[scponly] Permission denied

Chris de Vidal Chris at deVidal.tv
Fri Apr 1 09:53:44 EST 2005


Kaleb Pederson said this while chewing gum:
> It's most likely something at the system level.  It really sounds like a
> shell problem because it's happening before the user gets to access
> scponly, but you indicated that it is present.

It works if I change to the non-chrooted binary so I doubt it's the shell
(am I wrong?).


> Perhaps there is a permissions problem on the file or something else of
> that nature.

Perms:
-rwsr-xr-x 1 root root 55079 Apr 1 09:31 /usr/sbin/scponlyc


> If they happen to be getting to scponly, then you could do something like
> the following to turn up debugging:
>
> echo "1" > /etc/scponly/debuglevel
>
> Once you up your debuglevel (change the path above as necessary), then you
> should get quite a few messages in the log when the user is actually
> getting to scponly, but I doubt that's the problem.

Which log file would show the errors?  I didn't see anything in messages
or debug or anything new in auth.log.  Nothing new showed on the client
side.


> If you still can't figure it out, you could strace your ssh process and
> find out what ssh is doing for authentication and the associated failure.

Well again it works when I use the non-chrooted binary.  Would you strace
the server, the client, or both?

CD

Have you ever lied, no matter the color?  I have.  Have you ever stolen
anything, no matter the value?  I have.  Have you ever lusted?  I have. 
Jesus said whoever looks at a woman with lustful intent has already
committed adultery with her in his heart.

We are lying, thieving, adulterers at heart and will face judgement one day.

There is good news for us!  "God shows his love for us in that while we
were still sinners, Christ died for us.  Since, therefore, we have now
been justified by his blood, much more shall we be saved by him from the
wrath of God." (Romans 5:8,9)



More information about the scponly mailing list