Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # /etc/proftpd/proftpd.conf -- This is a basic ProFTPD configuration file.
- # To really apply changes reload proftpd after modifications.
- #
- # Includes DSO modules
- Include /etc/proftpd/modules.conf
- # Set off to disable IPv6 support which is annoying on IPv4 only boxes.
- UseIPv6 off
- # If set on you can experience a longer connection delay in many cases.
- IdentLookups off
- ServerName "Darky Land"
- ServerType standalone
- ServerIdent on "Darky Land"
- DeferWelcome off
- MultilineRFC2228 on
- DefaultServer on
- # on cache les liens symboliques
- ShowSymlinks off
- TimeoutNoTransfer 600
- TimeoutStalled 600
- TimeoutIdle 1200
- DisplayLogin welcome.msg
- DisplayChdir .message true
- # On limite le nombre de tentatives de login à 3.
- MaxLoginAttempts 3
- # nombre de connections par client
- MaxClientsPerHost 1
- # nombres de clients max
- MaxClients 4
- # nombres de clients max par utilisateur
- MaxClientsPerUser 1
- # TRES IMPORTANT : permettra de cacher les fichiers cachés :o)
- #ListOptions "-l"
- ListOptions "" strict
- DenyFilter \*.*/
- # On chroot tous les users dans leur home
- DefaultRoot /home/servftp
- # On désactive le login root
- RootLogin off
- # directive qui n'affiche pas les fichiers cachés
- <Directory />
- HideFiles ^\..*
- <Limit ALL>
- IgnoreHidden On
- </Limit>
- </Directory>
- # Pas de shell pour les users
- RequireValidShell off
- # Port 21 is the standard FTP port.
- Port 519
- # In some cases you have to specify passive ports range to by-pass
- # firewall limitations. Ephemeral ports can be used for that, but
- # feel free to use a more narrow range.
- PassivePorts 53000 54000
- # If your host was NATted, this option is useful in order to
- # allow passive tranfers to work. You have to use your public
- # address and opening the passive ports used on your firewall as well.
- #MasqueradeAddress www.mondomaine.fr
- # This is useful for masquerading address with dynamic IPs:
- # refresh any configured MasqueradeAddress directives every 8 hours
- <IfModule mod_dynmasq.c>
- # DynMasqRefresh 28800
- </IfModule>
- # To prevent DoS attacks, set the maximum number of child processes
- # to 30. If you need to allow more than 30 concurrent connections
- # at once, simply increase this value. Note that this ONLY works
- # in standalone mode, in inetd mode you should use an inetd server
- # that allows you to limit maximum number of processes per service
- # (such as xinetd)
- MaxInstances 30
- # Set the user and group that the server normally runs at.
- User proftpd
- Group ftpuser
- # Umask 022 is a good standard umask to prevent new files and dirs
- # (second parm) from being group and world writable.
- Umask 022 022
- # Normally, we want files to be overwriteable.
- AllowOverwrite on
- # Autorise la reprise des téléchargements.
- AllowRetrieveRestart on
- # Autorise les clients à reprendre les Uploads vers vous.
- AllowStoreRestart on
- # Autorise seulement les noms de fichiers normaux (caractères alphanumérique)
- PathAllowFilter "[a-zA-Z0-9]"
- # Refuse l'upload de fichiers .ftpaccess ou .htaccess
- PathDenyFilter "(\.ftp)|(\.hta)[a-z]+$"
- # N'autorise pas de passer des printf-Formats.
- AllowFilter "^[a-zA-Z0-9@~ /,_.-]*$"
- DenyFilter "%"
- # Récupère l'ip de la machine de l'utilisateur
- IdentLookups on
- # Uncomment this if you are using NIS or LDAP via NSS to retrieve passwords:
- # PersistentPasswd off
- # This is required to use both PAM-based authentication and local passwords
- # AuthOrder mod_auth_pam.c* mod_auth_unix.c
- # Be warned: use of this directive impacts CPU average load!
- # Uncomment this if you like to see progress and transfer rate with ftpwho
- # in downloads. That is not needed for uploads rates.
- #
- # UseSendFile off
- TransferLog /var/log/proftpd/xferlog
- SystemLog /var/log/proftpd/proftpd.log
- # pour la gestions des users
- <IfModule mod_sql.c>
- SQLBackend mysql
- </IfModule>
- <IfModule mod_quotatab.c>
- QuotaEngine on
- </IfModule>
- <IfModule mod_ratio.c>
- Ratios off
- </IfModule>
- # Delay engine reduces impact of the so-called Timing Attack described in
- # http://security.lss.hr/index.php?page=details&ID=LSS-2004-10-02
- # It is on by default.
- <IfModule mod_delay.c>
- DelayEngine on
- </IfModule>
- <IfModule mod_ctrls.c>
- ControlsEngine on
- ControlsMaxClients 2
- ControlsLog /var/log/proftpd/controls.log
- ControlsInterval 5
- ControlsSocket /var/run/proftpd/proftpd.sock
- </IfModule>
- <IfModule mod_ctrls_admin.c>
- AdminControlsEngine on
- </IfModule>
- #
- # Alternative authentication frameworks
- #
- #Include /etc/proftpd/ldap.conf
- #Include /etc/proftpd/sql.conf
- #
- # This is used for FTPS connections
- #
- Include /etc/proftpd/tls.conf
- #
- # Useful to keep VirtualHost/VirtualRoot directives separated
- #
- #Include /etc/proftpd/virtuals.conf
- <IfModule mod_tls.c>
- TLSEngine on
- TLSLog /var/log/proftpd-tls.log
- TLSProtocol tlsv1
- # Are clients required to use FTP over TLS when talking to this server?
- TLSRequired on
- TLSRSACertificateFile /etc/proftpd/ftpd-rsa.pem
- TLSRSACertificateKeyFile /etc/proftpd/ftpd-rsa-key.pem
- # Authenticate clients that want to use FTP over TLS?
- TLSVerifyClient off
- </IfModule>
- AllowRetrieveRestart on
- AllowStoreRestart on
- TLSOptions NoSessionReuseRequired
Advertisement
Add Comment
Please, Sign In to add comment