Date: Sun, 23 Dec 2012 14:46:25 +0000 From: Matthew Seaman <matthew@FreeBSD.org> To: Fbsd8 <fbsd8@a1poweruser.com> Cc: Damien Fleuriot <ml@my.gd>, FreeBSD Questions <freebsd-questions@freebsd.org> Subject: Re: how to configure host login account to use jail? Message-ID: <50D71941.10306@FreeBSD.org> In-Reply-To: <50D702F6.6010408@a1poweruser.com> References: <50D66FEF.5040105@a1poweruser.com> <7B1B77F2-A104-4796-996B-DA5B8D448D54@my.gd> <50D702F6.6010408@a1poweruser.com>
index | next in thread | previous in thread | raw e-mail
[-- Attachment #1 --] On 23/12/2012 13:11, Fbsd8 wrote: > Ok but as my question asks, how do you configure things > to get that to work? I am after the details. You need to run an instance of sshd in each jail. Because sshd defaults to binding to INADDR_ANY, you need to modify the sshd configuration in the host system, so it binds to a specific address, otherwise it will likely block out the jailed sshd's: ListenAddress 192.0.2.1 ListenAddress 2001:DB8::1 ListenAddress 127.0.0.1 ListenAddress ::1 sshd in the jails doesn't need any similar configuration change. You don't need user accounts in your host system for the jail users -- each jail can have it's own passwd file etc. However, it can be useful to make sure that UID numbers for regular users in host and jails don't overlap. Cheers, Matthew -- Dr Matthew J Seaman MA, D.Phil. PGP: http://www.infracaninophile.co.uk/pgpkey [-- Attachment #2 --] -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.16 (Darwin) Comment: Using GnuPG with undefined - http://www.enigmail.net/ iEYEARECAAYFAlDXGUoACgkQ8Mjk52CukIw/LgCeMjMeoovPcYMUvgKOWEv4716a C8YAoICqlGwvLqTxUrQh3i/mmssHOaw7 =OrGm -----END PGP SIGNATURE-----help
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?50D71941.10306>
