vsftpd As FTPS Only, TLS 1.3, Chrooted Local Users
vsftpd from AppStream made into an FTPS server: TLS for every login and transfer, TLS 1.3 only, data connections tied to the logged-in session, users chrooted, no anonymous access, passive ports on a fixed range, each file checked by vsftpd first. The live test transfers a file over TLS and is refused in clear, anonymously and over TLS 1.2. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-vsftpd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [vsftpd As FTPS Only, TLS 1.3, Chrooted Local Users](https://www.iac-bazaar.com/catalog/ansible-vsftpd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# vsftpd As FTPS Only, TLS 1.3, Chrooted Local Users: https://www.iac-bazaar.com/catalog/ansible-vsftpd (download from your IaC Bazaar account)
```Preview:
Documentation
vsftpd
vsftpd from AppStream, made into an FTPS server: TLS required for every login and every transfer, TLS 1.3 only by default, the host's own accounts each locked into their home, passive data ports on a fixed range, no anonymous access, and every configuration checked by vsftpd itself before it lands. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages vsftpd, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
The distribution's unit, our configuration. The role installs
vsftpd and openssl, writes the whole of /etc/vsftpd/vsftpd.conf (root
0600), and enables the unit the package ships: systemctl cat vsftpd shows the
distribution's own unit. The listener is 127.0.0.1:21 by default; the live
test reads the listening sockets and expects loopback only.
The package's own file is plain FTP on every interface. The stock
vsftpd.conf listens on [::]:21 (listen_ipv6=YES, a dual-stack socket), lets
local users log in and write, and configures no TLS at all, so a password
crosses the network in clear (read in the package). The role writes the whole
file instead: TLS forced for logins and for data - a plain-text login gets
"530 Non-anonymous sessions must use encryption." and a data connection in
clear "522 Data connections must be encrypted." (both measured) - TLS 1.3 only
(a TLS 1.2 client is refused; vsftpd_tls12: true accepts it for older
clients), anonymous off, active mode off, passive mode on a fixed port range.
A data connection must resume the control connection's TLS session, which
proves it comes from the client that logged in: one that does not gets "522 SSL
connection failed: session reuse required" (measured; vsftpd_require_ssl_reuse: false lifts it for clients that cannot resume).
Local users, chrooted. Logins are the host's own accounts through PAM
(/etc/pam.d/vsftpd requires a shell listed in /etc/shells), each locked into
its home: the live test's user is still at / after cd ... vsftpd refuses a
chroot root the user can write to, and the role keeps that refusal (it does not
set allow_writeable_chroot), so a user's home belongs to root and the user
writes in a directory inside it - tests/pre-converge.yml makes one that way.
/etc/vsftpd/user_list keeps its stock deny list (root and the system
accounts), and vsftpd_denied_users adds to it.
Checked before it lands, without a check flag. vsftpd has no test mode.
Given the file and then -olisten=NO, it parses the whole file, loads the
certificate and stops at its inetd check - "not configured for standalone, must
be started from inetd" - binding nothing; any other message is the file's own
error ("unrecognised variable in config file", "bad bool value", "SSL: cannot
load RSA certificate" - measured). The order matters: vsftpd applies options in
the order given, so with -olisten=NO BEFORE the file, the file's
listen=YES wins and a real server starts - an earlier draft of this check did
exactly that, and left a server holding port 21 that the real start then could
not bind. /usr/local/libexec/iacbazaar-vsftpd-check is the template's
validate.
A certificate is made if you bring none. Self-signed, P-256, 825 days, the
common name from vsftpd_tls_common_name, the key root 0600. Point
vsftpd_tls_cert and vsftpd_tls_key at your own and set
vsftpd_tls_generate: false.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-borg
BorgBackup from EPEL: an encrypted, deduplicated repository, your paths backed up on a systemd timer with daily, weekly and monthly retention, the passphrase generated once and the key exported. The live test backs up a file through the unit, deletes it, restores it byte for byte, and sees a wrong passphrase refused. Original role, live-tested on Rocky Linux 10.
ansible-garage
Garage on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with a single-node layout applied on the first start; the live test creates a bucket and a key through the RPC, grants it, reads it back, and sees an anonymous S3 request refused. Original role, live-tested on Rocky Linux 10.
ansible-kopia
kopia on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which creates a filesystem repository, snapshots a directory, lists the snapshot and has kopia verify read every object back, all offline. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-samba-share
Samba for named accounts over SMB 3 only. The package accepts SMB 2.0.2, encrypts and signs only when the client asks, shares every local home, exposes printer shares and runs NetBIOS on 139. This role requires encryption and signing (the live test reads it from the server), serves only the shares you list, and speaks on 445 alone. Original role, live-tested on Rocky Linux 10.
ansible-seaweedfs
SeaweedFS (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test writes a file through the filer, reads it back and deletes it, sees anonymous S3 refused, runs a SigV4-signed bucket/put/get/delete round trip with the configured identity, sees a wrong secret refused, and reads the metrics. Original role, live-tested on Rocky Linux 10.
ansible-syncthing
Syncthing from the upstream release with its API on loopback behind a key that never appears in the unit file. Discovery, relays, NAT traversal, crash reports and self-upgrade are switched off through the REST API. The live test sees a missing or wrong key refused, finds no key in the unit, and watches a shared folder get indexed. Original role, live-tested on Rocky Linux 10.