12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Transferring Files with FTP 387. per_source: Set the maximum number of service instances per IP address.. access_times: Set the time intervals when the service is available in the formhour:min-hour:min. Connections are accepted at the bounds of the interval.Transferring Files with FTPFTP stands for File Transfer Protocol. An FTP server allows clients to connect to it eitheranonymously or with a username and password combination. After successful authentication,files can be transferred back and forth between the server and client. The files areneither encrypted nor compressed.CAUTIONBecause the files are not encrypted, use caution when transferring files if they containsensitive information. Anyone on the same network, including the Internet if the transfergoes over the public Internet, can intercept the files as well as the username andpassword used to connect to the FTP server.FTP and SE<strong>Linux</strong>If SE<strong>Linux</strong>, a mandatory access control security mechanism, is set to enforcing mode, theFTP daemon is protected by it. Refer to Chapter 23 for details on SE<strong>Linux</strong>.If the FTP daemon is configured to share files anonymously, the shared files must belabeled with the public_content_t security context such as the following for the /var/ftp/ directory:chcon -R -t public_content_t /var/ftp/After setting up an uploads directory, you must set the security context of it topublic_content_rw_t such as the following for the /var/ftp/incoming/ directory:chcon -R -t public_content_rw_t /var/ftp/incoming/CAUTIONIf the filesystem is relabeled for SE<strong>Linux</strong>, the security context changes you make willbe overwritten. To make your changes permanent even through a relabel, refer to the“Making Security Context Changes Permanent” section in Chapter 23.19To allow users to write to the uploads directory, you must also enable theallow_ftpd_anon_write boolean with the following command:setsebool -P allow_ftpd_anon_write=1To verify that the setting has been changed, execute the following:getsebool allow_ftpd_anon_write=1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!