Users, FTP, security

Users, FTP, security

Posted by: chrisjj
Posted on: 2005-08-10 15:47:00

How can I set up a user to have access to the FTP space of only his site? Whereas (if I understand correctly) by default each user access to all the files of all sites under the same plan.

Thanks.

Chris (having searched the KB on this, still none the wiser)

Re: Users, FTP, security

Posted by: dallas
Posted on: 2005-08-11 16:57:00

If you set up a user as ftp-only (and not shell) they will be 'jailed' into their home directory when they log in.

It is true that by default all of the users under one plan will have the same default group, if that's what you mean by having access. Any files set to be readable only by the owner will still not be readable by other users on your plan.

- Dallas
- DreamHost Head Honcho/Founder

Re: Users, FTP, security

Posted by: chrisjj
Posted on: 2005-08-12 04:28:00

> It is true that by default all of the users under one plan will have
> the same default group, if that's what you mean by having access.

No it's not (though I'm not doubting it is true). What I mean by "having access" is having the ability to read/write/delete files.

For avoidance of doubt, could you just say whether by default one user is allowed to read/write/delete the files of another user on the same plan?




Re: Users, FTP, security

Posted by: dallas
Posted on: 2005-08-12 11:15:00

Via ftp, read/write/delete no. Via shell, read yes, write/delete no.

- Dallas
- DreamHost Head Honcho/Founder

Re: Users, FTP, security

Posted by: ardco
Posted on: 2005-08-12 12:36:00

> Via ftp, read/write/delete no. Via shell, read yes, write/delete no.

I beg to differ. :-)

Recently created a new user.

For directory I see:
drwxr-x--x


For new files, I see:

created with FTP:
-rw-r--r--
Therefore group: read yes, write/delete no. (We disagree on read)

created in shell:
-rw-rw-r--
Therefore group: read/write yes, delete no. (We disagree on write)

Cheers,

BobS

Re: Users, FTP, security

Posted by: dallas
Posted on: 2005-08-12 12:52:00

Oh, I meant that users who login via FTP (and ftp only) can't access files in other home directories. They're jailed into their own home. You have to set up the user without shell access to enforce it.

- Dallas
- DreamHost Head Honcho/Founder

Re: Users, FTP, security

Posted by: chrisjj
Posted on: 2005-08-14 14:07:00

Thanks for that. Then you need to correct the following that recently appeared on the panel "Add New User":

Please know that new users cannot access the files/folders of existing users!

Re: Users, FTP, security

Posted by: pookguy88
Posted on: 2005-08-15 13:20:00

Can, I, as the administrator, see the files that were uploaded from a newly created FTP user?

Re: Users, FTP, security

Posted by: dallas
Posted on: 2005-08-18 17:42:00

There is no concept of an 'administrator' user account as far as your setup is concerned. Every user is just like every other. Shell accounts can cd /home/username to see the contents of another of your user's files as long as those files are either group or world readable.

- Dallas
- DreamHost Head Honcho/Founder

Tags: ftp spaceaccessdefault