[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#798639: marked as done (ITP: restricted-ssh-commands -- Restrict SSH users to a predefined set of commands)



Your message dated Wed, 07 Oct 2015 10:01:17 +0000
with message-id <E1ZjlXB-0005St-Qm@franck.debian.org>
and subject line Bug#798639: fixed in restricted-ssh-commands 0.1-1
has caused the Debian Bug report #798639,
regarding ITP: restricted-ssh-commands -- Restrict SSH users to a predefined set of commands
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
798639: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=798639
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: wnpp
Severity: wishlist
Owner: Benjamin Drung <benjamin.drung@profitbricks.com>

* Package name    : restricted-ssh-commands
  Version         : TBD
  Upstream Author : Benjamin Drung <benjamin.drung@profitbricks.com>
* URL             : TBD
* License         : MIT
  Programming Lang: Bash
  Description     : Restrict SSH users to a predefined set of commands

restricted-ssh-commands is intended to be called by SSH to restrict a
user to only run specific commands. A list of allowed regular
expressions can be configured in /etc/restricted-ssh-commands/. The
requested command has to match at least one regular expression.
Otherwise it will be rejected.

restricted-ssh-commands is useful to grant restricted access via SSH to
do certain task. For example, it could allow a user to upload a Debian
packages via scp and run reprepro processincoming.

Create a configuration file in /etc/restricted-ssh-commands/ and add
following line to ~/.ssh/authorized_keys to use it

    command="/usr/bin/restricted-ssh-commands",no-port-forwarding,no-X11-forwarding,no-agent-forwarding,no-pty ssh-rsa [...]

restricted-ssh-commands is a small shell script, which I use for dput
uploads and safe reboots. I found no other tool that fit into this
niche. rssh and rbash are related, but behave slightly different. Let me
know if you know a similar tool. Otherwise I will write the man page,
create a package, and release it.

-- 
Benjamin Drung
System Developer
Debian & Ubuntu Developer

ProfitBricks GmbH
Greifswalder Str. 207
D - 10405 Berlin

Email: benjamin.drung@profitbricks.com
URL:  http://www.profitbricks.com

Sitz der Gesellschaft: Berlin.
Registergericht: Amtsgericht Charlottenburg, HRB 125506B.
Geschäftsführer: Andreas Gauger, Achim Weiss.

--- End Message ---
--- Begin Message ---
Source: restricted-ssh-commands
Source-Version: 0.1-1

We believe that the bug you reported is fixed in the latest version of
restricted-ssh-commands, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 798639@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Benjamin Drung <bdrung@debian.org> (supplier of updated restricted-ssh-commands package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Tue, 06 Oct 2015 12:32:49 +0200
Source: restricted-ssh-commands
Binary: restricted-ssh-commands
Architecture: source amd64
Version: 0.1-1
Distribution: unstable
Urgency: medium
Maintainer: Benjamin Drung <bdrung@debian.org>
Changed-By: Benjamin Drung <bdrung@debian.org>
Description:
 restricted-ssh-commands - Restrict SSH users to a predefined set of commands
Closes: 798639
Changes:
 restricted-ssh-commands (0.1-1) unstable; urgency=medium
 .
   * Initial release (Closes: #798639)
Checksums-Sha1:
 77432ff01f8e88437a59ded922a2e65571f47ada 1840 restricted-ssh-commands_0.1-1.dsc
 86cfbef8f3f60fdca9772786fd06e25f0a272f6d 3596 restricted-ssh-commands_0.1.orig.tar.xz
 02f43e43f5e75ed86c6ff3252d7ea6f72703e0f7 8472 restricted-ssh-commands_0.1-1.debian.tar.xz
 ac6d475879c5253cd46a9a01bba71fc746f1a379 6094 restricted-ssh-commands_0.1-1_amd64.deb
Checksums-Sha256:
 003aa05e234bb5bba10d064caa1c669b101cb8db0230e31e0661a4ccf4169463 1840 restricted-ssh-commands_0.1-1.dsc
 a8859d78d5d8c17d124e943e731e09492b960fc97d14e9e0cd5401bc7248ebf6 3596 restricted-ssh-commands_0.1.orig.tar.xz
 846a0ce06d871a91d9f3e9415b891790d3e9979efa7db6ebad0474bab06f2b64 8472 restricted-ssh-commands_0.1-1.debian.tar.xz
 9cbbf558b990bc1f8aee8f0bf76d7ebac745b8f90ecaec0e3d3b6049e2f9dbd9 6094 restricted-ssh-commands_0.1-1_amd64.deb
Files:
 925fd5216db9b01cf9c094f51fa5ce38 1840 net optional restricted-ssh-commands_0.1-1.dsc
 6b94dfa8de716942840fb16625067df6 3596 net optional restricted-ssh-commands_0.1.orig.tar.xz
 d6d792127b51095ce80f3a409ec77a3b 8472 net optional restricted-ssh-commands_0.1-1.debian.tar.xz
 10781604bc637bc5829c6013db075e70 6094 net optional restricted-ssh-commands_0.1-1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJWE6RcAAoJEN2M1aXejH56LtgP/iUdRtpQoc0zZitQmlDsbDBE
yTiyempzzzOnZLnf24zKy8rr79kcGO0NyPyj6GoCDgVV1DOhcRFVRUxBQM+q+mYd
LjWPXze1Xr3UwY3YvKiWuYP6PVeEqudB30jWWSNdOzZtyK3hGT9pFC3tg52C8ehE
3E1DENa23HtoeyhP7opprsXDieRs3Zidgt7mluG0hrlyQzzHpnmwdiPaPZwwTm5q
jlN8YftOc5oGAbkulfbSTdINbue1d1POTwjjuxU61sGUR2azXc9RmBlOgOgkkZcu
vkjHUIe5n1f4Ahgpbp07Whd+wbvxSUv/gUVveBRtvQxIQfnuHva6gX8JnQBwjbwp
Sm5c65l20X/Who1ZSKKT1nHugMbyyk9rhhalSq2kYNbB72RAV+v+KkviipqNE15T
cSWe4znbcrV6JICgtwEBJE8ly+vm/dItx4qNZqYeLde/GKWAWro4KbJVlgY1Gdlm
/ECzOel8EJjg1VSzJDkTA0iTVKSteTSB6vU++1OyEmkCoL0FiVt4Vpfr/w0QGoaJ
wua8vtCBJNtSsd9N+QeUHvpxOAWS3O9N+3XnB3uivBvS1YwYET4zZg1GBxlKWYWy
uXfeKrNhB36e9a0borVB1Vp6QtX8pPmCuMxgZTVrV7mCspmxfBd1FtZMRIPOtSJ8
ZteigFORdfat4MCIjaM7
=ZrMR
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: