chroot sftp

Add group sftponly

edit sshd config

# override default of no subsystems
#Subsystem sftp /usr/libexec/openssh/sftp-server
Subsystem sftp internal-sftp

Match Group sftponly
ChrootDirectory /home/%u
X11Forwarding no
AllowTCPForwarding no
ForceCommand internal-sftp

chown root FOLDER for the home directory (and every directory to /)

ssh won’t work, but sftp will work all users in sftponly group.


