SFTP and chroot

Michael De Cou

Explorer
Joined
Aug 12, 2016
Messages
50
Hi,

Currently running TrueNAS-12.0-U8, I have an FTP server setup and have run into the issue where SFTP users can log into their home directory, but chroot has not effect and users can navigate up to the root directory. I have read in the current user documentation that chroot has no effect for SFTP, and it suggests that if this is a concern, I may want to consider using FTP with TLS/SSL instead. My questions are as follows:

Is there any workaround to continue to use SFTP and lock users in their home directory? ie: Is there a way to create an alias for a home directory that shows no directories above the home directory?

Is there a way to deny SFTP connections? I cannot seem to find any settings for this within the GUI.

Thanks for any feedback.
 

Pabs

Explorer
Joined
Jan 18, 2017
Messages
52
Did you create a Dataset for FTP users, after doing that I got around that problem.
Not sure if this is the answer that you are looking for but it did get me around the jumping around folders issue.

Thx
 

Patrick M. Hausen

Hall of Famer
Joined
Nov 25, 2013
Messages
7,776
Chroot with SFTP is possible. I only have not tried it with TrueNAS, yet. Probably some auxiliary parameters for the SSH service are necessary. I'll try to provide more details tomorrow.
 

Ericloewe

Server Wrangler
Moderator
Joined
Feb 15, 2014
Messages
20,194
My method is to restrict this sort of usage to a jailed dataset. Gives you pretty much full control and better isolation.
 
Top