1. If you don’t want them to have shell access at all, then change their default user shell for each user on the ldap server.
— or —
2. If you want the users to have some shell access but just not on the file server, use Server Admin to specify the service access for SSH on the file server. Obviously this will keep the users from using SFTP, but since you titled the post AFP and LDAP I’m hoping you weren’t counting on SFTP access and no shell access. You can do that, but not without some extra work.
Comments are closed