FTPソスTソス[ソスoソス[ソス\ソスz(vsftpd)

ソスナ終ソスXソスVソスソスソスF 2014.02.19

<<ソスgソスbソスvソスyソス[ソスW <<ソスVソスソスソスソスソス <<ソスTソスCソスgソスソスソスソスソスソス <<CentOSソスナ趣ソスソスソスTソス[ソスoソス[ソス\ソスz <<Scientific Linuxソスナ趣ソスソスソスTソス[ソスoソス[ソス\ソスz

ソスソスソスTソスv

WebソスTソス[ソスoソス[ソスヨのフソス@ソスCソスソスソス]ソスソスソスpソスソスFTPソスTソス[ソスoソス[ソスソスソス\ソスzソスソスソスソスB
ソスソスソスソスソスナは、FedoraソスWソスソスソスソスFTPソスTソス[ソスoソス[ソスナゑソスソスソスvsftpdソスソスソスフ用ソスソスソスソスB
ソスネゑソスソスAソスソスソス[ソスUソスソスソスAソスpソスXソスソスソス[ソスhソスACGIソスソスソスノ擾ソスソスソスソス黷スソスpソスXソスソスソス[ソスhソスソス等の難ソスソスソスソスノゑソスソスsソスソスソスソスソスソスホ搾ソスニゑソスソスト、SSLソスノゑソスソステ搾ソスソスソスソスハ信ソスソスソスsソスソスソスソス謔、ソスノゑソスソスソスB
ソスワゑソスソスAソスヌ暦ソスソスメソスソス[ソスUソスネ外ソスヘ趣ソスソスgソスフホソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスソスソスソスwソスヨはアソスNソスZソスXソスナゑソスソスネゑソスソス謔、ソスノゑソスソスソスB


ソスソスvsftpdソスCソスソスソスXソスgソス[ソスソス

[root@fedora~]# yum -y install vsftpdソス@ソスソスソス@vsftpdソスCソスソスソスXソスgソス[ソスソス

ソスソスvsftpdソスン抵ソス

ソスiソスPソスjvsftpdソスン抵ソス
[root@fedora~]# vi /etc/vsftpd/vsftpd.confソス@ソスソスソス@vsftpdソスン抵ソスtソス@ソスCソスソスソスメ集
# Allow anonymous FTP? (Beware - allowed by default if you comment this out).
anonymous_enable=NOソス@ソスソスソス@anonymousソスソスソス[ソスU(ソスソスソスソスソスソスソス[ソスU)ソスフソスソスOソスCソスソスソスヨ止

# Uncomment this to allow local users to log in.
local_enable=YESソス@ソスソスソス@ソスソスソス[ソスJソスソスソスソスソス[ソスUソスフアソスNソスZソスXソスソスソスソス

# Uncomment this to enable any form of FTP write command.
write_enable=YESソス@ソスソスソス@ソスsソスソスソスソス#ソスソスソス除ソスソスソストコソスソスソスソスソスgソスソスソスソス(ソスソスソスソスソスソスソスンゑソスソスソスソスソス)

# Activate logging of uploads/downloads.
xferlog_enable=YESソス@ソスソスソス@/var/log/vsftpd.logソスノ接托ソスソスEソス]ソスソスソスソスソスLソス^(1/3)

# You may override where the log file goes if you like. The default is shown
# below.
xferlog_file=/var/log/vsftpd.logソス@ソスソスソス@/var/log/vsftpd.logソスノ接托ソスソスEソス]ソスソスソスソスソスLソス^(2/3)

# If you want, you can have your log file in standard ftpd xferlog format
xferlog_std_format=NOソス@ソスソスソス@/var/log/vsftpd.logソスノ接托ソスソスEソス]ソスソスソスソスソスLソス^(3/3)

# By default the server will pretend to allow ASCII mode but in fact ignore
# the request. Turn on the below options to have the server actually do ASCII
# mangling on files when in ASCII mode.
# Beware that on some FTP servers, ASCII support allows a denial of service
# attack (DoS) via the command "SIZE /big/file" in ASCII mode. vsftpd
# predicted this attack and has always been safe, reporting the size of the
# raw file.
# ASCII mangling is a horrible feature of the protocol.
ascii_upload_enable=YESソス@ソスソスソス@ソスAソスXソスLソス[ソスソスソス[ソスhソスナのアソスbソスvソスソスソス[ソスhソスソスソスソスソスソス
ascii_download_enable=YESソス@ソスソスソス@ソスAソスXソスLソス[ソスソスソス[ソスhソスナのダソスEソスソスソスソスソス[ソスhソスソスソスソスソスソス

# You may fully customise the login banner string:
ftpd_banner=Welcome to blah FTP service.ソス@ソスソスソス@FTPソスソスソスOソスCソスソスソスソスソスノソソスtソスgソスソスソスニバソス[ソスWソスソスソスソスソスソスソス\ソスソスソスソスソスソスネゑソスソス謔、ソスノゑソスソスソス

# You may specify an explicit list of local users to chroot() to their home
# directory. If chroot_local_user is YES, then this list becomes a list of
# users to NOT chroot().
chroot_local_user=YESソス@ソスソスソス@ソスfソスtソスHソスソスソスgソスナホソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスソスソスソスwソスヨのアソスNソスZソスXソスソスソスヨ止ソスソスソスソス
chroot_list_enable=YESソス@ソスソスソス@ソスzソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスソスソスソスwソスヨのアソスNソスZソスXソスソスソスソスソスツゑソスソス驛ソス[ソスUソスフソスソスXソスgソスフ有ソスソスソスソス
# (default follows)
chroot_list_file=/etc/vsftpd/chroot_listソス@ソスソスソス@ソスzソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスソスソスソスwソスヨのアソスNソスZソスXソスソスソスソスソスツゑソスソス驛ソス[ソスUソスフソスソスXソスg

# You may activate the "-R" option to the builtin ls. This is disabled by
# default to avoid remote users being able to cause excessive I/O on large
# sites. However, some broken FTP clients such as "ncftp" and "mirror" assume
# the presence of the "-R" option, so there is a strong case for enabling it.
ls_recurse_enable=YESソス@ソスソスソス@ソスfソスBソスソスソスNソスgソスソスソスソスソスニ削除ソスナゑソスソスソス謔、ソスノゑソスソスソス

ソスネ会ソスソスソスソスナ会ソスソスsソスヨ追会ソス
use_localtime=YESソス@ソスソスソス@ソス^ソスCソスソスソスXソス^ソスソスソスvソスソスソスヤゑソスソスソス{ソスソスソスヤにゑソスソスソス
pasv_addr_resolve=YESソス@ソスソスソス@PASVソスソスソス[ソスhソスレ托ソスソスソスIPソスAソスhソスソスソスXソスソスソスzソスXソスgソスソスソスソスソスソス謫セソスソスソスソス
pasv_address=fedorasrv.dip.jpソス@ソスソスソス@PASVソスソスソス[ソスhソスレ托ソスソスソスIPソスAソスhソスソスソスXソスソスソスソスソスソスソスソスzソスXソスgソスソスソスソス
pasv_min_port=60000ソス@ソスソスソス@PASVソスソスソス[ソスhソスレ托ソスソスソスソスフ最擾ソスソス|ソス[ソスgソスヤ搾ソス
pasv_max_port=60030ソス@ソスソスソス@PASVソスソスソス[ソスhソスレ托ソスソスソスソスフ最托ソス|ソス[ソスgソスヤ搾ソス
ssl_enable=YESソス@ソスソスソス@SSLソスフ有ソスソスソスソス
rsa_cert_file=/etc/pki/tls/certs/vsftpd.pemソス@ソスソスソス@ソスTソス[ソスoソス[ソスリ厄ソスソスソスソスソスソスwソスソス
require_ssl_reuse=NO
force_local_logins_ssl=NOソス@ソスソスソス@ソスソスソスOソスCソスソスソスソスソスソスSSLソスレ托ソスソスソスソスソスソスソスソスソスソスネゑソスソスソスソステ搾ソスソスソスソスソスソスネゑソスソスレ托ソスソスソスソスナゑソスソスソス謔、ソスノゑソスソスソス鼾ソスフゑソス
force_local_data_ssl=NOソス@ソスソスソス@ソスfソス[ソス^ソス]ソスソスソスソスソスソスSSLソスレ托ソスソスソスソスソスソスソスソスソスソスネゑソスソスソスソステ搾ソスソスソスソスソスソスネゑソスソスレ托ソスソスソスソスナゑソスソスソス謔、ソスノゑソスソスソス鼾ソスフゑソス
ソスソスpasv_addressソスノは、ソスTソス[ソスoソス[ソスフグソスソスソス[ソスoソスソスIPソスAソスhソスソスソスXソスソスソスソスソスソスソスソスzソスXソスgソスソスソスソスソスwソス閧キソスソスBソスネゑソスソスADNSソスTソス[ソスoソス[ソス導難ソスソスソスソスト難ソスソスソスソスソスソスソスフ厄ソスソスOソスソスソスソスソスソスソスノプソスソスソスCソスxソス[ソスgIPソスAソスhソスソスソスXソスノ変奇ソスソスソスソストゑソスソスワゑソスソストゑソスソスソス鼾ソスヘ、ソスVソスソスソスソスソスhソスソスソスCソスソスソスソスソス謫セソスソスソスADNSソスTソス[ソスoソス[ソスノ設定しソスネゑソスソス謔、ソスノゑソスソスト、ソス謫セソスソスソスソスソスhソスソスソスCソスソスソスソスソスソスpasv_addressソスノ指ソス閧キソスソスB

ソスiソスQソスjソスzソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスソスソスソスwソスヨのアソスNソスZソスXソスソスソスソスソスツゑソスソス驛ソス[ソスUソスフ登ソス^
[root@fedora~]# touch /etc/vsftpd/chroot_list
ソス@ソスソスソス@ソスzソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスソスソスソスwソスヨのアソスNソスZソスXソスソスソスソスソスツゑソスソス驛ソス[ソスUソスフソスソスXソスgソスソスソス成ソスソスソスホ象ソスソス[ソスUソスソスソスソスソスンゑソスソスネゑソスソストゑソスソス成ソスKソス{

[root@fedora~]# echo fedora >> /etc/vsftpd/chroot_list
ソス@ソスソスソス@ソスソスニゑソスソストソスソス[ソスUfedoraソスノゑソスソスzソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスソスソスソスwソスヨのアソスNソスZソスXソスソスソスソスソスツゑソスソスソス鼾
ソスソスソスヌ暦ソスソスメゑソスAソスソスソスgソスフホソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスネ外ソスヨアソスNソスZソスXソスナゑソスソスソス謔、ソスノゑソスソストゑソスソスソスソスKソスvソスソスソスソスソス驛ソス[ソスUソスフみ登ソス^ソスソスソストゑソスソスソス

ソスiソスRソスjソスzソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスソスソスソスwソスヨのアソスNソスZソスXソスソスソスナゑソスソスネゑソスソスソスソス[ソスUソスフタソスCソスソスソスXソス^ソスソスソスvソスソスソスソス{ソスソスソスヤにゑソスソスソス
ソスyソスVソスKソスソスソス[ソスUソスホ擾ソスソスz
[root@fedora~]# mkdir /etc/skel/etcソス@ソスソスソス@ソスソスソス[ソスUソスoソス^ソスソスソスノホソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスソスetcソスfソスBソスソスソスNソスgソスソスソスソスソス成ソスソスソスソスソス謔、ソスノゑソスソスソス

[root@fedora~]# cp /etc/localtime /etc/skel/etc/
ソス@ソスソスソス@ソスソスソス[ソスUソスoソス^ソスソスソスソス/etc/localtimeソスソスソスzソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスソスetcソスfソスBソスソスソスNソスgソスソスソスヨコソスsソス[ソスソスソスソスソス謔、ソスノゑソスソスソス

ソスyソスソスソスソスソスソスソス[ソスUソスホ擾ソスソスz
[root@fedora~]# vi localtimsetソス@ソスソスソス@localtimeソスZソスbソスgソスAソスbソスvソスXソスNソスソスソスvソスgソス成
#!/bin/bash

for user in `ls /home`
do
   id $user > /dev/null 2>&1
   if [ $? -eq 0 ]; then
        grep $user /etc/vsftpd/chroot_list > /dev/null 2>&1
        if [ $? -ne 0 ] && [ ! -f /home/$user/etc/localtime ]; then
            mkdir -p /home/$user/etc
            cp /etc/localtime /home/$user/etc
            echo $user
        fi
   fi
done

[root@fedora~]# sh localtimsetソス@ソスソスソス@localtimeソスZソスbソスgソスAソスbソスvソスXソスNソスソスソスvソスgソスソスソスs
user1
ソスE
ソスE
ソスE
usern

[root@fedora~]# rm -f localtimsetソス@ソスソスソス@localtimeソスZソスbソスgソスAソスbソスvソスXソスNソスソスソスvソスgソス除

ソスiソスSソスjFTPソスTソス[ソスoソス[ソスヨのアソスNソスZソスXソスソスソスヨ止ソスソスソス驛ソス[ソスUソスフ登ソス^
[root@fedora~]# echo fedora >> /etc/vsftpd/ftpusers
ソス@ソスソスソス@ソスソスニゑソスソストソスソス[ソスUfedoraソスノゑソスソスFTPソスTソス[ソスoソス[ソスヨのアソスNソスZソスXソスソスソスヨ止ソスソスソスソス鼾

ソスiソスTソスjソスTソス[ソスoソス[ソスリ厄ソスソスソスソス成
[root@fedora~]# cd /etc/pki/tls/certs/ソス@ソスソスソス@ソスfソスBソスソスソスNソスgソスソスソスレ難ソス

[root@fedora certs]# make vsftpd.pemソス@ソスソスソス@ソスTソス[ソスoソス[ソスリ厄ソスソスソスソス成
umask 77 ; \
PEM1=`/bin/mktemp /tmp/openssl.XXXXXX` ; \
PEM2=`/bin/mktemp /tmp/openssl.XXXXXX` ; \
/usr/bin/openssl req -utf8 -newkey rsa:1024 -keyout $PEM1 -nodes -x509 -days 365 -out $PEM2 -set_serial 0 ; \
cat $PEM1 >  vsftpd.pem ; \
echo ""    >> vsftpd.pem ; \
cat $PEM2 >> vsftpd.pem ; \
rm -f $PEM1 $PEM2
Generating a 1024 bit RSA private key
.................................++++++
................................++++++
writing new private key to '/tmp/openssl.OH7090'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [GB]:JPソス@ソスソスソス@ソスソスソスソスソスソスソスソス
State or Province Name (full name) [Berkshire]:Tokyoソス@ソスソスソス@ソスsソスソスソス{ソスソスソスソスソスソスソスソス
Locality Name (eg, city) [Newbury]:Shinjukuソス@ソスソスソス@ソスsソス謦ャソスソスソスソスソスソスソスソス
Organization Name (eg, company) [My Company Ltd]:fedorasrv.comソス@ソスソスソス@ソスTソスCソスgソスソスソスソスソスソス(ソスネゑソスナゑソスソスソスソスソス)
Organizational Unit Name (eg, section) []:ソス@ソスソスソス@ソスソスENTER
Common Name (eg, your name or your server's hostname) []:ftp.fedorasrv.comソス@ソスソスソス@ソスzソスXソスgソスソスソスソスソスソス
Email Address []:[email protected]ソス@ソスソスソス@ソスヌ暦ソスソスメソスソス[ソスソスソスAソスhソスソスソスXソスソスソスソス

[root@fedora certs]# cdソス@ソスソスソス@ソスzソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスヨ戻ゑソス

ソスソスvsftpdソスNソスソス

ソスiソスPソスjvsftpdソスNソスソス
[root@fedora~]# /etc/rc.d/init.d/vsftpd startソス@ソスソスソス@vsftpdソスNソスソス
vsftpd ソスpソスソス vsftpd ソスソスソスNソスソスソスソス:                               [  OK  ]

[root@fedora~]# chkconfig vsftpd onソス@ソスソスソス@vsftpdソスソスソスソスソスNソスソスソスン抵ソス

[root@fedora~]# chkconfig --list vsftpdソス@ソスソスソス@vsftpdソスソスソスソスソスNソスソスソスン抵ソスmソスF
vsftpd          0:off   1:off   2:on    3:on    4:on    5:on    6:offソス@ソスソスソス@ソスソスソスソスソスソスソスxソスソス2ソス`5ソスソスonソスmソスF

ソスiソスQソスjソス|ソス[ソスg21ソスヤゑソスOPEN
ソスソスソス[ソス^ソス[ソスソスソスフ設抵ソスナポソス[ソスg21ソスヤゑソスOPENソスソスソスソスB
ソスソスソスソスソス[ソス^ソス[ソスフ設抵ソスヘ各ソスソスソス[ソス^ソス[ソスフマソスjソスソスソスAソスソスソスワゑソスソスソスソスソスソス[ソスJソス[ソスハソスソス[ソス^ソス[ソス|ソス[ソスgソスJソスソスソス闖ソスソスソスQソスソス

ソス|ソス[ソスgソス`ソスFソスbソスNソスyソスOソスソスソスソスソスソス|ソス[ソスgソスJソスソスソスmソスFソスzソスナ「hostソスソスソスソスノサソス[ソスoソス[ソスソス(ソスソス:fedorasrv.com)ソスAソスportソスヤ搾ソスソスソスソス21ソスニ難ソスソスヘゑソスソスト「ソス|ソス[ソスgソス`ソスFソスbソスNソスソス{ソス^ソスソスソスソスソスソスソスソスソスAソスソスzソスXソスgソスソスfedorasrv.comソス@ソス|ソス[ソスgソスソス21ソス@ソスノアソスNソスZソスXソスナゑソスソスワゑソスソスソスソスBソスソスニ表ソスソスソスソスソスソス驍アソスニゑソスソスmソスFソスB

ソスiソスRソスjPASVソスレ托ソスソスpソス|ソス[ソスgソスソスOPEN
ソスソスソス[ソス^ソス[ソスソスソスフ設抵ソスソスPASVソスレ托ソスソスpソス|ソス[ソスg(60000ソス`60030)ソスソスOPENソスソスソスソスB
ソスソスソスソスソス[ソス^ソス[ソスフ設抵ソスヘ各ソスソスソス[ソス^ソス[ソスフマソスjソスソスソスAソスソスソスワゑソスソスソスソスソスソス[ソスJソス[ソスハソスソス[ソス^ソス[ソス|ソス[ソスgソスJソスソスソス闖ソスソスソスQソスソス

ソスソスSSLソスホ会ソスFTPソスNソスソスソスCソスAソスソスソスgソスソスソスソス

WindowsソスソスソスソスFTPソスTソス[ソスoソス[ソスヨ接托ソス(FileZilla)ソスQソスソス
ソスソスFileZillaソスソスSFTPソスレ托ソスソスノゑソスソスホ会ソスソスソスソストゑソスソスソスASFTPソスナ接托ソスソスソスソスソスソスFTPソスTソス[ソスoソス[ソスソスchrootソス@ソス\ソスソスソスソスソスソスソスネゑソスソスソスソスソスソスOソスCソスソスソスソスソス[ソスUソス[ソスソスソスgソスフホソス[ソスソスソスfソスBソスソスソスNソスgソスソスソスネ外ソスソスソスQソスニでゑソスソストゑソスソスワゑソスソスソスソス゚、SSHソスTソス[ソスoソス[ソスソスchrootソスン抵ソスソスソスsソスネゑソスソストゑソスソスソスソスソスソスソス

ソスソスソスAソスNソスZソスXソスソスソスソス

vsftpdソスヨアソスNソスZソスXソスナゑソスソスソスzソスXソスgソス制鯉ソスソスソスソスソスB
[root@fedora~]# echo "vsftpd:127.0.0.1" >> /etc/hosts.allowソス@ソスソスソス@ソスTソス[ソスoソス[ソスソスソスgソスソスソスソスソスvsftpdソスヨのアソスNソスZソスXソスソスソスソスソスソス

[root@fedora~]# echo "vsftpd:192.168.1." >> /etc/hosts.allowソス@ソスソスソス@ソスソスソスソス(ソスソス:192.168.1.XXXソスソスソスソスソスvsftpdソスヨのアソスNソスZソスXソスソスソスソスソスソス)

[root@fedora~]# echo "vsftpd:.ppp.asahi-net.or.jp"  >> /etc/hosts.allow
ソス@ソスソスソス@ソスOソスソス(ソスソス:xxx.ppp.asahi-net.or.jpソスソスソスソスソスvsftpdソスヨのアソスNソスZソスXソスソスソスソスソスソス)

[root@fedora~]# echo "vsftpd:ALL" >> /etc/hosts.denyソス@ソスソスソス@vsftpdソスヨの全ソストのアソスNソスZソスXソスソスソスヨ止
ソスソスソスソスLソスナは、ソスソスソスソス(ソスソス:192.168.1.XXX)ソスニ外ソスソス(ソスソス:xxx.ppp.asahi-net.or.jp)ソスソスソスソスフみ、vsftpdソスヨのアソスNソスZソスXソスソスソスソスソスツゑソスソストゑソスソスソス


ソスソスソスヨ連ソスRソスソスソスeソスソスソスc

<!ソス\ソスeソスLソスXソスgソスフみゑソス4ソスsソス\ソスソスソスノ追会ソスソスソスCソスソスソスソスソスソス\>



ソスソスソスソスソスフペソス[ソスWソスフトソスbソスvソスヨ戻ゑソス

ソスvソスソスソスCソスoソスVソス[ソス|ソスソスソスVソス[