AIX

AIX

Connect with fellow AIX users and experts to gain knowledge, share insights, and solve problems.


#Power
 View Only
Expand all | Collapse all

SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

  • 1.  SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Wed April 02, 2025 08:38 AM

    We are SFTP'ing to an AIX (OS 6.1)   server,   it was all running fine, now for some reason all users CAN still login, but can't list or change to any directory at all.

    What is more strange is that users CAN still create and remove directories,   just not see them.

    Eg:

    Connected to aix001
    sftp> pwd
    Remote working directory: /home/fred
    sftp> ls
    remote readdir("/home/fred"): Permission denied
    sftp> cd /tmp
    stat remote: Permission denied
    sftp> ls /tmp
    Can't ls: "/tmp" not found
    sftp> mkdir NEW_DIR               ( It DOES create this directory)
    sftp> ls NEW_DIR
    Can't ls: "/home/fred/NEW_DIR" not found
    sftp> rmdir NEW_DIR              # ( It DOES remove this directory)
    sftp> ls /tmp
    Can't ls: "/tmp" not found
    sftp> mkdir /tmp/NEW            # ( It DOES create this directory)
    sftp> ls /tmp/NEW
    Can't ls: "/tmp/NEW" not found
    sftp> rmdir /tmp/NEW              # (It DOES remove this directory)
    sftp> pwd
    Remote working directory: /home/fred

    Enabled debug, shows no errors. SFTP connections are established without error.

    sshd_config:     Subsystem       sftp    internal-sftp

    We're out of ideas,  there's no errors being returned at the OS level, just the errors in the FTP client.

    Have tried multiple SFTP clients,  they all get same error.

    SSH sessions ,  SCP  sessions,  still both work fine.

    Anyone ever seen anything like this !?!??!



    ------------------------------
    Dirk Bergl
    ------------------------------


  • 2.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Wed April 02, 2025 08:44 AM
    Enable syslog. It's likely a permissions issue in /.

    On Wed, Apr 02, 2025 at 12:37:42PM +0000, Dirk Bergl via IBM TechXchange Community wrote:
    > We are SFTP'ing to an AIX (OS 6.1) server, it was all running fine, now for some reason all users CAN still login, but can't list or change to any directory at all.
    >
    >
    > What is more strange is that users CAN still create and remove directories, just not see them.
    >
    >
    > Eg:
    >
    >
    > Connected to aix001
    > sftp> pwd
    > Remote working directory: /home/fred
    > sftp> ls
    > remote readdir("/home/fred"): Permission denied
    > sftp> cd /tmp
    > stat remote: Permission denied
    > sftp> ls /tmp
    > Can't ls: "/tmp" not found
    > sftp> mkdir NEW_DIR ( It DOES create this directory)
    > sftp> ls NEW_DIR
    > Can't ls: "/home/fred/NEW_DIR" not found
    > sftp> rmdir NEW_DIR # ( It DOES remove this directory)
    > sftp> ls /tmp
    > Can't ls: "/tmp" not found
    > sftp> mkdir /tmp/NEW # ( It DOES create this directory)
    > sftp> ls /tmp/NEW
    > Can't ls: "/tmp/NEW" not found
    > sftp> rmdir /tmp/NEW # (It DOES remove this directory)
    > sftp> pwd
    > Remote working directory: /home/fred
    >
    >
    >
    >
    >
    > Enabled debug, shows no errors. SFTP connections are established without error.
    >
    >
    > sshd_config: Subsystem sftp internal-sftp
    >
    >
    >
    >
    >
    > We're out of ideas, there's no errors being returned at the OS level, just the errors in the FTP client.
    >
    >
    > Have tried multiple SFTP clients, they all get same error.
    >
    >
    >
    >
    >
    > SSH sessions , SCP sessions, still both work fine.
    >
    >
    >
    >
    >
    > Anyone ever seen anything like this !?!??!
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    > ------------------------------
    > Dirk Bergl
    > ------------------------------
    >
    >
    > Reply to Sender : https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6049&MID=799031&SenderKey=2ac20846-1a47-4b53-8e13-0195f4815982
    >
    > Reply to Discussion : https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6049&MID=799031
    >
    >
    >
    > You are subscribed to "AIX" as Russell.Adams@AdamsSystems.nl. To change your subscriptions, go to http://community.ibm.com/community/user/preferences?section=Subscriptions. To unsubscribe from this community discussion, go to https://community.ibm.com/HigherLogic/eGroups/Unsubscribe.aspx?UserKey=c23dfccc-9910-40ae-beeb-fdcbced5bf1f&sKey=KeyRemoved&GroupKey=7b554d78-d4dc-417a-b4dc-017e309e5c91.


    ------------------------------------------------------------------
    Russell Adams Russell.Adams@AdamsSystems.nl
    Principal Consultant Adams Systems Consultancy
    https://adamssystems.nl/




  • 3.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Wed April 02, 2025 09:28 AM

    Thanks Russell,

    Did check  syslog,  but nothing popped up..    Have enabled:

    *.debug

    *.warn

    *.crit

    *auth.notice

    Only one we havn'et done is daemon.notice 

    It logs the SFTP user getting authentication, but not much  else - no obvious errors.

     



    ------------------------------
    Dirk Bergl
    ------------------------------



  • 4.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Wed April 02, 2025 09:40 AM
    Start another sshd on a different port with verbose debugging enabled,
    and try to send a file. It's got to be a / permissions issue.

    /usr/sbin/sshd -D -d -f /etc/ssh/sshd_config -p 2022

    Try to sftp on port 2022 and watch the output.

    On Wed, Apr 02, 2025 at 01:28:18PM +0000, Dirk Bergl via IBM TechXchange Community wrote:
    > Thanks Russell,
    >
    >
    > Did check syslog, but nothing popped up.. Have enabled:
    >
    >
    > *.debug
    >
    >
    > *.warn
    >
    >
    > *.crit
    >
    >
    > *auth.notice
    >
    >
    > Only one we havn'et done is daemon.notice
    >
    >
    >
    >
    >
    > It logs the SFTP user getting authentication, but not much else - no obvious errors.
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    > ------------------------------
    > Dirk Bergl
    > ------------------------------
    > -------------------------------------------
    > Original Message:
    > Sent: Wed April 02, 2025 08:44 AM
    > From: Russell Adams
    > Subject: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users
    >
    > Enable syslog. It's likely a permissions issue in /.
    >
    > On Wed, Apr 02, 2025 at 12:37:42PM +0000, Dirk Bergl via IBM TechXchange Community wrote:
    > > We are SFTP'ing to an AIX (OS 6.1) server, it was all running fine, now for some reason all users CAN still login, but can't list or change to any directory at all.
    > >
    > >
    > > What is more strange is that users CAN still create and remove directories, just not see them.
    > >
    > >
    > > Eg:
    > >
    > >
    > > Connected to aix001
    > > sftp> pwd
    > > Remote working directory: /home/fred
    > > sftp> ls
    > > remote readdir("/home/fred"): Permission denied
    > > sftp> cd /tmp
    > > stat remote: Permission denied
    > > sftp> ls /tmp
    > > Can't ls: "/tmp" not found
    > > sftp> mkdir NEW_DIR ( It DOES create this directory)
    > > sftp> ls NEW_DIR
    > > Can't ls: "/home/fred/NEW_DIR" not found
    > > sftp> rmdir NEW_DIR # ( It DOES remove this directory)
    > > sftp> ls /tmp
    > > Can't ls: "/tmp" not found
    > > sftp> mkdir /tmp/NEW # ( It DOES create this directory)
    > > sftp> ls /tmp/NEW
    > > Can't ls: "/tmp/NEW" not found
    > > sftp> rmdir /tmp/NEW # (It DOES remove this directory)
    > > sftp> pwd
    > > Remote working directory: /home/fred
    > >
    > >
    > >
    > >
    > >
    > > Enabled debug, shows no errors. SFTP connections are established without error.
    > >
    > >
    > > sshd_config: Subsystem sftp internal-sftp
    > >
    > >
    > >
    > >
    > >
    > > We're out of ideas, there's no errors being returned at the OS level, just the errors in the FTP client.
    > >
    > >
    > > Have tried multiple SFTP clients, they all get same error.
    > >
    > >
    > >
    > >
    > >
    > > SSH sessions , SCP sessions, still both work fine.
    > >
    > >
    > >
    > >
    > >
    > > Anyone ever seen anything like this !?!??!
    > >
    > >
    > >
    > >
    > >
    > >
    > >
    > >
    > >
    > >
    > >
    > > ------------------------------
    > > Dirk Bergl
    > > ------------------------------
    > >
    > >
    > > Reply to Sender : https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6049&MID=799031&SenderKey=2ac20846-1a47-4b53-8e13-0195f4815982 <https: community.ibm.com community user egroups postreply?groupid=6049&MID=799031&SenderKey=2ac20846-1a47-4b53-8e13-0195f4815982>
    > >
    > > Reply to Discussion : https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6049&MID=799031 <https: community.ibm.com community user egroups postreply?groupid=6049&MID=799031>
    > >
    > >
    > >
    > > You are subscribed to "AIX" as Russell.Adams@AdamsSystems.nl <russell.adams@adamssystems.nl>. To change your subscriptions, go to http://community.ibm.com/community/user/preferences?section=Subscriptions. <http: community.ibm.com community user preferences?section=Subscriptions.> To unsubscribe from this community discussion, go to https://community.ibm.com/HigherLogic/eGroups/Unsubscribe.aspx?UserKey=c23dfccc-9910-40ae-beeb-fdcbced5bf1f&sKey=KeyRemoved&GroupKey=7b554d78-d4dc-417a-b4dc-017e309e5c91. <https: community.ibm.com higherlogic egroups unsubscribe.aspx?userkey=c23dfccc-9910-40ae-beeb-fdcbced5bf1f&sKey=KeyRemoved&GroupKey=7b554d78-d4dc-417a-b4dc-017e309e5c91.>
    >
    >
    > ------------------------------------------------------------------
    > Russell Adams Russell.Adams@AdamsSystems.nl <russell.adams@adamssystems.nl>
    > Principal Consultant Adams Systems Consultancy
    > https://adamssystems.nl/ <https: adamssystems.nl>
    >
    >
    > Original Message:
    > Sent: 4/2/2025 12:21:00 AM
    > From: Dirk Bergl
    > Subject: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users
    >
    >
    > We are SFTP'ing to an AIX (OS 6.1) server, it was all running fine, now for some reason all users CAN still login, but can't list or change to any directory at all.
    >
    > What is more strange is that users CAN still create and remove directories, just not see them.
    >
    > Eg:
    >
    > Connected to aix001
    > sftp> pwd
    > Remote working directory: /home/fred
    > sftp> ls
    > remote readdir("/home/fred"): Permission denied
    > sftp> cd /tmp
    > stat remote: Permission denied
    > sftp> ls /tmp
    > Can't ls: "/tmp" not found
    > sftp> mkdir NEW_DIR ( It DOES create this directory)
    > sftp> ls NEW_DIR
    > Can't ls: "/home/fred/NEW_DIR" not found
    > sftp> rmdir NEW_DIR # ( It DOES remove this directory)
    > sftp> ls /tmp
    > Can't ls: "/tmp" not found
    > sftp> mkdir /tmp/NEW # ( It DOES create this directory)
    > sftp> ls /tmp/NEW
    > Can't ls: "/tmp/NEW" not found
    > sftp> rmdir /tmp/NEW # (It DOES remove this directory)
    > sftp> pwd
    > Remote working directory: /home/fred
    >
    >
    >
    > Enabled debug, shows no errors. SFTP connections are established without error.
    >
    > sshd_config: Subsystem sftp internal-sftp
    >
    >
    >
    > We're out of ideas, there's no errors being returned at the OS level, just the errors in the FTP client.
    >
    > Have tried multiple SFTP clients, they all get same error.
    >
    >
    >
    > SSH sessions , SCP sessions, still both work fine.
    >
    >
    >
    > Anyone ever seen anything like this !?!??!
    >
    >
    >
    >
    >
    >
    >
    >
    > ------------------------------
    > Dirk Bergl
    > ------------------------------
    >
    >
    > Reply to Sender : https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6049&MID=799066&SenderKey=2ac20846-1a47-4b53-8e13-0195f4815982
    >
    > Reply to Discussion : https://community.ibm.com/community/user/eGroups/PostReply?GroupId=6049&MID=799066
    >
    >
    >
    > You are subscribed to "AIX" as Russell.Adams@AdamsSystems.nl. To change your subscriptions, go to http://community.ibm.com/community/user/preferences?section=Subscriptions. To unsubscribe from this community discussion, go to https://community.ibm.com/HigherLogic/eGroups/Unsubscribe.aspx?UserKey=c23dfccc-9910-40ae-beeb-fdcbced5bf1f&sKey=KeyRemoved&GroupKey=7b554d78-d4dc-417a-b4dc-017e309e5c91.


    ------------------------------------------------------------------
    Russell Adams Russell.Adams@AdamsSystems.nl
    Principal Consultant Adams Systems Consultancy
    https://adamssystems.nl/




  • 5.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Wed April 02, 2025 08:45 PM

    Ran on a new port, even in -ddd debug mode...

    Nothing exciting popped up, except the session authentification info...

    Only remote warnings were:

    debug1: Failed to collect Cookie from Keystore
    debug1: Keystore Opening wil be failed after login
    However it does initially appear able to read data:
    debug1: matching key found: file /home/fred/.ssh/authorized_keys
    Will try looking around /  for permission issues..  SO far nothing stands out but will have another look.
    Oddly it happens on TWO servers, both logs return no warnings./errors that stand out.
    Thanks Russell


    ------------------------------
    Dirk Bergl
    ------------------------------



  • 6.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Thu April 03, 2025 10:05 PM

    Even tried switching to sftp-server,

    But same result -  Permission Denied everywhere,  no warnings or errors in logs. 



    ------------------------------
    Dirk Bergl
    ------------------------------



  • 7.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Fri April 04, 2025 01:28 AM

    Hi,

    Not sure if this is the case here, but noticed once something similar when your /etc/ssh/sshd_config did not have read permission for group +others... (eg CIS recommendation for /etc/ssh/sshd_config permissions is 600, but when U set that >> ssh works, but sftp not...after switching to 644 >> also sftp started working) 

    Br,

    tommi



    ------------------------------
    Tommi Sihvo, Lead Service Architect
    Tietoevry Tech Services
    email tommi.sihvo@tietoevry.com mobile +358 (0)40 5180 Finland
    ------------------------------



  • 8.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Fri April 04, 2025 02:37 AM

    Yep good call,

    We read that somewhere too,  checked and we're 644 so all good.

    Although almost worth playing with this and seeing if changing it does nay good.

    Cheers.

     



    ------------------------------
    Dirk Bergl
    ------------------------------



  • 9.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Fri April 04, 2025 03:18 AM

    Damn ;)

    Another call would be checking your /etc/ssh/sshd_config, if there are some denials etc which would prevent using sftp somehow (for certain users / groups etc) ...

    Br,

    tommi



    ------------------------------
    Tommi Sihvo, Lead Service Architect
    Tietoevry Tech Services
    email tommi.sihvo@tietoevry.com mobile +358 (0)40 5180 Finland
    ------------------------------



  • 10.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Mon April 07, 2025 01:27 AM

    Yup,   went and checked the sshd_config, even reverted to older settings,   but nothing in there that stands out.

    Even tried flipping between  sftp-server and internal-sftp,   they both get the same error.

    What's really odd is you CAN  create and remove directories .

    mkdir NEWDIR   works  (Dir created in /home/user/NEWDIR

    cd NEWDIR  -  Error - Permission denied

    rmdir NEWDIR  - Works


    So bizarre !



    ------------------------------
    Dirk Bergl
    ------------------------------



  • 11.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Mon April 07, 2025 01:36 AM

    This is now a loooooong shot, but is it a mounted filesystem which U R trying to cd to?

    If yes, then one option is that even though the FS permissions look OK, there might be underlying mount point directory permissions which prevent the cd (have seen that behaviour couple of times)

    If that is a filesystem, try unmount on it and checking the mounpoint directory permissions after amount..

    Br,

    tommi



    ------------------------------
    Tommi Sihvo, Lead Service Architect
    Tietoevry Tech Services
    email tommi.sihvo@tietoevry.com mobile +358 (0)40 5180 Finland
    ------------------------------



  • 12.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Mon April 07, 2025 01:45 AM

    Hey not a bad idea...   It makes sense.   Directories are /tmp and /home,   but have tried all other mount points, even 
    cd /

    mkdir /TEST

    chmod 777 /TEST

    However, might try /home and review the permissions,  once the users are off of course :)



    ------------------------------
    Dirk Bergl
    ------------------------------



  • 13.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Mon April 07, 2025 01:55 AM

    + U could try to debug the error messages;

    #Create debug log file :

    touch  /var/log/messages
    # add following line to  /etc/syslog.conf 
    *.debug /var/log/messages

    #restart syslogd 
    stopsrc -s syslogd; startsrc -s syslogd

    Then retry your sftp, should give some more info in log file

    After trial, revert the config changes 



    ------------------------------
    Tommi Sihvo, Lead Service Architect
    Tietoevry Tech Services
    email tommi.sihvo@tietoevry.com mobile +358 (0)40 5180 Finland
    ------------------------------



  • 14.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Wed April 09, 2025 08:16 PM

    Yep had debug on for syslog file but also modified for messages..
    Even ran in debug3 mode... 

    Strangely it output's nothing !  

    SFTP Client shows "Permission denied"   yet the log files ... zzzzz   nothing displays.

    It's like the server just can't see anything wrong ?!!?!



    ------------------------------
    Dirk Bergl
    ------------------------------



  • 15.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Mon April 07, 2025 04:54 AM

    Hi,

    You don't need to umount /home to check the mountpoint or change the permissions:

    # mount / /mnt
    # ls -ald /mnt/home
    drwxrwxr-x    2 root     system          256 Sep 10 2024  /mnt/home

    If it's not root.system 755/775, you can chown/chmod /mnt/home



    ------------------------------
    José Pina Coelho
    IT Specialist at Kyndryl
    ------------------------------



  • 16.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Fri April 04, 2025 08:53 AM

    Hi Dirk, 


    Perhaps a CHROOT environment is at play ? (not sure how to check on AIX but on IBM i we have this  specific "path" that shows outside when you login on 5250). 

    Perhaps someone also enabled outside security software that SSH is unaware off? (PowerSC comes to mind, blocking access or edits on other folders / files). 
    (check perhaps the install programs on the box to see if something is there that updated recently?) 

    HTH



    ------------------------------
    Marius le Roux theIBMiGuy
    Owner , IBM i Consultant & Technology Strategist
    MLR Consulting
    Port Alfred
    ------------------------------



  • 17.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Mon April 07, 2025 01:43 AM

    Yep checked CHROOT - and also looked for newly installed programs,  plus checked for ANY config file changes anywhere within the last 2-3 weeks.. Nothing !
    But might go and review again any blocks on dirs.



    ------------------------------
    Dirk Bergl
    ------------------------------



  • 18.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Tue April 08, 2025 04:26 AM

    Have you checked the permissions/ownership of the unlaying mount point?  ie: umount the filesystem and check the permissions/ownership of where it is mounted.  The permissions of the mount point and the filesystem should match, weird things can happen if they don't.

    Phill.



    ------------------------------
    Phill Rowbottom
    Unix Consultant
    Service Express
    Bedford
    ------------------------------



  • 19.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Wed April 09, 2025 07:58 PM

    Checked the mount points..

    777 on /home and  /tmp

     



    ------------------------------
    Dirk Bergl
    ------------------------------



  • 20.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Thu April 10, 2025 01:20 AM

    Apologies, I should have been clearer...

    Checked underlying mount points,  mounted / on /mnt

    777 on both home and tmp



    ------------------------------
    Dirk Bergl
    ------------------------------



  • 21.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Thu April 10, 2025 01:33 AM

    One more stupid Q...Both are plain local filesystems, not NFS mounted or anything from some other AIX etc server?



    ------------------------------
    Tommi Sihvo, Lead Service Architect
    Tietoevry Tech Services
    email tommi.sihvo@tietoevry.com mobile +358 (0)40 5180 Finland
    ------------------------------



  • 22.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Thu April 10, 2025 11:10 PM

    Yeah all plain local filesystems.. /home/  and /tmp

    Even tried   mkdir /TEST   and chmod 777 

    User CAN access this when ssh into server,  but when using SFTP  ,  even /TEST is "access denied"

     



    ------------------------------
    Dirk Bergl
    ------------------------------



  • 23.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Fri April 11, 2025 06:43 AM

    well, that is pretty wide open.



    ------------------------------
    Phill Rowbottom
    Unix Consultant
    Service Express
    Bedford
    ------------------------------



  • 24.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Thu April 10, 2025 03:47 AM
    Edited by Anwar Williams Thu April 10, 2025 05:19 AM

    Hey Dirk

    What sftp client are you using to connect? Filezilla client offers nice verbose/debug logging.

    I have tried to simulate your setup but obviously do not have ALL your config, however, here are my results.

    My subsystem is as follows:

    Subsystem sftp  /usr/sbin/sftp-server

    I sftp with verbose option to my AIX box from a terminal emulater but Filezilla would also be possible i just didnt test that. (NB:output truncated)

    sftp -v fred@x.x.x.x
    OpenSSH_7.5p1, OpenSSL 1.0.2r  26 Feb 2019
    debug1: Reading configuration data /etc/ssh_config
    debug1: Connecting to x.x.x.x port xxxx.
    debug1: Connection established.
    debug1: Sending subsystem: sftp
    Connected to x.x.x.x.
    sftp>

    sftp> pwd
    Remote working directory: /home/fred
    sftp> ls
    sftp> ls -la
    drwxr-xr-x    2 fred     staff         256 Apr 10 09:01 .
    drwxr-xr-x   14 bin      bin          4096 Apr 10 09:01 ..
    -rwxr-----    1 fred     staff         254 Apr 10 09:01 .profile
    sftp> cd /tmp
    sftp> pwd
    Remote working directory: /tmp
    sftp> ls /tmp
    /tmp/_FLRT_20250402082944035-emgr.txt                 /tmp/_FLRT_20250402082944035-lslpp.txt
    /tmp/_FLRT_20250409083013575-emgr.txt                 /tmp/_FLRT_20250409083013575-lslpp.txt
    /tmp/NULL                                                                /tmp/VMRUIdownload
    /tmp/cache_mgt.lock                                                      /tmp/cfgvg.out
    /tmp/croutXUwDfV                                                         /tmp/ctrmc_MDdr.dbg
    /tmp/deleted_ksyscluster_logs                                            /tmp/diagSEgenSnap
    /tmp/dnf_aixtoolbox.nim.sh                                               /tmp/dpi_socket
    /tmp/errmbatch                                                           /tmp/etc_daemon.lock
    /tmp/ksys.log                                                            /tmp/ksys_create.txt
    /tmp/ksys_create2.txt                                                    /tmp/ksysmgr.log
    /tmp/ksysmgr.tmp                                                         /tmp/ksysmgr.tmp.-U9qea
    /tmp/ksysmgr.tmp.0I27ea                                                  /tmp/ksysmgr.tmp.JYOMea
    /tmp/ksysmgr.tmp.LYY7ea                                                  /tmp/ksysmgr.tmp.Srpaea
    /tmp/ksysmgr.tmp.WYQMea                                                  /tmp/ksysmgr.tmp.ZUv7ea
    /tmp/ksysmgr.tmp.fME7ea                                                  /tmp/ksysmgr.tmp.jQS7ea
    /tmp/ksysmgr.tmp.or77ea                                                  /tmp/ksysmgr.tmp.xnJMea
    /tmp/lost+found                                                          /tmp/lpar2rrd-agent-7.30-2.ppc.rpm
    /tmp/lpar2rrd-agent-7.60-5.ppc.rpm                                       /tmp/lvmt.log
    /tmp/nodedeps_7.2.tar.gz                                                 /tmp/pcmsrv.out
    /tmp/pfcdaemon.out                                                       /tmp/pmcfg.out
    /tmp/rc.net.out                                                          /tmp/rc.net.serial.out
    /tmp/relSDDPCMbootrsv.out                                                /tmp/rmwparpcmsrv_02-02-2024.out
    /tmp/rmwparpcmsrv_02-04-2020.out                                         /tmp/rmwparpcmsrv_02-06-2020.out
    /tmp/rmwparpcmsrv_02-07-2020.out                                         /tmp/rmwparpcmsrv_04-18-2023.out
    /tmp/rmwparpcmsrv_05-29-2020.out                                         /tmp/rmwparpcmsrv_06-25-2023.out
    /tmp/rmwparpcmsrv_07-17-2020.out                                         /tmp/rmwparpcmsrv_10-17-2019.out
    /tmp/rmwparpcmsrv_10-23-2019.out                                         /tmp/rmwparpcmsrv_10-27-2021.out
    /tmp/rmwparpcmsrv_10-29-2019.out                                         /tmp/rpm_instcpio-2.11-2.log

    1. As you can see everything is working, however, I am not sure of you have a CHROOT'ed environment. Please confirm?
    2. I am using password authentication for user=fred and not ssh_keys. Please confirm you are doing the same?
    3. You can also share your sftp config/sshd_config for proper simulation.

    Hope any of this helps, happy to look into more depth with you. 

    Regards

    Anwar




  • 25.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Thu April 10, 2025 08:26 AM
    Edited by Carl Burnett Fri April 11, 2025 09:19 AM



    ------------------------------
    RUii PEng
    ------------------------------



  • 26.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Thu April 10, 2025 09:55 AM

    I assume it to be a openssh bug, is it possible for you to update openssh to latest possible version ? 



    ------------------------------
    Digvijay Singh
    ------------------------------



  • 27.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Thu April 10, 2025 11:05 PM

    It might be, however we have a production server with the same version and it is working OK.

    However valid point, will suggest an update.



    ------------------------------
    Dirk Bergl
    ------------------------------



  • 28.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Fri April 11, 2025 01:11 AM

    OK, Solved:  But still odd.

    So this was missed in SFTP_CONFIG (apologies)... I have limited access.

    AllowFiles "user1:/apps/test/home/data/uploads/*"

    I commented OUT the line, restarted the service ... ALL users can SFTP freely.

    But...

    On the other (working) server it has  a similar entry, 

    AllowFiles "user2:/apps/test/home/data/uploads/*" 

    However on this server all other users CAN still login and move about.

    The intention was obviously to limit "user1"  to a fixed directory at some point but whoever put it in has limited everyone.

    But I dont get how on the other (working) server, this comment is active, yet everyone can still login ?! 



    ------------------------------
    Dirk B
    ------------------------------



  • 29.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Fri April 11, 2025 02:54 AM
    Edited by Anwar Williams Fri April 11, 2025 02:56 AM

    Hi Dirk

    Glad you got it working.

    We got around this using the Match clause in sshd_config.

    First we tried with Match group but then it affects ALL users of that group but perhaps this will work for your two users (i.e. user1 & user2) since they are restricted to the same folder.

    Otherwise we used individual Match user username clause for each user.

    NB: We did find that sshd evaluates these Match blocks in the order they appear in the file so check this carefully. The first one that is a match is actually applied. (This was one that kept us up for many nights :-))

    You then add the chrootdirectory and the forcecommand into the Match block as in the simple example below.

    Your config may look different and since it is not in your best interest to share it I apologise that this may not be a complete solution but may hopefully nudge you closer in the right direction.

    Match Group groupname(%u will jail any user part of this group matched)

       ChrootDirectory /your_path/%u

       ForceCommand internal-sftp

       X11Forwarding no

       AllowTcpForwarding no

    OR

    Match Group username(%u will jail any user matched)

       ChrootDirectory /your_path/%u

       ForceCommand internal-sftp

       X11Forwarding no

       AllowTcpForwarding no

    Hope this helps somewhat, it is difficult without seeing you config.



    ------------------------------
    Anwar Williams
    ------------------------------



  • 30.  RE: SFTP to AIX: AIX Server returns "Permission Denied" for all directories and all users

    Posted Fri April 11, 2025 03:07 AM

    Thanks Anwar, 

    Thanks for those tips ... I will look at this Monday.
    Yeah bit hard to share some of the config for obvious reasons.

    But agree there's going to be some edit/save/restart  iterations as we try get the best match.

    Which is our case is meant to be "Allow everyone , but for userX / userY - In this case allow, but lock the directory."

    Thanks again for the above notes and template.   




    ------------------------------
    Dirk B
    ------------------------------