Site Tools


arqiva:isilon_as_ftp_server

This is an old revision of the document!


Isilon as FTP server

helpful page https://community.emc.com/message/844739

I've used the referenced KB and I'm able to do whatever I want (i.e.: chroot all except certain users, chroot only certain users, use custom config, etc)

However, please note when using a custom config, the filename must match your full username that you use to login. In my case I logged in with a user 'YFISI\tohill'. So my custom config file is called 'YFISI\tohill' and NOT tohill.

In my setup below, only user 'YFISI\tohill' gets chroot and the chroot directory is /ifs/home/scratch as defined in its custom config file. All details below.

ftp config

  yfvm-7111-2# isi ftp list  
  accept-timeout         60  
  allow-anon-access      NO  
  allow-anon-upload      YES  
  allow-dirlists         YES  
  allow-downloads        YES  
  allow-local-access     YES  
  allow-writes           YES  
  always-chdir-homedir   YES  
  anon-chown-username    root  
  anon-root-path         /ifs/home/ftp  
  anon-umask             077  
  ascii-mode             off  
  connect-timeout        60  
  data-timeout           300  
  dirlist-localtime      NO  
  dirlist-names          hide  
  file-create-perm       0666  
  local-root-path        local user home directory  
  local-umask            077  
  server-to-server       NO  
  session-support        YES  
  session-timeout        300  
  user-config-dir        /ifs/vsftpd/user_config  
  
  denied-user-list       (none)  

  limit-anon-passwords   NO  
  anon-password-list     (disabled)  

  chroot-local-mode      Only chroot the local users in the exception list  
  chroot-exception-list  YFISI\tohill  

Content of my '/ifs/vsftpd/user_config' dir and the custom file for 'YFISI\tohill'

  yfvm-7111-2# pwd  
  /ifs/vsftpd/user_config  
  yfvm-7111-2# ls -l  
  total 26  
  -rw-r--r--    1 root  wheel  51 Oct 22 08:55 YFISI\tohill  
  yfvm-7111-2# cat YFISI\\tohill  
  local_root=/ifs/home/scratch  
  chroot_local_user=yes  

Permissions on the /ifs/home/scratch directory:

  yfvm-7111-2# pwd  
  /ifs/home  
  yfvm-7111-2# ls -led scratch  
  drwxrwxr-x +  2 root  YFISI\domain use  26 Oct 22 09:21 scratch  
   OWNER: user:root  
   GROUP: group:YFISI\domain users  
   0: user:root allow dir_gen_read,dir_gen_write,dir_gen_execute,std_write_dac,delete_child  
   1: group:YFISI\domain users allow dir_gen_read,dir_gen_write,dir_gen_execute,delete_child  
   2: everyone allow dir_gen_read,dir_gen_execute  

When I login with the 'YFISI\tohill' user, this is what I get:

  Name (192.168.32.222:xxxxx): YFISI\tohill  
  331 Please specify the password.  
  Password:  
  230 Login successful.  
  Remote system type is UNIX.  
  Using binary mode to transfer files.  
  ftp> pwd  
  Remote directory: /  
  ftp> dir  
  229 Entering Extended Passive Mode (|||27988|).  
  150 Here comes the directory listing.  
  -rw-------    1 ftp      ftp           373 Oct 22 13:21 test.txt  
  226 Directory send OK.  

This is basically the content of the '/ifs/home/scratch' directory.

Force users into correct folder

remove home directory

       rm -rf /ifs/data/sdi/

create subdirectory in new location if required

        mkdir /ifs/data/sony/sdi        

create symlink to new location

      ln -s /ifs/data/sony/sdi/ /ifs/data/sdi

re own folder

      chown -R sony:ftp_users /ifs/data/sony/

Cron jobs

A few points to keep in minds:

- of course your jobs will be light-weighted and do no harm to the cluster…

- the crontab might get wiped when installing OneFS updates (even minor ones)

- you can't execute files from /ifs

  1. - but you can execute scripts as /bin/bash /ifs/path/to/my/script
  1. - if you put scripts or executables under a node's / or /var: these are small! and may get wiped, too.

- any node would do, but if it goes offline, there is no automated failover to another node (crontab is a basic UNIX thing)

Refer to this doc https://community.emc.com/docs/DOC-48465 for running CRON successfully on one node only

Configure a custom email quota notification template

If email notifications are enabled, you can configure custom templates for email notifications.

If the default email notification templates do not meet your needs, you can configure your own custom email notification templates using a combination of text and SmartQuotas variables.

Procedure

- Open a text editor and create a .txt file that includes any combination of text and OneFS email notification variables. -Save the template file as ASCII text or in ISO-8859-1 format. - Upload the file to an appropriate directory on the Isilon cluster. For example, /ifs/templates.

Example 1 Example of a custom quota email notification text file

The following example illustrates a custom email template to notify recipients about an exceeded quota.

Text-file contents with variables

The disk quota on directory <ISI_QUOTA_PATH> owned by <ISI_QUOTA_OWNER> was exceeded.
The <ISI_QUOTA_TYPE> quota limit is <ISI_QUOTA_THRESHOLD>, and SmartQuotas </Q>

Map an email notification rule for a quota 325

Example 1 Example of a custom quota email notification text file (continued)

<ISI_QUOTA_USAGE> is in use. Please free some disk space by deleting unnecessary files.

For more information, contact Jane Anderson in IT.

Email contents with resolved variables

The disk quota on directory /ifs/data/sales_tools/collateral owned by jsmith was exceeded.
The hard quota limit is 10 GB, and 11 GB is in use. Please free some disk space by deleting unnecessary files.
For more information, contact Jane Anderson in IT.

After you finish

To use the custom template, click Cluster Managements > General Settings > Email Settings, and select the custom template in the Event Notification Settings area.

Sync folder

rsync -av root@172.16.188.115:/ftp/flipfactory/nbcu /ifs/data/

Copy isilon node 1 into remote authorised keys

cat ~/.ssh/id_rsa.pub | ssh root@172.16.188.115 "mkdir -p ~/.ssh && cat >>  ~/.ssh/authorized_keys"

Provision home directories with dot files

You can provision home directories with dot files.

Before you begin

To perform most configuration tasks, you must log on as a member of the SecurityAdmin role.

The skeleton directory, which is located at /usr/share/skel by default, contains a set of files that are copied to the user's home directory when a local user is created or when a user home directory is dynamically created during login. Files in the skeleton directory that begin with dot. are renamed to remove the dot prefix when they are copied to the user's home directory. For example, dot.cshrc is copied to the user's home directory as .cshrc. This format enables dot files in the skeleton directory to be viewable through the command-line interface without requiring the ls -a command.

For SMB shares that might use home directories that were provisioned with dot files, you can set an option to prevent users who connect to the share through SMB from viewing the dot files.

arqiva/isilon_as_ftp_server.1474726414.txt.gz · Last modified: (external edit)