This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

ssh support
#1
ssh support
Hi guys,

I'm looking here, why not ssh support to sentora? I think that is good idea to implement ssh chroot jail on accounts to provide ssh access.
Then, user can create N ftp accounts, can be create N ssh accounts too.

What do you think? good idea? let's discuss Smile
Reply
Thanks given by:
#2
RE: ssh support
I don't understand why you'd want to put in a "potential" major security hole, for the sake of letting users create ftp accounts...

Is there any other reason for ssh access?
Elijah
Reply
Thanks given by:
#3
RE: ssh support
This is actually some interesting feature, but needs to be done with very care because it can expose the whole server if a mistake is made.

But to answer joubertredrat question about "why not?" I can tell almost for sure that this is not essential, can create other critical issues and will steer the dev team from the main objective of sentora.

I vote for this, but as a module, not on core sentora.
My Sentora Resources
[Module] Mail Quota Count | Vagrant Box with Sentora

[Image: vanguardly-logo-micro.png]
Graphic and Web Design. Development.
www.vanguardly.com


Reply
Thanks given by:
#4
RE: ssh support
(05-28-2015, 12:03 AM)elijahbate Wrote: I don't understand why you'd want to put in a "potential" major security hole, for the sake of letting users create ftp accounts...

Is there any other reason for ssh access?
Elijah
Is normal to use ssh on hosting to install or manage applications, PHP as example, you can need to run composer do get dependences or wget to download source to run application.

(05-28-2015, 12:09 AM)apinto Wrote: This is actually some interesting feature, but needs to be done with very care because it can expose the whole server if a mistake is made.

But to answer @[joubertredrat] question about "why not?" I can tell almost for sure that this is not essential, can create other critical issues and will steer the dev team from the main objective of sentora.

I vote for this, but as a module, not on core sentora.

Yes, can be a module, I can develop this and test here and if works, I publish for test.
Reply
Thanks given by:
#5
RE: ssh support
I've just never seen that in a standard shared hosting environment.
I can understand the benefits that way but just I would think most people that would do that would get a cloud or vps hosted or pre deploy

Elijah
Reply
Thanks given by:
#6
RE: ssh support
I have no idea how you think this would work with Sentora. The current server permissions do not allow for this. How would you manager to lock each person down to their own folders? Each SSH user would need their own account on the server. Me.B can shed some more light on this topic.
-TGates - Project Council

SEARCH the Forums or read the DOCUMENTATION before posting!
Support Sentora and Donate: HERE

Find my support or modules useful? Donate to TGates HERE
Developers and code testers needed!
Contact TGates for more information
Reply
Thanks given by:
#7
RE: ssh support
elijahbate Actually a lot of shared host providers give SSH access to some degree (HostGator for example).

But this really needs tight control.
My Sentora Resources
[Module] Mail Quota Count | Vagrant Box with Sentora

[Image: vanguardly-logo-micro.png]
Graphic and Web Design. Development.
www.vanguardly.com


Reply
Thanks given by:
#8
RE: ssh support
Sandboxing SSH is not an easy task and you would check any guides over hardening CPANEL and you will see first requirement don't ever provide SSH.

We can provide TLS for FTP without having to move offer SSH that will require first of all setting a USER on the box per account created while here we are using virtual users that don't even exist or have permissions on the server and use sandboxing for each service ( ftp/apache/php).

I don't like the idea to offer SSH in shared hosting. Currently VPS like openVZ offer more suitable sandboxing for the low end and you can get rock solid sandboxing using full VM hypervisors like xen/hyperV/Vmare.

M B
No support using PM (Auto adding to IGNORE list!), use the forum. 
How to ask
Freelance AWS Certified Architect & SysOps// DevOps

10$ free to start your VPS
Reply
Thanks given by:
#9
RE: ssh support
(05-28-2015, 01:42 AM)TGates Wrote: I have no idea how you think this would work with Sentora. The current server permissions do not allow for this. How would you manager to lock each person down to their own folders? Each SSH user would need their own account on the server. @[Me.B] can shed some more light on this topic.

Because this I saw ssh chroot jail, not pure ssh.

With chrooted jail is possible to create minimal and isolated environment.

http://www.sdri.co.jp/rssh/CHROOT_en.html 

https://www.debian.org/doc/manuals/secur...nv.en.html
http://allanfeid.com/content/creating-ch...ssh-access


I will see if I have time to develop a small alpha to show this working on sentora.
Reply
Thanks given by: apinto
#10
RE: ssh support
(05-29-2015, 06:32 AM)joubertredrat Wrote: Because this I saw ssh chroot jail, not pure ssh.

With chrooted jail is possible to create minimal and isolated environment.

http://www.sdri.co.jp/rssh/CHROOT_en.html 

https://www.debian.org/doc/manuals/secur...nv.en.html
http://allanfeid.com/content/creating-ch...ssh-access


I will see if I have time to develop a small alpha to show this working on sentora.

Ok, that would be cool!
-TGates - Project Council

SEARCH the Forums or read the DOCUMENTATION before posting!
Support Sentora and Donate: HERE

Find my support or modules useful? Donate to TGates HERE
Developers and code testers needed!
Contact TGates for more information
Reply
Thanks given by:


Possibly Related Threads…
Thread Author Replies Views Last Post
Ubuntu 12.04 end of support Me.B 2 7 ,563 04-19-2017, 05:09 AM
Last Post: Me.B
SSL support in sentora Me.B 9 26 ,218 09-16-2016, 04:09 PM
Last Post: Nigel
Nginx support Me.B 17 46 ,642 02-25-2016, 01:34 AM
Last Post: apinto

Forum Jump:


Users browsing this thread: 1 Guest(s)