{"id":493,"date":"2019-04-10T08:24:54","date_gmt":"2019-04-10T08:24:54","guid":{"rendered":"https:\/\/jan.schnasse.org\/blog\/?p=493"},"modified":"2026-09-28T11:39:16","modified_gmt":"2026-09-28T09:39:16","slug":"readonly-sftp","status":"publish","type":"post","link":"https:\/\/jan.schnasse.org\/blog\/2019\/04\/10\/readonly-sftp\/","title":{"rendered":"Unix tools introduced. Today: Readonly SFTP"},"content":{"rendered":"<p>To create a user (sftp) with readonly\u00a0 access via sftp to a single directory (\/var\/sftp_readonly), perform the following steps:<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"shell\">sudo su #become root\n\nuseradd sftp #create new user\n\npasswd sftp #set a password\n\ngroupadd sftp_readonly #create a group\n\nmkdir \/var\/sftp_readonly #create a directory\n\nusermod -G sftp_readonly sftp # add user to group\n\nchmod 755 \/var\/sftp_readonly\/ #allow others to read\n\ncp \/etc\/ssh\/sshd_config ~\/sshd_config.bck #backup your ssh config\n\neditor  \/etc\/ssh\/sshd_config # edit your ssh_config<\/pre>\n<p>Add the following lines to the bottom of \/etc\/ssh\/sshd_config<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"shell\">Match Group sftp_readonly\n  X11Forwarding no\n  AllowTcpForwarding no\n  ChrootDirectory \/var\/sftp_readonly\/\n  ForceCommand internal-sftp<\/pre>\n<p>Also make sure that the following line is present<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"shell\">Subsystem sftp internal-sftp<\/pre>\n<p>Reload your ssh service<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"shell\">sudo service ssh reload<\/pre>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>To create a user (sftp) with readonly\u00a0 access via sftp to a single directory (\/var\/sftp_readonly), perform the following steps: sudo su #become root useradd sftp #create new user passwd sftp #set a password groupadd sftp_readonly #create a group mkdir \/var\/sftp_readonly #create a directory usermod -G sftp_readonly sftp # add user to group chmod 755 \/var\/sftp_readonly\/ [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,17],"tags":[],"class_list":["post-493","post","type-post","status-publish","format-standard","hentry","category-admin","category-unixtools"],"_links":{"self":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/posts\/493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/comments?post=493"}],"version-history":[{"count":1,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/posts\/493\/revisions"}],"predecessor-version":[{"id":4353,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/posts\/493\/revisions\/4353"}],"wp:attachment":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/media?parent=493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/categories?post=493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/tags?post=493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}