How to configure FTP server to support SSL/TLS?


(2 comments)

Full documentation to configure FTP server with proftpd is provided at http://www.proftpd.org. Here we confirm the configuration in practice.
In addition to the default configuration in Omarine, you add the configuration directives below.
First, load the mod_tls module



<IfModule mod_dso.c>
LoadModule mod_tls.c
</IfModule>


Then add the section <IfModule mod_tls.c>. The directives for the configuration have comments attached to explain:



<IfModule mod_tls.c>
TLSEngine on
TLSLog /var/ftpd/tls.log

# Support both SSLv3 and TLSv1
TLSProtocol SSLv3 TLSv1

# We don't require clients to use FTP over TLS
TLSRequired off

# Server's RSA certificate, assume your server certificate file is server-cert.pem
# and the certificate's private key file is server-key.pem
TLSRSACertificateFile /etc/ftpd/server-cert.pem
TLSRSACertificateKeyFile /etc/ftpd/server-key.pem

# CA certificate file of the server, assume server.ca-bundle
TLSCACertificateFile /etc/ftpd/server.ca-bundle

# Do not authenticate clients over TLS
TLSVerifyClient off

# Do not force SSL/TLS renegotiations
TLSRenegotiate none

# Relax the requirement that the SSL session be reused for data transfers
TLSOptions NoSessionReuseRequired

</IfModule>

Which client works with the FTP server over TLS?
FileZilla is one of the most suitable clients. You can use the binary version or build it from source for use in Omarine. I am also using FileZilla.


Configuring the log
This is a supplement to the proftpd configuration in general. We often want to record anonymous activities. You add the following directive to the section <Anonymous ~ ftp>:


ExtendedLog /var/log/ftp.log read, write


Below is an example of the content being logged



Currently unrated

Comments

thue xe 7 cho di chau doc 4 weeks ago

VS

Link | Reply
Currently unrated

thue xe 7 cho da lat gia re 2 weeks ago

I intended to put you one very small note to be able to thank you yet again on the lovely pointers you have provided
on this page. It is so shockingly open-handed with people like you
to grant easily exactly what a number of us would've
offered as an e book in making some bucks for their own end, most importantly given that you could possibly have tried it in case you desired.
The smart ideas also served as a good way to comprehend many people have the same desire like my own to grasp more and more on the subject of this
issue. I believe there are millions of more pleasurable situations in the
future for individuals that read carefully your site.

Link | Reply
Current rating: 5

New Comment

required

required (not published)

optional

required


What is 9 - 8?

required