SFTP chroot access (user limited to their folder)
Create secure SFTP access for a client or developer, without full SSH access.
What this tutorial does
The tutorial "SFTP chroot access (user limited to their folder)" helps you achieve this goal:
Create secure SFTP access for a client or developer, without full SSH access.
Debian/Ubuntu
- --- Create the user and their directory ---
- adduser client1
- mkdir -p /var/www/sites/client1
-
chown root:root /var/www/sites/client1 (required for chroot) - mkdir -p /var/www/sites/client1/www
-
chown client1:client1 /var/www/sites/client1/www -
--- Configure SSH for SFTP chroot --- -
Edit /etc/ssh/sshd_config and add at the end of the file: - Match User client1
- ChrootDirectory /var/www/sites/client1
-
ForceCommand internal-sftp - AllowTcpForwarding no
- X11Forwarding no
-
Restart SSH: systemctl restart sshd -
--- Test the SFTP connection --- -
sftp client1@IP (the user only sees the /www folder) -
Classic SSH connection will be automatically refused for this user.