ftpd deprecated in 15; docs lag

Tftpd is requiered for enabling , amongs others, CISCO switch/router IOS images upload .

Today I use scp /sftp and FIlezilla to port 22 , to transfer files.
 
So you're suggesting to give SSH-access to the guys and gals that currently have FTP-access only? How does that enhance security?
JUST.PUT.IT.BACK.
Pretty please.
 
So you're suggesting is give SSH-access to the guys and gals that currently have FTP-access only? How does that enhance security?
JUST.PUT.IT.BACK.
Pretty please.
You can tune sshd to limit security problems, knowing that it's already secure at the base. You might even forbid ssh session to only have sftp server.

FTP is not the more secure protocol, to say it softly.
 
You can tune sshd to limit security problems, knowing that it's already secure at the base. You might even forbid ssh session to only have sftp server.

FTP is not the more secure protocol, to say it softly.
I know. But it has inetd and it has ftpchroot. I need all of ssh to maintain my server.
Please explain how I can limit the current ftpuser to only use sftp and not run any commands in the directory this wil give him access to.
 
The package description for ftp/freebsd-ftpd says:
Yes. I noticed. The thing is we're not encouraged to mix ports and pkgs and installing from ports requires /usr/src, so it turns out you need a lot of extra files to install it. It's all not as straightforward as it (freebsd) used to be.
Come on, just put it back! It saves someone from updating the docs as well. 👍
 
The package description for ftp/freebsd-ftpd says:
I believe this is what's happened to other things that used to be part of base that got deprecated.
pkg search ftpd shows a bunch of options.

The thing is we're not encouraged to mix ports and pkgs and installing from ports requires /usr/src, so it turns out you need a lot of extra files to install it.
pkg search on a 15.1 system is telling me it finds "freebsd-ftpd-20260512"
That implies to me there is a package being built; are you not installing packages and building ports instead?
 
Nice. I can sense a consensus being reached here over de-deprecating ftpd and cleaning up this mess in the process.
Now who should we call? ☎️
 
So you're suggesting to give SSH-access to the guys and gals that currently have FTP-access only? How does that enhance security?

Please explain how I can limit the current ftpuser to only use sftp and not run any commands in the directory this wil give him access to.

I am far from being an expert but sftp used via a chroot environment seems fine to me.
Once users logged in with the right permissions (read-only if you want) it's safe, nothing but sftp commands which look like a lot to ftp ones.
There is a bit of configuration to make that happen but nothing difficult.

Look at this blog post written by Micski , straight forward and well explained. It's a good blog BTW there is some good FreeBSD stuff to read, thanks to him.

Also if you are still interested by ftp readings then sidetone wrote good threads, hopefully you might find something that helps you.

Good luck and have fun.
 
Good luck and have fun.
This is really helpful. Thanks for your contribution! I'm gonna test all this after asking the sysadmins of the company that is using the FTP-account on my server if they are able to upgrade to sftp and accepting my self-made-cert (the regular hourly ftp-batches are already complicated for them).
It's all windows 365 overthere, zo they're prolly going to say yes, but we all know it's gonna take at least 2 months.

(in the mean time I still prefer for ftpd to return)
 
(in the mean time I still prefer for ftpd to return)

Literally NO ONE is stopping you from installing ftpd?

Here is a link to it: https://www.freshports.org/ftp/freebsd-ftpd/
Download, compile, install and you are all good - go on with your life.

And "NO", by default, we are not going install a file transfer product that can run (unencrypted) over the unprotected INTERNET and compromise peoples files "in transit" to and from a destination host. Really? You think we are all going to do that "anyway" in order to support YOUR one business case verses the health of the entire FreeBSD infrastructure?

If you REALLY need backwards compatibility then use an older FreeBSD release. Version 13 probably does what you want with ftpd?

Don't you think I am not mad that FreeBSD removed uucico(8) from the base system? How am I going to support my uucp(8) and USENET traffic now? I might even have to switch to Linux !
 
It's still available as ftp/freebsd-ftpd. This is mentioned in the posts that gotnull and CShell posted above. It moved from the base system to that.

Sftp isn't ftp, but it's similar in name and basic purpose, but it functions alongside SSH rules, rather than that of ftp. I couldn't figure out how to limit which directories where available for sftp. If you want to learn sftp and ssh, that's an alternative route.
 
Back
Top