如何在Ubuntu SFTP用户添加脚本中传入root账号密码
Solution for Adding Root Authentication to Your SFTP User Creation Script
Got it, let's tweak your existing script so it can run from any user context by accepting root credentials as parameters. I'll walk through the modified script and explain the key changes below.
Modified Script
#!/bin/bash # Configuration SFTPONLY_GROUP="sftponly" SFTP_BASE_FOLDER="/srv/sftp" UPLOAD_DIR="htdocs" # Parameter handling USERID="$1" ROOT_PASS="$2" # Check if required parameters are provided if [ -z "$USERID" ] || [ -z "$ROOT_PASS" ]; then echo "Usage: $0 <sftp-username> <root-password>" exit 1 fi # Function to execute commands as root run_as_root() { echo "$ROOT_PASS" | su - root -c "$1" } # Verify root password works first echo "Verifying root credentials..." if ! run_as_root "echo 'Root authentication successful'"; then echo "Error: Invalid root password" exit 1 fi # Create sftponly group if it doesn't exist echo "Checking sftponly group..." run_as_root "getent group $SFTPONLY_GROUP || groupadd $SFTPONLY_GROUP" # Create base SFTP folder if it doesn't exist echo "Setting up base SFTP directory..." run_as_root "mkdir -p $SFTP_BASE_FOLDER && chown root:root $SFTP_BASE_FOLDER && chmod 755 $SFTP_BASE_FOLDER" # Create user and set up their directory echo "Creating SFTP user $USERID..." # Create user with no shell, home directory in SFTP base run_as_root "useradd -m -d $SFTP_BASE_FOLDER/$USERID -s /usr/sbin/nologin -G $SFTPONLY_GROUP $USERID" # Set user password (you might want to make this a parameter too, or auto-generate) echo "$USERID:$USERID" | run_as_root "chpasswd" # Set up upload directory echo "Configuring upload directory..." run_as_root "mkdir -p $SFTP_BASE_FOLDER/$USERID/$UPLOAD_DIR" run_as_root "chown $USERID:$SFTPONLY_GROUP $SFTP_BASE_FOLDER/$USERID/$UPLOAD_DIR" run_as_root "chmod 755 $SFTP_BASE_FOLDER/$USERID/$UPLOAD_DIR" # Restrict user to SFTP only (update sshd_config if needed) echo "Updating SSH configuration..." SSHD_CONFIG="/etc/ssh/sshd_config" # Check if sftponly group config already exists if ! run_as_root "grep -q 'Match Group $SFTPONLY_GROUP' $SSHD_CONFIG"; then run_as_root "cat >> $SSHD_CONFIG <<EOF Match Group $SFTPONLY_GROUP ChrootDirectory $SFTP_BASE_FOLDER/%u ForceCommand internal-sftp X11Forwarding no AllowTcpForwarding no EOF" # Restart sshd to apply changes run_as_root "systemctl restart sshd" fi echo "SFTP user $USERID created successfully!"
Key Changes Explained
- Parameter Validation: The script now checks that both the SFTP username and root password are provided, and shows a clear usage message if either is missing.
run_as_rootHelper Function: This function wraps all privileged commands withsu - root, using the provided password to switch to root context. It first validates the password to avoid wasting time on failed operations.- Security Heads-Up: Passing the root password as a command-line parameter is not ideal—it will show up in your shell history and process lists. If you can, consider using
sudowith NOPASSWD access for the user running the script, or replace the parameter with an interactive prompt (likeread -s -p "Enter root password: " ROOT_PASS). - Preserved Original Logic: All your original SFTP setup steps (group creation, directory permissions, SSH config locks) are kept intact, just wrapped to run with root privileges.
Usage Example
Run the script from any user account like this:
./create_sftp_user.sh mynewuser myrootpassword
内容的提问来源于stack exchange,提问作者Kavendra
相关产品推荐
相关产品推荐

