Score:0

add notty to authorized users

co flag

I miss to understand the topic: a request from my corp's sec team.

while setting up an sftp with chroot they insist I've to (quoting) "add notty to authorized users". to my knowledge the notty is the outcome of a login made by a user with no shell (e.g. an ssh user whose config bind her to sftp only and -to-say- has /usr/sbin/nologin configured).

what am I missing? any pointer on the openssh docs (redhat version 7)?

thank you

Score:1
cn flag

This looks like it's what you want: https://serverfault.com/a/354618/230046

It'll mean users in the sftponly group can only SFTP, not SSH.

matteo nunziati avatar
co flag
Yep this is what we have setup... But sec in my company seems to not be happy until a mystic notty user will be added to some group... I start thinking they simply don't know what a sftp setup is...
cn flag
I think they want you to add the option `notty` to the users? I'm sure if you show them the config and speak to your local friendly security person, you'll get it sorted!
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.