You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Ubuntu SFTP用户添加脚本中传入root账号密码

Solution for Adding Root Authentication to Your SFTP User Creation Script

Got it, let's tweak your existing script so it can run from any user context by accepting root credentials as parameters. I'll walk through the modified script and explain the key changes below.

Modified Script

#!/bin/bash

# Configuration
SFTPONLY_GROUP="sftponly"
SFTP_BASE_FOLDER="/srv/sftp"
UPLOAD_DIR="htdocs"

# Parameter handling
USERID="$1"
ROOT_PASS="$2"

# Check if required parameters are provided
if [ -z "$USERID" ] || [ -z "$ROOT_PASS" ]; then
    echo "Usage: $0 <sftp-username> <root-password>"
    exit 1
fi

# Function to execute commands as root
run_as_root() {
    echo "$ROOT_PASS" | su - root -c "$1"
}

# Verify root password works first
echo "Verifying root credentials..."
if ! run_as_root "echo 'Root authentication successful'"; then
    echo "Error: Invalid root password"
    exit 1
fi

# Create sftponly group if it doesn't exist
echo "Checking sftponly group..."
run_as_root "getent group $SFTPONLY_GROUP || groupadd $SFTPONLY_GROUP"

# Create base SFTP folder if it doesn't exist
echo "Setting up base SFTP directory..."
run_as_root "mkdir -p $SFTP_BASE_FOLDER && chown root:root $SFTP_BASE_FOLDER && chmod 755 $SFTP_BASE_FOLDER"

# Create user and set up their directory
echo "Creating SFTP user $USERID..."
# Create user with no shell, home directory in SFTP base
run_as_root "useradd -m -d $SFTP_BASE_FOLDER/$USERID -s /usr/sbin/nologin -G $SFTPONLY_GROUP $USERID"
# Set user password (you might want to make this a parameter too, or auto-generate)
echo "$USERID:$USERID" | run_as_root "chpasswd"

# Set up upload directory
echo "Configuring upload directory..."
run_as_root "mkdir -p $SFTP_BASE_FOLDER/$USERID/$UPLOAD_DIR"
run_as_root "chown $USERID:$SFTPONLY_GROUP $SFTP_BASE_FOLDER/$USERID/$UPLOAD_DIR"
run_as_root "chmod 755 $SFTP_BASE_FOLDER/$USERID/$UPLOAD_DIR"

# Restrict user to SFTP only (update sshd_config if needed)
echo "Updating SSH configuration..."
SSHD_CONFIG="/etc/ssh/sshd_config"
# Check if sftponly group config already exists
if ! run_as_root "grep -q 'Match Group $SFTPONLY_GROUP' $SSHD_CONFIG"; then
    run_as_root "cat >> $SSHD_CONFIG <<EOF
Match Group $SFTPONLY_GROUP
    ChrootDirectory $SFTP_BASE_FOLDER/%u
    ForceCommand internal-sftp
    X11Forwarding no
    AllowTcpForwarding no
EOF"
    # Restart sshd to apply changes
    run_as_root "systemctl restart sshd"
fi

echo "SFTP user $USERID created successfully!"

Key Changes Explained

  • Parameter Validation: The script now checks that both the SFTP username and root password are provided, and shows a clear usage message if either is missing.
  • run_as_root Helper Function: This function wraps all privileged commands with su - root, using the provided password to switch to root context. It first validates the password to avoid wasting time on failed operations.
  • Security Heads-Up: Passing the root password as a command-line parameter is not ideal—it will show up in your shell history and process lists. If you can, consider using sudo with NOPASSWD access for the user running the script, or replace the parameter with an interactive prompt (like read -s -p "Enter root password: " ROOT_PASS).
  • Preserved Original Logic: All your original SFTP setup steps (group creation, directory permissions, SSH config locks) are kept intact, just wrapped to run with root privileges.

Usage Example

Run the script from any user account like this:

./create_sftp_user.sh mynewuser myrootpassword

内容的提问来源于stack exchange,提问作者Kavendra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 10:00:56