DOCUMENT OF SFTP SERVER WITH 256 BIT AES ENCRYPTION
Appearance
DOCUMENT OF SFTP SERVER WITH 256 BIT AES ENCRYPTION AT INNODATA[edit]
Sftp comes with ssh service so there is no separate daemon for this
STEPS. Open sshd config file which is /etc/ssh/sshd_config
Comment out below line
#Subsystem sftp /usr/libexec/openssh/sftp-server
And add below lines
Subsystem sftp internal-sftp Match Group sftponly ChrootDirectory /home/%u #JAILED FTP ForceCommand internal-sftp AllowTcpForwarding no Ciphers aes256-ctr,aes256-cbc #to enable aes 256bit encryption
Commands to Add New User. Type in terminal:
# groupadd sftponly # usermod -g sftponly saket # usermod -s /bin/false saket # chmod 755 /home/saket # chmod 755 /home/saket # chown root:root /home/saket # mkdir /home/saket/FTPDATA # chown saket:sftponly /home/saket/FTPDATA
Now Restart SSH Service.
# /etc/init.d/ssh restart
