PDA

Archiv verlassen und diese Seite im Standarddesign anzeigen : (Pro)Ftpd Login-Problem (530)



Dj-SPm
01.06.07, 20:22
Hallo,

ich habe ProftpD 1.3.0a installiert und die Standart-Conf unverändert gelassen. Nur leider kann sich kein User, außer dem Anonymen User einloggen. Habe hier Debug und Conf-File.

Ich habe einen Benutzer, der heißt "notebook" mit dem Passwort "geheim". Dieser User ist in der Gruppe "users".

Starte ich jetzt einen FTP_Client und logge mich mit notebook und geheim ein, so verweigert er mir den Login mit dem Fehlercode 530 (Login incorrect)

Das ist auch der Fall, wenn ich die Direktive


<Limit LOGIN>
DenyGroup !users
</Limit>

eingebe.

Was mache ich falsch??? Hier alle Daten

Debug vom Moment des Einloggens (weiter unten die conf)


SRVMuellers.site (192.168.2.103[192.168.2.103]) - ROOT PRIVS at main.c:1025
SRVMuellers.site (192.168.2.103[192.168.2.103]) - SETUP PRIVS at main.c:1030
SRVMuellers.site (192.168.2.103[192.168.2.103]) - FTP session requested from unknown class
SRVMuellers.site (192.168.2.103[192.168.2.103]) - performing module session initializations
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: opening DelayTable '/usr/local/var/proftpd/proftpd.delay'
SRVMuellers.site (192.168.2.103[192.168.2.103]) - ROOT PRIVS at mod_delay.c:948
SRVMuellers.site (192.168.2.103[192.168.2.103]) - FS: using system open()
SRVMuellers.site (192.168.2.103[192.168.2.103]) - RELINQUISH PRIVS at mod_delay.c:950
SRVMuellers.site (192.168.2.103[192.168.2.103]) - ROOT PRIVS at mod_auth.c:145
SRVMuellers.site (192.168.2.103[192.168.2.103]) - opening scoreboard '/usr/local/var/proftpd/proftpd.scoreboard'
SRVMuellers.site (192.168.2.103[192.168.2.103]) - RELINQUISH PRIVS at mod_auth.c:147
SRVMuellers.site (192.168.2.103[192.168.2.103]) - performing ident lookup
SRVMuellers.site (192.168.2.103[192.168.2.103]) - ident connection failed: Interrupted system call
SRVMuellers.site (192.168.2.103[192.168.2.103]) - ident lookup returned 'UNKNOWN'
SRVMuellers.site (192.168.2.103[192.168.2.103]) - connected - local : 192.168.2.11:21
SRVMuellers.site (192.168.2.103[192.168.2.103]) - connected - remote : 192.168.2.103:51148
SRVMuellers.site (192.168.2.103[192.168.2.103]) - FTP session opened.
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching PRE_CMD command 'USER notebook' to mod_core
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching PRE_CMD command 'USER notebook' to mod_core
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching PRE_CMD command 'USER notebook' to mod_delay
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching PRE_CMD command 'USER notebook' to mod_auth
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endpwent" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endpwent" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endgrent" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endgrent" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching CMD command 'USER notebook' to mod_auth
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "getgroups" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "getgroups" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - retrieved group IDs: 100, 49, 1102, 1002
SRVMuellers.site (192.168.2.103[192.168.2.103]) - retrieved group names: users, ftp, ftpgroup, ftpuser
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching POST_CMD command 'USER notebook' to mod_delay
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: mapping DelayTable '/usr/local/var/proftpd/proftpd.delay' into memory
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: write-locking DelayTable '/usr/local/var/proftpd/proftpd.delay', row 1
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: selecting median interval from 18 values
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: adding 519 usecs to USER row
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: unlocking DelayTable '/usr/local/var/proftpd/proftpd.delay', row 1
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: unmapping DelayTable '/usr/local/var/proftpd/proftpd.delay' from memory
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching LOG_CMD command 'USER notebook' to mod_log
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching PRE_CMD command 'PASS (hidden)' to mod_core
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching PRE_CMD command 'PASS (hidden)' to mod_core
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching PRE_CMD command 'PASS (hidden)' to mod_delay
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching PRE_CMD command 'PASS (hidden)' to mod_auth
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endpwent" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endpwent" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endgrent" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endgrent" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching CMD command 'PASS (hidden)' to mod_auth
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "getgroups" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "getgroups" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - retrieved group IDs: 100, 49, 1102, 1002
SRVMuellers.site (192.168.2.103[192.168.2.103]) - retrieved group names: users, ftp, ftpgroup, ftpuser
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "getpwnam" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "getpwnam" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - retrieved UID 1001 for user 'notebook'
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "gid2name" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "gid2name" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "auth" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "auth" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - ROOT PRIVS at mod_auth_unix.c:423
SRVMuellers.site (192.168.2.103[192.168.2.103]) - RELINQUISH PRIVS at mod_auth_unix.c:488
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "check" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "check" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - USER notebook (Login failed): Incorrect password.
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching POST_CMD_ERR command 'PASS (hidden)' to mod_delay
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: mapping DelayTable '/usr/local/var/proftpd/proftpd.delay' into memory
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: write-locking DelayTable '/usr/local/var/proftpd/proftpd.delay', row 2
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: selecting median interval from 7 values
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: adding 1870 usecs to PASS row
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: unlocking DelayTable '/usr/local/var/proftpd/proftpd.delay', row 2
SRVMuellers.site (192.168.2.103[192.168.2.103]) - mod_delay/0.5: unmapping DelayTable '/usr/local/var/proftpd/proftpd.delay' from memory
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching LOG_CMD_ERR command 'PASS (hidden)' to mod_log
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching LOG_CMD_ERR command 'PASS (hidden)' to mod_auth
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching event 'core.exit' to core
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching event 'core.exit' to mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endpwent" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endpwent" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endgrent" to module mod_auth_file
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching auth request "endgrent" to module mod_auth_unix
SRVMuellers.site (192.168.2.103[192.168.2.103]) - dispatching event 'core.exit' to mod_xfer


und jetzt die Conf


# This is a basic ProFTPD configuration file (rename it to
# 'proftpd.conf' for actual use. It establishes a single server
# and a single anonymous login. It assumes that you have a user/group
# "nobody" and "ftp" for normal operation and anon.

ServerName "ProFTPD Default Installation"
ServerType standalone
DefaultServer on
RequireValidShell off

<Limit LOGIN>
DenyGroup !ftpuser
</Limit>

# Port 21 is the standard FTP port.
Port 21

# Umask 022 is a good standard umask to prevent new dirs and files
# from being group and world writable.
Umask 022

# To prevent DoS attacks, set the maximum number of child processes
# to 30. If you need to allow more than 30 concurrent connections
# at once, simply increase this value. Note that this ONLY works
# in standalone mode, in inetd mode you should use an inetd server
# that allows you to limit maximum number of processes per service
# (such as xinetd).
MaxInstances 30

# Set the user and group under which the server will run.
User nobody
Group nogroup

# To cause every FTP user to be "jailed" (chrooted) into their home
# directory, uncomment this line.
#DefaultRoot ~

# Normally, we want files to be overwriteable.
AllowOverwrite on

# Bar use of SITE CHMOD by default
<Limit SITE_CHMOD>
DenyAll
</Limit>

# A basic anonymous configuration, no upload directories. If you do not
# want anonymous users, simply delete this entire <Anonymous> section.
<Anonymous ~ftp>
User ftp
Group ftp

# We want clients to be able to login with "anonymous" as well as "ftp"
UserAlias anonymous ftp

# Limit the maximum number of anonymous logins
MaxClients 10

# We want 'welcome.msg' displayed at login, and '.message' displayed
# in each newly chdired directory.
DisplayLogin welcome.msg
DisplayFirstChdir .message

# Limit WRITE everywhere in the anonymous chroot
<Limit WRITE>
DenyAll
</Limit>
</Anonymous>


Vielen Dank

suck
01.06.07, 22:31
Da steht "!ftpuser" statt "!users"!
<Limit LOGIN>
DenyGroup !ftpuser
</Limit>

Dj-SPm
01.06.07, 22:37
Danke, ich habe es abgeändert, neugestartet, aber es hat auch nicht geholfen...

Iluminat23
02.06.07, 04:01
hier mal ein kleiner eventuell nützlicher link
http://proftpd.de/index.php?id=54&language=&directive_name=DenyGroup&module_id=&=OK


eventuell solltest du ja noch ein allow reinpacken?

mfg philipp

Dj-SPm
02.06.07, 11:12
Hallo,

habe jetzt bei "Limit LOGIN" die DenyGroup gelöscht und statt dessen ein AllowUser / AllowGroup mit notebook / users gesetzt. Beides funktioniert auch nicht. Der FTP-Server läuft allerdings. Ich verstehe es nicht. Überall heißt es, nach Installation sei der Server fertig vorkonfiguriert und die SystemUser können sich anmelden...

Dj-SPm
02.06.07, 11:37
Hallo,

habe das Problem gelöst. Ich habe den user notebook zwar angelegt, aber habe ihm beim Anlegen die Anmeldung auf der Shell nicht erlaubt. Somit hat er keinen PW-Eintrag in der Shadow gemacht und blockte die Anmeldung.

Lösung: Shell verbieten, Kennwort vergeben, einloggen. Dann past's!

Hab die User immer mit Webmin angelegt.

Danke