chroot and no terminal all users but one

Do you have a question? Post it now! No Registration Necessary.  Now with pictures!

I have successfully added a rule to automatically chroot and deny terminal all
users, but I would like to exclude a single user from that rule. The problem is
that I can't seem to get the match to work:

Match User !excludeduser

Doesn't seem to work. I've also tried adding an overriding

Match User excludeduser
   chroot ...
   forcecommand ...

But I don't know how to make these reset to normal.

Site Timeline