VPS1Euro Dashboard Wiki

Complete client guide: infrastructure, services, account and support.

FR EN

SFTP chroot access (user limited to their folder)

Create secure SFTP access for a client or developer, without full SSH access.

What this tutorial does

The tutorial "SFTP chroot access (user limited to their folder)" helps you achieve this goal:

Create secure SFTP access for a client or developer, without full SSH access.

← Back to tutorials
1 profiles 17 steps 9 commands ~20 min

Debian/Ubuntu

  1. --- Create the user and their directory ---
  2. adduser client1
  3. mkdir -p /var/www/sites/client1
  4. chown root:root /var/www/sites/client1 (required for chroot)
  5. mkdir -p /var/www/sites/client1/www
  6. chown client1:client1 /var/www/sites/client1/www
  7. --- Configure SSH for SFTP chroot ---
  8. Edit /etc/ssh/sshd_config and add at the end of the file:
  9. Match User client1
  10. ChrootDirectory /var/www/sites/client1
  11. ForceCommand internal-sftp
  12. AllowTcpForwarding no
  13. X11Forwarding no
  14. Restart SSH: systemctl restart sshd
  15. --- Test the SFTP connection ---
  16. sftp client1@IP (the user only sees the /www folder)
  17. Classic SSH connection will be automatically refused for this user.