0

I miss to understand the topic: a request from my corp's sec team.

while setting up an sftp with chroot they insist I've to (quoting) "add notty to authorized users". to my knowledge the notty is the outcome of a login made by a user with no shell (e.g. an ssh user whose config bind her to sftp only and -to-say- has /usr/sbin/nologin configured).

what am I missing? any pointer on the openssh docs (redhat version 7)?

thank you

matteo nunziati
  • 624
  • 1
  • 4
  • 13

1 Answers1

1

This looks like it's what you want: https://serverfault.com/a/354618/230046

It'll mean users in the sftponly group can only SFTP, not SSH.

shearn89
  • 3,143
  • 2
  • 14
  • 39
  • Yep this is what we have setup... But sec in my company seems to not be happy until a mystic notty user will be added to some group... I start thinking they simply don't know what a sftp setup is... – matteo nunziati Feb 15 '22 at 18:16
  • I think they want you to add the option `notty` to the users? I'm sure if you show them the config and speak to your local friendly security person, you'll get it sorted! – shearn89 Feb 15 '22 at 19:22