Guest User

config

a guest
Jan 29th, 2012
28
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.90 KB | None | 0 0
  1.  
  2. # /etc/proftpd/proftpd.conf -- This is a basic ProFTPD configuration file.
  3. # To really apply changes reload proftpd after modifications.
  4. #
  5.  
  6. # Includes DSO modules
  7. Include /etc/proftpd/modules.conf
  8.  
  9. # Set off to disable IPv6 support which is annoying on IPv4 only boxes.
  10. UseIPv6 off
  11. # If set on you can experience a longer connection delay in many cases.
  12. IdentLookups off
  13.  
  14. ServerName "Darky Land"
  15. ServerType standalone
  16. ServerIdent on "Darky Land"
  17. DeferWelcome off
  18.  
  19. MultilineRFC2228 on
  20. DefaultServer on
  21.  
  22. # on cache les liens symboliques
  23. ShowSymlinks off
  24.  
  25. TimeoutNoTransfer 600
  26. TimeoutStalled 600
  27. TimeoutIdle 1200
  28.  
  29. DisplayLogin welcome.msg
  30. DisplayChdir .message true
  31.  
  32. # On limite le nombre de tentatives de login à 3.
  33. MaxLoginAttempts 3
  34.  
  35. # nombre de connections par client
  36. MaxClientsPerHost 1
  37.  
  38. # nombres de clients max
  39. MaxClients 4
  40.  
  41. # nombres de clients max par utilisateur
  42. MaxClientsPerUser 1
  43. # TRES IMPORTANT : permettra de cacher les fichiers cachés :o)
  44. #ListOptions "-l"
  45. ListOptions "" strict
  46.  
  47. DenyFilter \*.*/
  48.  
  49. # On chroot tous les users dans leur home
  50.  
  51. DefaultRoot /home/servftp
  52.  
  53. # On désactive le login root
  54. RootLogin off
  55.  
  56. # directive qui n'affiche pas les fichiers cachés
  57. <Directory />
  58. HideFiles ^\..*
  59. <Limit ALL>
  60. IgnoreHidden On
  61. </Limit>
  62. </Directory>
  63.  
  64. # Pas de shell pour les users
  65. RequireValidShell off
  66.  
  67. # Port 21 is the standard FTP port.
  68. Port 519
  69.  
  70. # In some cases you have to specify passive ports range to by-pass
  71. # firewall limitations. Ephemeral ports can be used for that, but
  72. # feel free to use a more narrow range.
  73. PassivePorts 53000 54000
  74.  
  75. # If your host was NATted, this option is useful in order to
  76. # allow passive tranfers to work. You have to use your public
  77. # address and opening the passive ports used on your firewall as well.
  78. #MasqueradeAddress www.mondomaine.fr
  79.  
  80. # This is useful for masquerading address with dynamic IPs:
  81. # refresh any configured MasqueradeAddress directives every 8 hours
  82. <IfModule mod_dynmasq.c>
  83. # DynMasqRefresh 28800
  84. </IfModule>
  85.  
  86. # To prevent DoS attacks, set the maximum number of child processes
  87. # to 30. If you need to allow more than 30 concurrent connections
  88. # at once, simply increase this value. Note that this ONLY works
  89. # in standalone mode, in inetd mode you should use an inetd server
  90. # that allows you to limit maximum number of processes per service
  91. # (such as xinetd)
  92. MaxInstances 30
  93.  
  94. # Set the user and group that the server normally runs at.
  95. User proftpd
  96. Group ftpuser
  97.  
  98. # Umask 022 is a good standard umask to prevent new files and dirs
  99. # (second parm) from being group and world writable.
  100. Umask 022 022
  101. # Normally, we want files to be overwriteable.
  102. AllowOverwrite on
  103.  
  104. # Autorise la reprise des téléchargements.
  105. AllowRetrieveRestart on
  106.  
  107. # Autorise les clients à reprendre les Uploads vers vous.
  108. AllowStoreRestart on
  109.  
  110. # Autorise seulement les noms de fichiers normaux (caractères alphanumérique)
  111. PathAllowFilter "[a-zA-Z0-9]"
  112.  
  113. # Refuse l'upload de fichiers .ftpaccess ou .htaccess
  114. PathDenyFilter "(\.ftp)|(\.hta)[a-z]+$"
  115.  
  116. # N'autorise pas de passer des printf-Formats.
  117. AllowFilter "^[a-zA-Z0-9@~ /,_.-]*$"
  118. DenyFilter "%"
  119.  
  120. # Récupère l'ip de la machine de l'utilisateur
  121. IdentLookups on
  122.  
  123. # Uncomment this if you are using NIS or LDAP via NSS to retrieve passwords:
  124. # PersistentPasswd off
  125.  
  126. # This is required to use both PAM-based authentication and local passwords
  127. # AuthOrder mod_auth_pam.c* mod_auth_unix.c
  128.  
  129. # Be warned: use of this directive impacts CPU average load!
  130. # Uncomment this if you like to see progress and transfer rate with ftpwho
  131. # in downloads. That is not needed for uploads rates.
  132. #
  133. # UseSendFile off
  134.  
  135. TransferLog /var/log/proftpd/xferlog
  136. SystemLog /var/log/proftpd/proftpd.log
  137.  
  138. # pour la gestions des users
  139. <IfModule mod_sql.c>
  140. SQLBackend mysql
  141. </IfModule>
  142.  
  143. <IfModule mod_quotatab.c>
  144. QuotaEngine on
  145. </IfModule>
  146.  
  147. <IfModule mod_ratio.c>
  148. Ratios off
  149. </IfModule>
  150.  
  151.  
  152. # Delay engine reduces impact of the so-called Timing Attack described in
  153. # http://security.lss.hr/index.php?page=details&ID=LSS-2004-10-02
  154. # It is on by default.
  155. <IfModule mod_delay.c>
  156. DelayEngine on
  157. </IfModule>
  158.  
  159. <IfModule mod_ctrls.c>
  160. ControlsEngine on
  161. ControlsMaxClients 2
  162. ControlsLog /var/log/proftpd/controls.log
  163. ControlsInterval 5
  164. ControlsSocket /var/run/proftpd/proftpd.sock
  165. </IfModule>
  166.  
  167. <IfModule mod_ctrls_admin.c>
  168. AdminControlsEngine on
  169. </IfModule>
  170.  
  171. #
  172. # Alternative authentication frameworks
  173. #
  174. #Include /etc/proftpd/ldap.conf
  175. #Include /etc/proftpd/sql.conf
  176.  
  177. #
  178. # This is used for FTPS connections
  179. #
  180. Include /etc/proftpd/tls.conf
  181.  
  182. #
  183. # Useful to keep VirtualHost/VirtualRoot directives separated
  184. #
  185. #Include /etc/proftpd/virtuals.conf
  186.  
  187. <IfModule mod_tls.c>
  188. TLSEngine on
  189. TLSLog /var/log/proftpd-tls.log
  190. TLSProtocol tlsv1
  191.  
  192. # Are clients required to use FTP over TLS when talking to this server?
  193. TLSRequired on
  194.  
  195. TLSRSACertificateFile /etc/proftpd/ftpd-rsa.pem
  196. TLSRSACertificateKeyFile /etc/proftpd/ftpd-rsa-key.pem
  197.  
  198. # Authenticate clients that want to use FTP over TLS?
  199. TLSVerifyClient off
  200. </IfModule>
  201.  
  202. AllowRetrieveRestart on
  203. AllowStoreRestart on
  204. TLSOptions NoSessionReuseRequired
Advertisement
Add Comment
Please, Sign In to add comment