frazer-lab / cluster

Repo for cluster issues.
1 stars 0 forks source link

sftp user account #288

Closed hirokomatsui closed 4 years ago

hirokomatsui commented 4 years ago

Hi Paul,

Is it easy to create a user account which can access only to the home directory? We want our collaborator uploading some files on our cluster. If it's not easy, never mind. I'll just can create a regular user account for a short time.

tatarsky commented 4 years ago

Different than frazerguest1 ?

We can do another of these if you wish. Just advise the username and the homedir! But we have that active. I do not recall the password ;)

# Support Upload
Match User frazerguest1
    ChrootDirectory /frazer01/home/sftp
    AllowTCPForwarding no
    X11Forwarding no
    ForceCommand internal-sftp
tatarsky commented 4 years ago

And we might have to check iptables as I believe we blocked ssh to campus awhile back. I'll look in the morning but just advise on re-use of frazerguest1 or not.

hirokomatsui commented 4 years ago

Can you remove the user frazerguest1, as well as the home directory too. I've checked the files there.

The new user's on UCSD campus, so no need to change iptables. The user name will be gaulton.

hirokomatsui commented 4 years ago

The password can be any random strings.

tatarsky commented 4 years ago

OK. Making a chroot sftp account called "gaulton" with a random password which I'll send to you and a homedir of the same name.

And removing the older frazerguest1 config.

tatarsky commented 4 years ago

Sent you an email with items provided! Advise if issues and note carefully the need to cd upload in the sftp as sshd chroot permissions got a little more strict.

I'll do the same config on fl-hn2 if you want. Right now its just fl-hn1.

tatarsky commented 4 years ago

Did the same on fl-hn2.

tatarsky commented 4 years ago

frazerguest1 removed. homedir removed.

hirokomatsui commented 4 years ago

I've confirmed that works. Thanks!

tatarsky commented 4 years ago

Excellent! You are very welcome. Have a great weekend.