[opensuse-support] changes in sftp chroot behavior between openSUSE 42.3 and 15.x
Hello all, after upgrading from openSUSE Leap 42.3 to 15.1 we noticed that the SFTP accounts we set up for some webspaces do no longer work, e.g.: Jun 21 10:50:31 it-708 sshd[22545]: fatal: bad ownership or modes for chroot directory "/srv/www/vhosts/aktive/htdocs" I guess this is caused by your removal of [openssh-7.2p2-sftp_homechroot.patch] during the change * Do Jan 11 2018 pcerny@suse.com - Update to vanilla 7.6p1 …, which removed the following feature: | ChrootDirectory […] | In the special case when only sftp is used, not ssh nor scp, it | is possible to use ChrootDirectory %h or ChrootDirectory | /some/path/%u. The file system containing this directory must be | mounted with options nodev and either nosuid or noexec. The owner | of the directory should be the user. The ownership of the other | components of the path must fulfill the usual conditions. No adi- | tional files are required to be present in the directory. I wonder if the removal of this feature was intended (and why) or if this is maybe just an unwanted side effect of some refactoring. Any hints? Regards Martin --· Mensa in Deutschland e. V. Martin H. Sluka mailto:root@mensa.de -- To unsubscribe, e-mail: opensuse-support+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-support+owner@opensuse.org
participants (1)
-
Martin Sluka