一、安装FTP及相关配制
[ ~]# yum install vsftpd
==============================================
Package Arch Version Repository
==============================================
Installing:
vsftpd i386 2.0.5-16.el5 FTP134.200-32b 1
Transaction Summary
===========================
Total download size: 140 k
Is this ok [y/N]: y
Downloading Packages:
vsftpd-2.0.5-16.el5.i386.rpm | 140 kB 00:00
Finished Transaction Test
Installed:
vsftpd.i386 0:2.0.5-16.el5
Complete!
[{aa8aa} ~]# rpm -q vsftpd
vsftpd-2.0.5-16.el5
[{aa7aa} ~]# rpm -ql vsftpd
/etc/logrotate.d/vsftpd.log
/etc/pam.d/vsftpd
/etc/rc.d/init.d/vsftpd
/etc/vsftpd
/etc/vsftpd/ftpusers
/etc/vsftpd/user_list
/etc/vsftpd/vsftpd.conf
/etc/vsftpd/vsftpd_conf_migrate.sh
/usr/sbin/vsftpd
...
/var/ftp
/var/ftp/pub
[{aa6aa} upload]# vi /etc/vsftpd/vsftpd.conf
# 允许匿名用户登录
# Allow anonymous FTP? (Beware - allowed by default if you comment this out).
anonymous_enable=YES
# 允许系统用户登录
# Uncomment this to allow local users to log in.
local_enable=YES
# 允许系统用户写权限用户登录
# Uncomment this to enable any form of FTP write command.
write_enable=YES
# 允许匿名用户上传
# Uncomment this to allow the anonymous FTP user to upload files. This only
# has an effect if the above global write enable is activated. Also, you will
# obviously need to create a directory writable by the FTP user.
anon_upload_enable=YES
# 允许匿名用户写权限、其它权限
# Uncomment this if you want the anonymous FTP user to be able to create
# new directories.
anon_mkdir_write_enable=YES
anon_other_write_enable=YES
# 显示.messages中的自定义信息
# Activate directory messages - messages given to remote users when they
# go into a certain directory.
dirmessage_enable=YES
# 打开日志功能
# The target log file can be vsftpd_log_file or xferlog_file.
# This depends on setting xferlog_std_format parameter
xferlog_enable=YES
#
# Make sure PORT transfer connections originate from port 20 (ftp-data).
connect_from_port_20=YES
# 修改上传名的权限
# If you want, you can arrange for uploaded anonymous files to be owned by
# a different user. Note! Using "root" for uploaded files is not
# recommended!
#chown_uploads=YES
#chown_username=whoever
# 打开日志功能之 定义日志名
# The name of log file when xferlog_enable=YES and xferlog_std_format=YES
# WARNING - changing this filename affects /etc/logrotate.d/vsftpd.log
xferlog_file=/var/log/vsftpd.log
# 启动日志标准格式
# Switches between logging into vsftpd_log_file and xferlog_file files.
# NO writes to vsftpd_log_file, YES to xferlog_file
xferlog_std_format=YES
# 禁锢部分用户在家目录下(方法一)
# You may specify an explicit list of local users to chroot() to their home
# directory. If chroot_local_user is YES, then this list becomes a list of
# users to NOT chroot().
chroot_list_enable=YES 定义启用
# (default follows)
chroot_list_file=/etc/vsftpd/chroot_list 定义到列表中方可生效
# 禁锢所有用户在家目录下(方法二)
chroot_local_user=YES
pam_service_name=vsftpd
userlist_enable=YES # userlist中的用户名控制启用,规则参照下一个命令
userlist_deny=YES # 若=NO白名单,若=YES则为黑名单
tcp_wrappers=YES
[ vsftpd]# ls /etc/vsftpd/
chroot_list ftpusers user_list vsftpd.conf vsftpd_conf_migrate.sh
[{aa4aa} vsftpd]# cat user_list
# vsftpd userlist
# If userlist_deny=NO, only allow users in this file
# If userlist_deny=YES (default), never allow users in this file, and
# do not even prompt for a password.
# Note that the default vsftpd pam config also checks /etc/vsftpd/ftpusers
# for users that are denied.
root
bin
daemon
adm
lp
sync
shutdown
halt
mail
news
uucp
operator
games
nobody
[ vsftpd]#
二、安装FTP认证登录
FTP中同时有系统读写权限和文件共享读写权限时,FTP帐号才有读写权限;
[ ftp]# ls -ld /var/ftp/pub/
drwxr-xr-x 2 root root 4096 May 13 2009 /var/ftp/pub/
ls -ld /var/ftp/
drwxr-xr-x 3 root root 4096 Jan 12 10:48 /var/ftp/
mkdir upload[ ftp]# lspub upload ls -ld /var/ftp/upload/drwxr-xr-x 2 root root 4096 Jan 12 15:30 /var/ftp/upload/ setfasetfacl setfattr setfacl -m /var/ftp/upload/ 新增ftp帐号的所有权限getfacl /var/ftp/upload/getfacl: Removing leading ‘/‘ from absolute path names# file: var/ftp/upload# owner: root# group: rootuser::rwxgroup::r-xmask::rwxother::r-x
来源: