These forums are locked and archived, but all topics have been migrated to the new forum. You can search for this topic on the new forum: Search for Jailkit on the new forum.
I read a post here about jailkit being considered to provide chrooting SSH. I have already successfully used it on my Virtualmin GPL server. I was also pleasantly surprised to find out how easy it was to chroot a user using jailkit. Is this already included in the pro version?
No, it's not being included now, though they're exploring using a similar feature available in more recent SSH versions.
Some thoughts on that are included in this bug report:
http://www.virtualmin.com/index.php?option=com_flyspray&Itemid=82&am...
Actually, it is very unlikely chroot will ever be a standard feature in Virtualmin. No matter how easy it becomes, unless/until the serious security implications are corrected (which seems impossible, if I understand the issue correctly) we're not going to encourage people to do something dangerous just because it <i>looks</i> like better security.
The right solution, if there is one short of full virtualization (Xen) or near-virtualization (vservers, OpenVZ, Zones), will make use of SELinux rather than chroot. SELinux is and has always been intended as a security feature. chroot never has been. SELinux doesn't break privilege separation. chroot does.
--
Check out the forum guidelines!
Oh, and we do have a product for managing Xen and vservers and Zones coming out in a few days.
--
Check out the forum guidelines!
Thanks for the clarification. Looking forward to the new product managing xen servers!!!
supporting cloudlinux would address the issues jailkit intends to solve.
No, it wouldn't. Cloudlinux isn't needed for any of the things we're using jailkit for.
--
Check out the forum guidelines!
So I see the option "Base directory for Jailkit directories" under Virtualmin configuration. Does that mean jailkit is now supported by virtualmin? Do I need to install it seperately?
Jailkit is supported in Virtualmin, yes. And, you only need to install something if you installed long enough ago that it wasn't part of the default installation (if you installed using a 6.x version of the installer, you already have it, if you didn't you don't). There's probably some minor other config stuff to do, I don't remember how much we handle in Virtualmin and how much we handle in the installer in terms of setting it up and configuring it.
--
Check out the forum guidelines!