FTP Server Only SSL/TLS

Backup and data protection discussion at its finest.

Moderator: Lillian.W@AST

Post Reply
blackstar
Posts: 59
youtube meble na wymiar Warszawa
Joined: Thu Apr 25, 2013 3:37 am

FTP Server Only SSL/TLS

Post by blackstar »

Hi,
I have two questions :

1) Is it possible to disable "regular" FTP connection while leaving FTPES connections open ?

2) How do I hide the "Home" folder of my ftp user when connecting through a ftp client ?

Thanks for any help that could be provided.
Cheers.
meteora
Posts: 37
Joined: Wed Mar 13, 2013 2:12 pm

Re: FTP Server Only SSL/TLS

Post by meteora »

i remember proftpd.conf doesn't have such option for running SSL/TLS only
User avatar
James.W@AST
Posts: 189
Joined: Wed Jun 06, 2012 12:50 am

Re: FTP Server Only SSL/TLS

Post by James.W@AST »

Hi there,

1. FTP server cannot run SSL/TLS solely.
2. Just did some quick experiments, but I can just make the Home folder becomes inaccessible. There seems no easy way to hide the Home folder for any specific user...
To Infinity and Beyond!

Friends of My AS-606T: (RAID 5 with WD Black 2TB * 4, WD Red 2TB * 2)
MacBook Air (10.8) & Self-assembled Windows PC (Windows 7)
iPhone 4S (iOS 6) & iPad 2 (iOS 6)
Boxee Box, Logitech Squeezebox Duet
SONY HT-CT150 Sound Bar (Connected directly to the NAS via HDMI)
CISCO Linksys E4200
blackstar
Posts: 59
Joined: Thu Apr 25, 2013 3:37 am

Re: FTP Server Only SSL/TLS

Post by blackstar »

Mmmm,

In that case, is there a way to block the user from accesing via "regular" ftp connection ?

I want the users only to access through FTPES connection and not be able to log via simple ftp connection...
blackstar
Posts: 59
Joined: Thu Apr 25, 2013 3:37 am

Re: FTP Server Only SSL/TLS

Post by blackstar »

Hi again, I've been snooping around the other NAS devices. ANd I found out that QNAP does allow for such configuration :
only FTP over explicit SSL withou "regular" FTP

And after discussing the subject with a friend of mine, I also foudn out that on QNAP there's an option when creating a user that allows NOT to create a home directory for the user.

Is there any way we could achieve this is a next release ?

In the meantime, I thought about a workaround : is there a way to use different port for FTP and FTP over SSL ? If so, Iwould only have to redirect only the FTPES port on my router to my NAS.
blackstar
Posts: 59
Joined: Thu Apr 25, 2013 3:37 am

Re: FTP Server Only SSL/TLS

Post by blackstar »

meteora wrote:i remember proftpd.conf doesn't have such option for running SSL/TLS only
I just looked at this website : http://www.proftpd.org/docs/howto/TLS.html

and here what I found :
# Are clients required to use FTP over TLS when talking to this server?
TLSRequired off

Might it be how to configure it to require the explicit SSL and unable user to connect without it.
blackstar
Posts: 59
Joined: Thu Apr 25, 2013 3:37 am

Re: FTP Server Only SSL/TLS

Post by blackstar »

It seems there's also another issue : when I configure my FTP server on the non standard port and configure the port redirection on my router here's what I get when trying to connect with my public IP :
Statut : Le serveur a envoyé une réponse passive avec une adresse non routable. Adresse remplacée par celle du serveur.
Commande : MLSD
Erreur : GnuTLS error -53: Erreur au niveau de la fonction "push".
(Sorry it is in French)

Any help would be greatly appreciated.
Cheers.
blackstar
Posts: 59
Joined: Thu Apr 25, 2013 3:37 am

Re: FTP Server Only SSL/TLS

Post by blackstar »

Actually managed to find what was wrong : I had not redirected the passive ports.

Now connection works fine both with explicit ssl but also without.

It would be awesome if we could turn off one while leaving the other running in the future.
Having an option to create specific quser without home directories would be nice ( that way no Home directory would show up on the FTP client side)

Cheers.
User avatar
yogi
Posts: 93
Joined: Fri Jul 12, 2013 2:43 am
Location: Berlin

Re: FTP Server Only SSL/TLS

Post by yogi »

i agree, creating an own home dir for every ftp user is bs :oops:

and we need a 'force ssl' option, i would never use plain ftp unencrypted on port 21 ;)
Home Storage: 8x Seagate IronWolf NAS HDD 8TB ST8000VN0022 @ 608T
blackstar
Posts: 59
Joined: Thu Apr 25, 2013 3:37 am

Re: FTP Server Only SSL/TLS

Post by blackstar »

Hello,
Any input on this topic from the asustor team.
It would be really nice to be able to use this functionality.
Post Reply

Return to “Backup and Data Protection”