Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

Allow SFTP but lock down SSH with key only

Discussion in 'Security' started by CBG, Dec 20, 2017.

Tags:
  1. CBG

    CBG Active Member

    Joined:
    Apr 23, 2010
    Messages:
    36
    Likes Received:
    1
    Trophy Points:
    58
    cPanel Access Level:
    Root Administrator
    Hi,

    How do I allow SFTP on the SSH port, but also lock down SSH.
    So that when logging in to SSH, you need to have the key file, and stop password logins.

    Is this possible and if so how?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. cPanelMichael

    cPanelMichael Technical Support Community Manager
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    44,803
    Likes Received:
    1,897
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Twitter:
    Hello,

    This isn't supported by default through a specific feature, but you may find the workaround referenced on the following third-party URL helpful:

    Separate SSH and SFTP

    Thank you.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
    CBG likes this.
  3. sparek-3

    sparek-3 Well-Known Member

    Joined:
    Aug 10, 2002
    Messages:
    1,762
    Likes Received:
    116
    Trophy Points:
    343
    cPanel Access Level:
    Root Administrator
    The feature request:

    SFTP access for virtual FTP users

    might apply here.

    Personally, if it were me, I'd encourage cPanel to provide SFTP support through ProFTPd (or some other FTP daemon that supports SFTP emulation... I'm only aware of ProFTPd). This way you can have a bit more granular control, i.e. run SFTP off of a different port than your SSH service. This can also provide SFTP support for virtual FTP users.

    But this feature request seems to have gotten stuck into what I like to call feature request purgatory.
     
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice