首页 运维 网络学院 查看内容

CentOS 5下SELinux阻止vsftp用户访问主目录

2009-1-31 01:24 541 0

摘要:   在CentOS 5的安装过程中,如果启用了SELinux,则本地用户通过ftp访问服务器时,将会发生如下错误:  500 OOPS: cannot change directory:/home/u...
关键词: home ftp SELinux directories daemon access setsebool users allow preventing

  在CentOS 5的安装过程中,如果启用了SELinux,则本地用户通过ftp访问服务器时,将会发生如下错误:  500 OOPS: cannot change directory:/home/user  Login failed.  在系统日志中也可以看到如下信息:  [root@web ~]# tail /var/log/messages  Sep  5 08:30:59 web setroubleshoot: SELinux is preventing the ftp daemon from reading users home directories (./home). For complete SELinux messages. run sealert -l 81cf3268-4d97-449a-9949-3a08ceef49b6  按照其中所述,运行  [root@web ~]# sealert -l 81cf3268-4d97-449a-9949-3a08ceef49b6  Summary:  SELinux is preventing the ftp daemon from reading users home directories (./home).  Detailed Description:  SELinux has denied the ftp daemon access to users home directories (./home). Someone is attempting to login via your ftp daemon to a user account. If you only setup ftp to allow anonymous ftp, this could signal a intrusion attempt.  Allowing Access:  If you want ftp to allow users access to their home directories you need to turn on the ftp_home_dir boolean: "setsebool -P ftp_home_dir=1"  The following command will allow this access:  setsebool -P ftp_home_dir=1  按照其中描述,执行该命令:  [root@web ~]# setsebool -P ftp_home_dir=1  之后本地用户就可以用FTP登录该服务器了。
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系 [邮箱地址] 删除

路过

雷人

握手

鲜花

鸡蛋

最新评论

返回顶部