FTP broken after recent updates on 10.4 server

Terry Allen hmag at ozemail.com.au
Wed Aug 22 14:19:20 PDT 2007


>Greetings all,
>
>I've got a 10.4.10 Server which predominantly handles file sharing,
>with a few light FTP users.  It pulls authentication from Active
>Directory.
>
>After applying the post-10.4.10 security updates, FTP broke and no
>amount of futzing has fixed it.  Googling has led me down a few stray
>paths; for example, it is not the problem with the botched security
>update released back in May which changed which FTP daemon was
>launched on startup.
>
>-The FTP server is set to show users the FTP root and mounts, but when
>a local user attempts login, regardless of whether their home
>directory exists, I get:
>FTP LOGIN FAILED (cannot chdir)
>
>If they are a local user and NOT a member of the com.apple.allservices
>group, then I get:
>ACL Check failed for (username).
>
>-If an AD user attempts login, I get:
>FTP LOGIN REFUSED (bad shell or username in
>/Library/FTPServer/Configuration/ftpusers)
>
>(I tried adding a user to ftpusers.  No difference.  I've been
>wondering if the problem is that they don't have a shell defined.)
>
>This is driving me batty.  Everything was working smooth as silk until
>the system was rebooted last week after applying security updates.
>
>Any suggestions?
>
>Thanks!
>Brett
Hi again,
	Try setting the shell of the users to /usr/bin/false or /sbin/nologin
	I'm not running the same system, but FTP users on numerous 
systems I administrate have those shells set.
-- 

	Bye for now, Terry Allen 
	___________________________________________________________________
hEARd

Postal Address:
	hEARd, 26B Glenning Rd,	Glenning Valley, NSW 2261, Australia
Internet -
	WWW: http://heard.com.au http://itavservices.com
EMAIL: hmag at ozemail.com.au
Phone: Australia - 02 4388 1400 / International - + 61 2 43881400
Mobile: Australia - 04 28881400 / International - 61 4 28881400
-----------------------------------------------
Non profit promotion for new music - since 1994
-----------------------------------------------


More information about the MacOSX-admin mailing list