Files
2026-07-10 09:57:37 +02:00

1.9 KiB

Add new Users to SFTP Server

Introduction

We configured a SFTP server with a shared chroot jail and such that the server can only be authenticated via public key exchange.

The shared SFTP root folder is at /sftp:

root@z-sftp-01:~# ls -al /sftp/
total 16
drwxr-xr-x  4 root root      4096 Jan 30 15:16 .
drwxr-xr-x 19 root root      4096 Feb  4 00:00 ..
drwxrwx---  2 root sftpusers 4096 Jan 30 15:47 data
drwxrwx---  2 root sftpusers 4096 Jan 30 15:23 uploads

The server can only be reached via sftp by users which are members of the sftpusers group; while these users are not able to login via ssh. Only users which are in admins group can access the server via ssh and this also only via public key authentication.

New User

User Creation

We create the user on the server:

useradd -m -s /sbin/nologin <username>

The option -m explicitly creates a home folder (under /home) for the user which is not created when using the option -s and giving the user the /sbin/nologin shell.

And add the user to the correct group:

usermod -aG sftpusers <username>

SSH authentication

Create a ssh key pair for the user with the command,

ssh-keygen -o -a 100 -t ed25519 -f ~/.ssh/<sbx-sftp-name> -C <user-mail>

which can be done in an arbitrary Unix shell supporting ssh-keygen.

In order for the user to be able to authenticate via public key exchange we have to create a /home/<username>/.ssh/authorized_keys file with proper permissions:

mkdir /home/<username>/.ssh
touch /home/<username>/.ssh/authorized_keys
chown -R <username>:<username> /home/<username>/.ssh
chmod 700 /home/<username>/.ssh
chmod 600 /home/<username>/.ssh/authorized_keys

Take the content of the public key file an insert into the proper authorized_key file

cat ~/.ssh/<sbx-sftp-name>.pub | tee -a ~/.ssh/authorized_keys