以下内容都在selinux为disabled情况下进行
2)本地用户设定
local_enable=YES|NO ##本地用户登陆限制
write_enable=YES|NO ##本地用户写权限限制
#<本地用户家目录修改>
local_root=/directory
#<本地用户上传文件权限>
local_umask=xxx
#<限制本地用户浏览/目录>
所有用户被锁定到自己的家目录中
chroot_local_user=YES
chmod u-w /home/*
用户黑名单建立
chroot_local_user=NO
chroot_list_enable=YES
chroot_list_file=/etc/vsftpd/chroot_list
用户白名单建立
chroot_local_user=YES
chroot_list_enable=YES
chroot_list_file=/etc/vsftpd/chroot_list
#<限制本地用户登陆>
vim /etc/vsftpd/ftpusers ##用户黑名单
vim /etc/vsftpd/user_list ##用户临时黑名单
用户白名单设定
userlist_deny=NO
/etc/vsftpd/user_list ##参数设定,此文件变成用户白名单,只在名单中出现的用户可以登陆ftp
本地用户
#<限制本地用户浏览/目录>
所有用户被锁定到自己的家目录中
chroot_local_user=YES
chmod u-w /home/*
[root@localhost ~]# vim /etc/vsftpd/vsftpd.conf
chroot_local_user=YES
[root@localhost ~]# systemctl restart vsftpd.service
[root@localhost ~]# chmod u-w /home/*
测试:
[root@foundation48 ~]# lftp 172.25.254.10 -u aa ##YES时
Password:
lftp aa@172.25.254.10:~> ls
ls: Login failed: 500 OOPS: cannot change directory:/aa
lftp aa@172.25.254.10:~> exit
[root@foundation48 ~]# lftp 172.25.254.10 -u aa ##NO时
Password:
lftp aa@172.25.254.10:~> ls
lftp aa@172.25.254.10:~> ls
lftp aa@172.25.254.10:~>
用户黑名单
[root@localhost ~]# vim /etc/vsftpd/vsftpd.conf
chroot_local_user=NO
chroot_list_enable=YES
chroot_list_file=/etc/vsftpd/chroot_list
[root@localhost ~]# systemctl restart vsftpd.service
[root@localhost ~]# vim /etc/vsftpd/chroot_list
[root@localhost ~]# cat /etc/vsftpd/chroot_list
aa
另一边测试:
[root@foundation48 ~]# lftp 172.25.254.10 -u aa
Password:
lftp aa@172.25.254.10:~> ls
ls: Login failed: 500 OOPS: cannot change directory:/aa
lftp aa@172.25.254.10:~> ls
ls: Login failed: 500 OOPS: cannot change directory:/aa
lftp aa@172.25.254.10:~>
用户白名单
[root@localhost ~]# vim /etc/vsftpd/vsftpd.conf
chroot_local_user=YES
chroot_list_enable=YES
chroot_list_file=/etc/vsftpd/chroot_list [root@localhost ~]# systemctl restart vsftpd.service [root@localhost ~]# vim /etc/vsftpd/chroot_list
[root@localhost ~]# cat /etc/vsftpd/chroot_list
aa
测试:
[root@foundation48 ~]# lftp 172.25.254.10 -u aa
Password:
lftp aa@172.25.254.10:~> ls
lftp aa@172.25.254.10:~> ls
lftp aa@172.25.254.10:~> ls
lftp aa@172.25.254.10:~> exit
[root@foundation48 ~]# lftp 172.25.254.10 -u lee
Password:
lftp lee@172.25.254.10:~> ls
lss' at 0 [Sending commands...] ls: Login failed: 530 Login incorrect. lftp lee@172.25.254.10:~> ls `ls' at 0 [Sending commands...]
限制本地用户登录
[root@localhost ~]# vim /etc/vsftpd/ftpusers 永久黑名单
You have new mail in /var/spool/mail/root
[root@localhost ~]# cat /etc/vsftpd/ftpusers
# Users that are not allowed to login via ftp
root
bin
daemon
adm
lp
sync
shutdown
halt
mail
news
uucp
operator
games
nobody
lee
测试
[root@foundation48 ~]# lftp 172.25.254.10 -u lee
Password:
lftp lee@172.25.254.10:~> ls
`ls' at 0 [Sending commands...]
临时黑名单
[root@localhost ~]# vim /etc/vsftpd/user_list
[root@localhost ~]# cat /etc/vsftpd/user_list
# vsftpd userlist
# If userlist_deny=NO, only allow users in this file
# If userlist_deny=YES (default), never allow users in this file, and
# do not even prompt for a password.
# Note that the default vsftpd pam config also checks /etc/vsftpd/ftpusers
# for users that are denied.
root
bin
daemon
adm
lp
sync
shutdown
halt
mail
news
uucp
operator
games
nobody
lee
测试:
[root@foundation48 ~]# lftp 172.25.254.10 -u lee
Password:
lftp lee@172.25.254.10:~> ls
ls: Login failed: 530 Permission denied.
lftp lee@172.25.254.10:~>