 09:21 scratch OWNER: user:root GROUP: group:YFISI\domain users 0: user:root allow dir_gen_read,dir_gen_write,dir_gen_execute,std_write_dac,delete_child 1: group:YFISI\domain users allow dir_gen_read,dir_gen_write,dir_gen_execute,delete_child 2: everyone allow dir_gen_read,dir_gen_execute
When I login with the 'YFISI\tohill' user, this is what I get:
Name (192.168.32.222:xxxxx): YFISI\tohill 331 Please specify the password. Password: 230 Login successful. Remote system type is UNIX. Using binary mode to transfer files. ftp> pwd Remote directory: / ftp> dir 229 Entering Extended Passive Mode (|||27988|). 150 Here comes the directory listing. -rw------- 1 ftp ftp 373 Oct 22 13:21 test.txt 226 Directory send OK.
This is basically the content of the '/ifs/home/scratch' directory.
Force users into correct folder
remove home directory
rm -rf /ifs/data/sdi/
create subdirectory in new location if required
mkdir /ifs/data/sony/sdi
create symlink to new location
ln -s /ifs/data/sony/sdi/ /ifs/data/sdi
re own folder
chown -R sony:ftp_users /ifs/data/sony/
Cron jobs
A few points to keep in minds:
- of course your jobs will be light-weighted and do no harm to the cluster…
- the crontab might get wiped when installing OneFS updates (even minor ones)
- you can't execute files from /ifs
- - but you can execute scripts as /bin/bash /ifs/path/to/my/script
- - if you put scripts or executables under a node's / or /var: these are small! and may get wiped, too.
- any node would do, but if it goes offline, there is no automated failover to another node (crontab is a basic UNIX thing)
Refer to this doc https://community.emc.com/docs/DOC-48465 for running CRON successfully on one node only
