ProFTP is a configurable FTP server available on most *nix platforms.
I recently had the need to get this working and authenticating off a PHP maintained MySQL backend, and this post is primarily to aid my own memory should I ever have to do it again.
apt-get install mysql-server proftpd proftpd-mod-mysql
The database schema
Next, you need to install the database schema to store your users and passwords.
CREATE TABLE IF NOT EXISTS users (
userid varchar(30) NOT NULL default '',
passwd varchar(128) NOT NULL default '',
uid int(11) default NULL,
gid int(11) default NULL,
homedir varchar(255) default NULL,
shell varchar(255) default NULL,
UNIQUE KEY uid (uid),
UNIQUE KEY userid (userid)
CREATE TABLE IF NOT EXISTS groups (
groupname varchar(30) NOT NULL default '',
gid int(11) NOT NULL default '0',
members varchar(255) default NULL
One important thing to note here – that caused me a fair amount of hair pulling when I tried to use encrypted passwords – is that the password field shown in many howtos on the internet is much too short. This causes the hashed password to be quietly truncated by MySQL when saved.
This results in a somewhat misleading “No such user found” error to appear in the logs when using encrypted passwords.
To end all argument I’ve allowed passwords up to 128 chars, but this field could probably be a good deal shorter.
The user table looks much like /etc/passwd and is largely self explanatory. The uid & gid fields correspond to a system user in most cases, but since we’re using virtual users they can largely be ignored. Homedir points to a location which will serve as the user’s default directory. Shell is largely unused and can be set to /bin/false or similar.
Next, you need to make some changes to the ProFTP configuration files stored in /etc/proftpd. While doing this it is handy to run proftp in debug mode from the console:
- Make sure the AuthOrder line looks like:
- Ensure that the following line is uncommented:
- For belts and braces I’ve included the following at the end, although I’m not entirely sure it’s strictly required:
- Our users don’t need a valid shell, so:
- Make sure the following lines are uncommented:
- Set your SQL backend and ensure that authentication is turned on:
- Tell proftp how passwords are stored. You have a number of options here, but since I was using mysql’s PASSWORD function, I’ll defer to the backend.
- Tell proftp how to connect to your database by providing the required connection details, ensure that the user has full access to these tables.
SQLConnectInfo database@host user password
- Define your table structure in the format tablename fields….
SQLUserInfo users userid passwd uid gid homedir shell
SQLGroupInfo groups groupname gid members
I manage users from within a PHP web application that I’m developing, but in a nutshell adding FTP users from this point is a simple insert statement looking something like:
mysql_query("REPLACE INTO users
(userid, passwd, uid, gid, homedir, shell)
('$userid', PASSWORD('$password'), $uid, $gid, '$homedir', '$shell')");