rdiff-backup-users
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [rdiff-backup-users] Clarification of --restrict-update-only


From: Chris G
Subject: Re: [rdiff-backup-users] Clarification of --restrict-update-only
Date: Thu, 5 Feb 2009 10:38:42 +0000
User-agent: Mutt/1.5.17 (2007-11-01)

Anyway, back to the original point of my question, if I put:-

    Match User=bak
    ForceCommand rdiff-backup --server --restrict-update-only /

at the end of my sshd configuration on the backup server will it prevent
rdiff-backup doing anything but updates on any/every part of the
backup hierarchy?

I know the "ForceCommand rdiff-backup --server" bit works, attempts to
log in to the backup server using ssh to the bak account fail. Thus
the only thing an intruder can do from a client machine using the
passwordless bak account is to run rdiff-backup.  If I can further
restrict it to minimise the possibility of deleting useful data then
so much the better, I just want to clarify how the restrict-update-only 
works.

-- 
Chris Green




reply via email to

[Prev in Thread] Current Thread [Next in Thread]