1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
| ############################################################
# # # Configuration file for pure-ftpd wrappers # # # ######
# If you want to run Pure-FTPd with this configuration
# instead of command-line options, please run the
# following command :
# # /usr/sbin/pure-config.pl /etc/pure-ftpd/pure-ftpd.conf
# # Please don't forget to have a look at documentation at
# http://www.pureftpd.org/documentation.shtml for a complete list of
# options.
# Cage in every user in his home directory 将所有用户锁定于其home目录
ChrootEveryone yes
# If the previous option is set to "no", members of the following group
# won't be caged. Others will be. If you don't want chroot()ing anyone,
# just comment out ChrootEveryone and TrustedGID.设置一个信任的组ID,这样就可以不被锁定于home目录了。
# TrustedGID 100
# Turn on compatibility hacks for broken clients 可以兼容IE浏览器
BrokenClientsCompatibility no
# Maximum number of simultaneous users 服务器可以同时登录的最大客户端数目
MaxClientsNumber 50
# Fork in background 是否以守护进程运行
Daemonize yes
# Maximum number of sim clients with the same IP address同一IP最大连接数,默认是8
MaxClientsPerIP 4
# If you want to log all client commands, set this to "yes".
# This directive can be duplicated to also log server responses.记录所有的客户端命令到日志里面。
VerboseLog no
# List dot-files even when the client doesn't send "-a". 显示隐藏文件。
DisplayDotFiles yes
# Don't allow authenticated users - have a public anonymous FTP only. 禁止匿名登录
AnonymousOnly no
# Disallow anonymous connections. Only allow authenticated users. 禁止匿名连接,只允许认证用户。
NoAnonymous yes
# Syslog facility (auth, authpriv, daemon, ftp, security, user, local*)
# The default facility is "ftp". "none" disables logging. SyslogFacility ftp
# Display fortune cookies
# FortunesFile /usr/share/fortune/zippy
# Don't resolve host names in log files. Logs are less verbose, but
# it uses less bandwidth. Set this to "yes" on very busy servers or
# if you don't have a working DNS.
DontResolve yes
# Maximum idle time in minutes (default = 15 minutes) 最大空闲时间
MaxIdleTime 5
# LDAP configuration file (see README.LDAP)
# LDAPConfigFile /etc/pure-ftpd/pureftpd-ldap.conf
# MySQL configuration file (see README.MySQL)
# MySQLConfigFile /etc/pure-ftpd/pureftpd-mysql.conf
# Postgres configuration file (see README.PGSQL)
# PGSQLConfigFile /etc/pure-ftpd/pureftpd-pgsql.conf
# PureDB user database (see README.Virtual-Users)
# PureDB /etc/pure-ftpd/pureftpd.pdb # Path to pure-authd socket (see README.Authentication-Modules)
# ExtAuth /var/run/ftpd.sock
# If you want to enable PAM authentication, uncomment the following line
PAMAuthentication yes
# If you want simple Unix (/etc/passwd) authentication, uncomment this
UnixAuthentication yes
# Please note that LDAPConfigFile, MySQLConfigFile, PAMAuthentication and
# UnixAuthentication can be used only once, but they can be combined
# together. For instance, if you use MySQLConfigFile, then UnixAuthentication,
# the SQL server will be asked. If the SQL authentication fails because the
# user wasn't found, another try
# will be done with /etc/passwd and
# /etc/shadow. If the SQL authentication fails because the password was wrong,
# the authentication chain stops here. Authentication methods are chained in
# the order they are given.
# 'ls' recursion limits. The first argument is the maximum number of
# files to be displayed. The second one is the max subdirectories depth
LimitRecursion 2000 8
#Are anonymous users allowed to create new directories ?
AnonymousCanCreateDirs no
# If the system is more loaded than the following value,
# anonymous users aren't allowed to download.
MaxLoad 4
# Port range for passive connections replies. - for firewalling. PASSIVE端口范围
PassivePortRange 45000 50000
# Force an IP address in PASV/EPSV/SPSV replies. - for NAT.
# Symbolic host names are also accepted for gateways with dynamic IP
# addresses.
#如果FTP服务器在内网,而PASSIVE的模式是被动连接,所以要指定一个公网IP。如果不是通过NAT出公网,就不需要了。
ForcePassiveIP x.x.x.x
# Upload/download ratio for anonymous users.
# AnonymousRatio 1 10
# Upload/download ratio for all users.
# This directive superscedes the previous one.
# UserRatio 1 10
# Disallow downloading of files owned by "ftp", ie.
# files that were uploaded but not validated by a local admin.
AntiWarez yes
# IP address/port to listen to (default=all IP and port 21).
# FTP服务绑定的IP和端口,我发现设置为127.0.0.1后,不能连接,设置为0.0.0.0后就可以,这个大家注意一下。
# Bind 127.0.0.1,21
# Maximum bandwidth for anonymous users in KB/s
# AnonymousBandwidth 8
# Maximum bandwidth for *all* users (including anonymous) in KB/s
# Use AnonymousBandwidth *or* UserBandwidth, both makes no sense.
# UserBandwidth 8
# File creation mask. <umask files="" for="">:</umask><umask dirs="" for=""> .
# 177:077 if you feel paranoid.
Umask 133:022
# Minimum UID for an authenticated user to log in. 登录用户的UID如果低于500,是无法登录的。
MinUID 500
# Do not use the /etc/ftpusers file to disable accounts. We're already
# using MinUID to block users with uid :<max anonymous="" sessions="">
# For instance, 3:20 means that the same authenticated user can have 3 active
# sessions max. And there are 20 anonymous sessions max.
# PerUserLimits 3:20
# When a file is uploaded and there is already a previous version of the file
# with the same name, the old file will neither get removed nor truncated.
# Upload will take place in a temporary file and once the upload is complete,
# the switch to the new version will be atomic. For instance, when a large PHP
# script is being uploaded, the web server will still serve the old version and
# immediatly switch to the new one as soon as the full file will have been
# transfered. This option is incompatible with virtual quotas.
# NoTruncate yes
# This option can accept three values :
# 0 : disable SSL/TLS encryption layer (default). 关闭SSL/TLS加密层,也就是只支持普通的明文连接。
# 1 : accept both traditional and encrypted sessions. 支持明文连接和加密连接。
# 2 : refuse connections that don't use SSL/TLS security mechanisms,
# including anonymous sessions.只允许SSL/TLS加密连接。
# Do _not_ uncomment this blindly. Be sure that :
# 1) Your server has been compiled with SSL/TLS support (--with-tls),
# 2) A valid certificate is in place,
# 3) Only compatible clients will log in. TLS 2
# Listen only to IPv4 addresses in standalone mode (ie. disable IPv6)
# By default, both IPv4 and IPv6 are enabled. 只监听IPV4地址。
IPV4Only yes
# Listen only to IPv6 addresses in standalone mode (ie. disable IPv4)
# By default, both IPv4 and IPv6 are enabled.
IPV6Only no
# UTF-8 support for file names (RFC 2640)
# Define charset of the server filesystem and optionnally the default charset
# for remote clients if they don't use UTF-8.
# Works only if pure-ftpd has been compiled with --with-rfc2640
# 客户端编码
#FileSystemCharset utf-8
ClientCharset gbk
|