From owner-ssh@clinet.fi  Fri May 18 01:00:08 2001
Received: from smtp1.clinet.fi (smtp1.clinet.fi [194.100.2.57])
	by hutcs.cs.hut.fi (8.9.3/8.9.3) with ESMTP id BAA26911
	for <ssh-archiver@cs.hut.fi>; Fri, 18 May 2001 01:00:07 +0300 (EET DST)
Received: from mail.clinet.fi (mail.clinet.fi [194.100.0.7])
	by smtp1.clinet.fi (Postfix) with ESMTP
	id 0850220135; Fri, 18 May 2001 01:00:01 +0300 (EEST)
Received: (from majordom@localhost)
	by mail.clinet.fi (8.9.3/8.9.3) id AAA17415
	for ssh-outgoing; Fri, 18 May 2001 00:39:27 +0300
Received: from mailsvr.fame.com (mailsvr.fame.com [192.88.67.18])
	by mail.clinet.fi (8.9.3/8.9.3) with ESMTP id AAA17408
	for <ssh@clinet.fi>; Fri, 18 May 2001 00:39:26 +0300
Received: from hou (hou.fame.com [192.88.65.68])
	by mailsvr.fame.com (8.9.3/8.9.3) with SMTP id RAA07777;
	Thu, 17 May 2001 17:39:16 -0400 (EDT)
Reply-To: <lhou@fame.com>
From: "Lucy Hou" <lhou@fame.com>
To: "Jesse Adelman" <jesse@denalii.com>, <ssh@clinet.fi>
Subject: RE: No shell access?
Date: Thu, 17 May 2001 17:49:09 -0400
Message-ID: <NEBBJBOLHKACCPEKKMDHAEHLCBAA.lhou@fame.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2911.0)
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
In-Reply-To: <HMEMJCIMDNFOOAEFBLDDCEBICAAA.jesse@denalii.com>
Sender: owner-ssh@clinet.fi
Precedence: bulk

Check out http://www.snailbook.com/faq/restricted-scp.auto.html  and
http://marc.theaimsgroup.com/?l=secure-shell&r=1&w=2 . It is the only
provided solution I have known and I didn't get it to work on Solaris.

-----Original Message-----
From: owner-ssh@clinet.fi [mailto:owner-ssh@clinet.fi]On Behalf Of Jesse
Adelman
Sent: Thursday, May 17, 2001 4:55 PM
To: ssh@clinet.fi
Subject: No shell access?


Hello, good SSH users and developers. I need to set up SSH such that users
can scp and sftp but NOT log in to a shell. I've attempted to set a shell as
/bin/<doesnotexist>, but that breaks SSH generally, including scp and sftp.
What is the best/preferred method for disabling shell access and allowing
scp and sftp to work?

Systems used: RH Linux, Solaris 8

Thanks in advance,

Jesse Adelman
Sr. Systems Engineer
Denalii, Inc.


