The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Linuxユーザーに許可した操作だけをさせたい場合、目的に合わせて方式を選びます。簡単な対話型コマンド制限にはBashの rbash、SSH鍵に対する単一処理の強制にはOpenSSHの強制コマンド、ファイル転送だけなら internal-sftp が適しています。rbash は完全なサンドボックスではないため、信頼できないユーザーの隔離にはコンテナや専用VMなどを検討してください。
まず目的に合う方式を選ぶ
| 目的 | 適した方式 | 注意点 |
|---|---|---|
| 限定されたコマンドを対話的に使わせる | rbash、root所有の起動設定、限定したPATH |
許可したプログラムから制限を回避される可能性があります。 |
| SSH鍵で特定の処理だけ許可する | authorized_keys の restrict,command= |
強制コマンドの実装と引数検証が重要です。 |
| SSH経由で特定の処理を強制する | sshd_config の ForceCommand |
転送やPTYなど不要な機能も無効にします。 |
| ファイル転送だけ許可する | ForceCommand internal-sftp |
見せる範囲も限定するなら ChrootDirectory を追加します。 |
| 信頼できない利用者を強く隔離する | 専用VM、コンテナ、jail、SELinux/AppArmorなど | rbash や単独のchrootを強い隔離境界とみなさないでください。 |
rbash が制限するもの、しないもの
Bashは実行ファイル名が rbash の場合、または --restricted / -r を付けて起動した場合にrestricted modeになります。通常のBashに似ていますが、たとえば cd、PATH など一部の環境変数の変更、コマンド名へのスラッシュの指定、出力リダイレクト、exec などが制限されます。詳細はBash公式マニュアルを参照してください。
ただし、これはシェルの機能制限であり、ファイルシステムやカーネルから利用者を隔離する仕組みではありません。許可したエディター、ページャー、インタープリターなどが別のシェルや任意コマンドを起動できれば、制限を回避されることがあります。また、restricted modeからシェルスクリプトを起動すると、そのスクリプトを処理するシェルでは制限が解除され得ます。任意のスクリプトを実行可能にしないでください。
Recommended Free Tools
ユーザーのログインシェルを rbash にする
まず、システムにある rbash の場所を調べます。パスはディストリビューションによって異なる場合があります。
#1 Best Overall
- Intel Core i5-1335U Processor (12M Cache, 12 Threads, up to 4.6 GHz) - 256GB Solid State Drive - 16GB DDR4 SDRAM
- 15.6" FHD (1920x1080) Non-Touch Anti-Glare Display - Intel UHD 620 Integrated Graphics - Stereo Speakers
- 720p HD Webcam with Privacy Shutter. Integrated Microphone - Intel Dual Band Wireless-AC (2x2) 8265, Bluetooth Version 4.2
- I/O Ports: 2x USB 3.0, 1x USB 3.1 Type-C 3.1, Headphone/Mic Combo Port, 4-in-1 Card Reader, HDMI, Kensington Mini-Lock Slot
- Linux Mint (Cinnamon) 64-Bit - Keyboard with Full NumberPad - Fast Charging
command -v rbash
専用ユーザーを作る例です。/bin/rbash が実在し、システムで利用可能なログインシェルであることを確認してから使ってください。
sudo useradd -m -s /bin/rbash restricteduser
sudo passwd restricteduser
getent passwd restricteduser
既存アカウントのシェルを変更するなら、次のようにします。
sudo usermod -s /bin/rbash restricteduser
getent passwd の結果に、意図したホームディレクトリとシェルが表示されることを確認してください。ディストリビューションのアカウント作成ツールや設定によって、ホームディレクトリの作成方法などは異なります。
限定したPATHを管理者が設定する
rbash は利用者自身による PATH の変更を制限できますが、初期値まで安全にしてくれるわけではありません。必要な実行ファイルだけを置く、管理者所有のディレクトリを作ります。
sudo install -d -o root -g root -m 755 /opt/restricted-bin
sudo ln -s /usr/bin/ls /opt/restricted-bin/ls
sudo ln -s /usr/bin/cat /opt/restricted-bin/cat
sudo ln -s /usr/bin/whoami /opt/restricted-bin/whoami
ユーザーが変更できないログイン初期化設定で、たとえば次のようにします。
Rank #2
- Intel Core i5-10210U (up to 4.2GHz) - 1TB PCIe NVMe + 1TB HDD - 32GB DDR4 SDRAM
- 17.3" HD+ (1600x900) Display, Intel UHD Graphics 620
- Built in HD 720p Webcam with Microphone - Bluetooth Version4.2
- I/O Ports: 2x USB 3.1 (Data Only), 1x USB 2.0, 1x HDMI, 1x Headphone/Microphone Combo Jack
- Linux Mint Cinnamon 64-Bit - 6-Row Keyboard w/ Full Numberpad
PATH=/opt/restricted-bin
export PATH
実際に読み込まれる起動ファイルはBashの起動方法やディストリビューションの設定で異なります。対象ユーザーでログインし、意図した値が設定されていることを確認してください。ユーザーが書き込めるディレクトリを PATH に含めると、偽の実行ファイルを置かれるおそれがあります。
ホームと起動ファイルの書き込み権限を確認する
利用者が起動ファイルや実行ファイルを差し替えられないよう、所有者と権限を設計します。次は、ホームディレクトリ自体を管理者所有にし、利用者が書き込めない例です。
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchessudo chown root:root /home/restricteduser
sudo chmod 755 /home/restricteduser
sudo touch /home/restricteduser/.bash_profile
sudo chown root:root /home/restricteduser/.bash_profile
sudo chmod 644 /home/restricteduser/.bash_profile
この設定では、利用者がホーム直下にファイルを作成できません。利用者に作業用の書き込み場所が必要なら、別途専用ディレクトリを用意し、その場所をコマンド検索用の PATH から外してください。
ログイン後に制限を確認する
echo "$SHELL"
echo "$-"
set -o | grep restricted
shopt restricted_shell
さらに、制限されるはずの操作を実際に試します。
cd /tmp
PATH=/tmp
exec /bin/bash
echo test > /tmp/testfile
操作が失敗することだけで安全性を判断してはいけません。許可コマンドが別の実行機能を持たないか、ユーザーが書き込める場所からスクリプトを実行できないかも点検します。
Rank #3
- [ULTRA-RUGGED DESIGN] MIL-STD-810G and IP65 certified. Built to survive 6-foot drops, heavy rain, and extreme vibrations. Features a magnesium alloy chassis with an integrated carry handle for maximum portability
- [4G LTE - WORK ANYWHERE] Integrated 4G LTE Multi-Carrier Mobile Broadband. Stay connected to the internet in remote areas or on the road without relying on Wi-Fi or phone hotspots. True mobile freedom for field professionals
- [1200-NIT SUNLIGHT READABLE] 13.1" XGA Touchscreen with CircuLumin technology. At 1200 nits, it is nearly 4x brighter than a standard laptop, ensuring perfect visibility under direct, intense sunlight
- [LINUX UBUNTU PRE-INSTALLED] Fast, secure, and bloatware-free. Optimized for developers, network engineers, and diagnostic software that thrives in a stable, open-source environment
- [LEGACY SERIAL PORT] Features a native RS-232 Serial Port, HDMI, and USB 3.0. Essential for connecting directly to industrial machinery, CNCs, and automotive diagnostic tools without unreliable adapter
SSHで限定アクセスを作る
SSH経由で利用者に限られた操作だけを許す場合、シェルを rbash にするよりSSHサーバー側で許可内容を明示する方が目的に合うことがあります。
サーバー側の ForceCommand
ForceCommand はクライアントが要求したコマンドを無視し、サーバー側で指定したコマンドを実行させます。シェル、通常のコマンド、サブシステムの要求に適用され、元のクライアントコマンドは SSH_ORIGINAL_COMMAND で参照できます。設定仕様はsshd_configのマニュアルを確認してください。
Match User restricteduser
ForceCommand /usr/local/sbin/restricted-command
DisableForwarding yes
PermitTTY no
指定したラッパーがクライアントコマンドを受け取る設計なら、許可するコマンド、引数、パスを厳密に検証します。SSH_ORIGINAL_COMMAND の値をそのままシェルに渡したり、eval で評価したりしてはいけません。ラッパー自身の脆弱性は ForceCommand では防げません。
SSH鍵ごとの強制コマンド
特定の鍵だけに制限を適用するなら、対象アカウントの ~/.ssh/authorized_keys に鍵オプションを指定できます。
restrict,command="/usr/local/sbin/restricted-command" ssh-ed25519 AAAA... comment
restrict はポート転送、エージェント転送、X11転送、PTY割り当て、~/.ssh/rc の実行などを無効にします。鍵オプションの詳細はsshdのマニュアルを参照してください。必要に応じて鍵の用途に合わせた追加制限を設定し、転送やTTYが使えないことを実接続で確かめます。
Rank #4
- THE POWER TO STAY PRODUCTIVE – Looking to make your everyday work and home life more manageable without breaking the bank? The Lenovo V15 Gen 4 offers long-term reliability with top-of-the-line features to make you your most productive self.
- CRUSH YOUR TO-DO LIST – The AMD Ryzen CPU pairs quiet performance and enhanced operating power to crush your high-demand workday. It optimizes performance and allows for seamless multitasking.
- TRUE-TO-LIFE VISUALS – The 15.6” FHD IPS display is anti-glare with 300 nits brightness to see your best outside or in. Its 88% screen-to-body ratio makes viewing detailed applications like spreadsheets a breeze.
- SEAMLESS COLLABORATION – Lenovo Smart Appearance enhances your camera effects to protect your privacy and to make you the focus of every video conference. Intelligent noise cancelation minimizes distraction and Dolby Audio provides an elegantly sonorous experience.
- BUILT TO WITHSTAND – Built for military-grade toughness, the V15 Gen 4 is tested to withstand harsh temperatures, pressure, humidity, vibrations and more. Keep your work safe from the board room to your living room and everywhere in between.
SFTPだけを許可する
ファイル転送だけが必要なら、restricted shellではなくOpenSSHの internal-sftp を使うのが直接的です。さらに利用者から見えるファイル範囲を限定する場合は、ChrootDirectory を組み合わせます。
たとえば次のような設定を sshd_config に追加します。
Match Group sftp-only
ChrootDirectory /srv/sftp/%u
ForceCommand internal-sftp
DisableForwarding yes
PermitTTY no
この例のユーザーとグループを作ります。ログインシェルの指定は環境に合わせて確認してください。nologin がPAMやディストリビューションの設定とどう連携するかは実機で検証します。
sudo groupadd sftp-only
sudo useradd -m -g sftp-only -s /usr/sbin/nologin alice
sudo passwd alice
chrootのルートと親ディレクトリは利用者が書き込めない所有者・権限にする必要があります。書き込み可能な場所はその下に別途作ります。
sudo mkdir -p /srv/sftp/alice/upload
sudo chown root:root /srv/sftp
sudo chmod 755 /srv/sftp
sudo chown root:root /srv/sftp/alice
sudo chmod 755 /srv/sftp/alice
sudo chown alice:sftp-only /srv/sftp/alice/upload
sudo chmod 750 /srv/sftp/alice/upload
ChrootDirectory はファイルシステム上で利用者に見える範囲を変える機能で、コンテナやVMと同じ強さの隔離機構ではありません。OpenSSHのchroot要件と設定の詳細はsshd_configのマニュアルを参照してください。internal-sftp はchroot内に外部SFTPサーバーバイナリやライブラリを用意せずに使えます。
Best Value
- Powerful Linux Laptop: This IdeaPad Slim 3 Laptop comes pre-installed with Ubuntu Linux, offering fast performance, robust security, and a clean, user-friendly experience. Enjoy full customization, seamless hardware compatibility, and access to thousands of open-source apps. Whether you're working, creating, or coding, it's built to keep up with everything you do.
- A Multitasking Master: The latest AMD Ryzen 7 5825U processor (up to 4.5 GHz) delivers powerful performance with 8 cores and 16 threads for smooth multitasking. Integrated AMD Radeon Graphics provide crisp visuals for streaming, browsing, photo editing, and casual gaming. With smart machine intelligence, it adapts to your needs for a fast, responsive experience.
- 15.6" Full HD Display: The IdeaPad Slim 3 boasts an 88% screen-to-body ratio for a floating, edge-to-edge visual experience. TÜV Low Blue Light certification reduces eye strain, making it perfect for long work or study sessions.
- Military-Grade Durability: The smart IdeaPad Slim 3 combines portability and durability, letting you work, study, and play on the go. With a profile 10% slimmer than the previous generation, it's lightweight yet military-grade rugged, ready for anything, anywhere.
- Versatile Connectivity: Enjoy the security of a built-in webcam with a privacy shutter. Connect effortlessly with multiple ports: 2x USB A, 1x USB C, 1x HDMI, 1x SD Card Reader, 1x Headphone/Microphone combo. Bundle comes with Stylus Pen, 256GB Portable SSD and 5-in-1 Docking Station.
設定を安全に反映して検証する
SSH設定を変更したら、現在の管理者セッションを閉じる前に構文を確認し、別の端末から試します。サービス名は環境によって sshd または ssh です。
sudo sshd -t
sudo sshd -T -C user=restricteduser,host=server.example.com,addr=192.0.2.10
sudo systemctl reload sshd
sshd -T -C は Match 条件を含む実効設定を確認するのに役立ちます。サービス名が ssh の環境では、再読み込みを次のようにします。
sudo systemctl reload ssh
接続テストでは、シェル、コマンド実行、TTY、転送のそれぞれを確認します。
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
ssh [email protected]
ssh [email protected] 'id'
ssh -T [email protected]
ssh -o RequestTTY=yes [email protected]
ssh -L 9999:127.0.0.1:22 [email protected]
ssh -R 9999:127.0.0.1:22 [email protected]
ssh -A [email protected]
ssh -X [email protected]
制限対象の機能が使えないことを確認します。SFTP専用構成では sftp [email protected] で接続し、pwd、ls、cd ..、put、get を試します。chroot外へ出られず、書き込み可能なのが許可した場所だけであることを確認してください。
アカウント設定やファイル権限も点検できます。
getent passwd restricteduser
id restricteduser
ls -ld /home/restricteduser
find /opt/restricted-bin -maxdepth 1 -type l -ls
find /home/restricteduser -type f -perm /111 -ls
誤設定で接続できなくなったときに備え、変更前に別の管理者経路を確保し、設定ファイルをバックアップしてください。新しい設定が動作すると確認できるまで、既存の管理セッションを閉じないでください。接続失敗の原因はSSHサーバーのログでも確認します。
よくある回避経路を点検する
- エディターやページャー:
vi、vim、lessなど、外部コマンドを起動できるものを不用意に許可しないでください。 - インタープリターや汎用ツール:
python、perl、awk、find、tar、gitなどは任意コード実行や別コマンド起動につながる場合があります。 - ユーザーが書き込めるPATH:実行ファイルを差し替えられないよう、検索対象ディレクトリとファイルを管理者所有にします。
- シェルスクリプト:任意スクリプトの実行を許可しないでください。必要なら、管理者所有で引数を厳しく検査する専用プログラムを使います。
- SSH転送やPTY:シェルを制限しても別のアクセス経路を残さないよう、鍵の
restrictやサーバー側のDisableForwarding yes、PermitTTY noを目的に応じて使います。
DisableForwarding などの利用可否や挙動は、インストール済みOpenSSHのバージョンとディストリビューションのマニュアルで確認してください。
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →まとめ:シェルではなく必要な機能を制限する
rbash は簡易的なコマンド制限には使えますが、実行可能プログラムやファイル権限を適切に設計しても、強固なサンドボックスにはなりません。単一処理ならSSHの強制コマンド、ファイル転送だけなら internal-sftp、ディレクトリ範囲も限定するなら ChrootDirectory を選びます。信頼できない利用者を強く隔離する必要がある場合は、コンテナ、jail、専用VMなどを脅威モデルに合わせて検討してください。

