{"id":277,"date":"2012-05-29T20:29:42","date_gmt":"2012-05-30T00:29:42","guid":{"rendered":"http:\/\/bitc.bme.emory.edu\/~lzhou\/blogs\/?p=277"},"modified":"2012-05-29T20:32:21","modified_gmt":"2012-05-30T00:32:21","slug":"simple-guide-for-executable-chroot-jail","status":"publish","type":"post","link":"https:\/\/csic.som.emory.edu\/~lzhou\/blogs\/?p=277","title":{"rendered":"Simple guide for executable chroot jail"},"content":{"rendered":"<p>1. Install Jailkit, CentOS rpm available in rpmforge repo.<br \/>\n2. mkdir -p  # to define your jail root<br \/>\n3. jk_init -v -j  ssh # to allow ssh in your jail<br \/>\n4. jk_jailuser -j   # to move the user into the jail<br \/>\n5. Edit \/etc\/jailkit\/jk_init.ini and \/etc\/jailkit\/jk_socketd.ini # to match your system<br \/>\n6. jk_cp -v -f  \/bin\/bash  # to allow users to login bash in the jail<br \/>\n7. repeat 6 on other commands you want the user to run<br \/>\n8. mkdir -p \/proc; mkdir -p \/dev<br \/>\n9. edit \/etc\/init.d\/jailkit to mount \/proc \/dev \/dev\/pts<br \/>\n10. mkdir -p \/var\/lib\/rpm<br \/>\n11. rpm &#8211;rebuilddb &#8211;root= # this enable you to install packages in the jail<br \/>\n12. yum &#8211;installroot= install redhat-release-server-6Server # to define your repo<br \/>\n13. yum &#8211;installroot= install -y rpm-build yum # to make yum available inside your jail<br \/>\n14. test your applications in the jail and repeat 11 if any packages are missing<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. Install Jailkit, CentOS rpm available in rpmforge repo. 2. mkdir -p # to define your jail root 3. jk_init -v -j ssh # to allow ssh in your jail 4. jk_jailuser -j # to move the user into the jail 5. Edit \/etc\/jailkit\/jk_init.ini and \/etc\/jailkit\/jk_socketd.ini # to match your system 6. jk_cp -v -f [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,3],"tags":[],"class_list":["post-277","post","type-post","status-publish","format-standard","hentry","category-computer-tips","category-mri-technical-support","post-blog"],"_links":{"self":[{"href":"https:\/\/csic.som.emory.edu\/~lzhou\/blogs\/index.php?rest_route=\/wp\/v2\/posts\/277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/csic.som.emory.edu\/~lzhou\/blogs\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/csic.som.emory.edu\/~lzhou\/blogs\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/csic.som.emory.edu\/~lzhou\/blogs\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/csic.som.emory.edu\/~lzhou\/blogs\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=277"}],"version-history":[{"count":3,"href":"https:\/\/csic.som.emory.edu\/~lzhou\/blogs\/index.php?rest_route=\/wp\/v2\/posts\/277\/revisions"}],"predecessor-version":[{"id":279,"href":"https:\/\/csic.som.emory.edu\/~lzhou\/blogs\/index.php?rest_route=\/wp\/v2\/posts\/277\/revisions\/279"}],"wp:attachment":[{"href":"https:\/\/csic.som.emory.edu\/~lzhou\/blogs\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/csic.som.emory.edu\/~lzhou\/blogs\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/csic.som.emory.edu\/~lzhou\/blogs\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}