ºìÁªLinuxÃÅ»§
Linux°ïÖú

Ïê½âLinuxÖÐSSHÔ¶³Ì·ÃÎÊ¿ØÖÆ

·¢²¼Ê±¼ä:2014-06-27 09:53:02À´Ô´:ºìÁª×÷Õß:velcbo
SSH£ºÊÇÒ»ÖÖ°²È«Í¨µÀЭÒ飬Ö÷ÒªÓÃÀ´ÊµÏÖ×Ö·û½çÃæµÄÔ¶³ÌµÇ¼£¬Ô¶³Ì¸´ÖƵȹ¦ÄÜ(ʹÓÃTCPµÄ22ºÅ¶Ë¿Ú)¡£SSHЭÒé¶ÔͨÐÅË«·½µÄÊý¾Ý´«Êä½øÐÐÁ˼ÓÃÜ´¦Àí£¬ÆäÖаüÀ¨Óû§µÇ¼ʱÊäÈëµÄÓû§¿ÚÁî¡£

ÔÚRHEL 5ϵͳÖÐʹÓõÄÊÇOpenSSH·þÎñÆ÷ÓÉopenssh£¬openssh-serverµÈÈí¼þ°üÌṩµÄ(ĬÈÏÒѾ­°²×°)£¬²¢ÒÔ½«sshdÌí¼ÓΪ±ê×¼µÄϵͳ·þÎñ¡£

SSHÌṩһÏÂÁ½ÖÖ·½Ê½µÄµÇ¼ÑéÖ¤£º
1¡¢ÃÜÂëÑéÖ¤£ºÒÔ·þÎñÆ÷Öб¾µØÏµÍ³Óû§µÄµÇ¼Ãû³Æ£¬ÃÜÂë½øÐÐÑéÖ¤¡£
2¡¢ÃØÔ¿¶ÔÑéÖ¤£ºÒªÇóÌṩÏàÆ¥ÅäµÄÃØÔ¿ÐÅÏ¢²ÅÄÜͨ¹ýÑéÖ¤¡£Í¨³£ÏÈÔÚ¿Í»§»úÖд´½¨Ò»¶ÔÃØÔ¿Îļþ(¹«Ô¿ºÍ˽Կ)£¬È»ºó½«¹«Ô¿Îļþ·Åµ½·þÎñÆ÷ÖеÄÖ¸¶¨Î»Öá£

×¢Ò⣺µ±ÃÜÂëÑéÖ¤ºÍ˽ԿÑéÖ¤¶¼ÆôÓÃʱ£¬·þÎñÆ÷½«ÓÅÏÈʹÓÃÃØÔ¿ÑéÖ¤¡£

SSHµÄÅäÖÃÎļþ£º
sshd·þÎñµÄÅäÖÃÎļþĬÈÏÔÚ/etc/ssh/sshd_config£¬ÕýÈ·µ÷ÕûÏà¹ØÅäÖÃÏ¿ÉÒÔ½øÒ»²½Ìá¸ßsshdÔ¶³ÌµÇ¼µÄ°²È«ÐÔ¡£

ÅäÖÃÎļþµÄÄÚÈÝ¿ÉÒÔ·ÖΪÒÔÏÂÈý¸ö²¿·Ö£º

1¡¢³£¼ûSSH·þÎñÆ÷¼àÌýµÄÑ¡ÏîÈçÏ£º
Port 22 //¼àÌýµÄ¶Ë¿ÚΪ22
Protocol 2 //ʹÓÃSSH V2ЭÒé
ListenAdderss 0.0.0.0 //¼àÌýµÄµØÖ·ÎªËùÓеØÖ·
UseDNS no //½ûÖ¹DNS·´Ïò½âÎö

2¡¢³£¼ûÓû§µÇ¼¿ØÖÆÑ¡ÏîÈçÏ£º
PermitRootLogin no //½ûÖ¹rootÓû§µÇ¼
PermitEmptyPasswords no //½ûÖ¹¿ÕÃÜÂëÓû§µÇ¼
LoginGraceTime 2m //µÇ¼Ñé֤ʱ¼äΪ2·ÖÖÓ
MaxAuthTries 6 //×î´óÖØÊÔ´ÎÊýΪ6
AllowUsers user //Ö»ÔÊÐíuserÓû§µÇ¼£¬ÓëDenyUsersÑ¡ÏîÏà·´

3¡¢³£¼ûµÇ¼ÑéÖ¤·½Ê½ÈçÏ£º
PasswordAuthentication yes //ÆôÓÃÃÜÂëÑéÖ¤
PubkeyAuthentication yes //ÆôÓÃÃØÔ¿ÑéÖ¤
AuthorsizedKeysFile .ssh/authorized_keys //Ö¸¶¨¹«Ô¿Êý¾Ý¿âÎļþ


SSH¿Í»§¶ËÃüÁî³ÌÐòssh¡¢scp¡¢sftp
ͨ¹ýsshÃüÁî¿ÉÒÔÔ¶³ÌµÇ¼µ½sshd·þÎñ£¬ÎªÓû§Ìṩһ¸ö°²È«µÄShell»·¾³£¬Ò»±é¶Ô·þÎñÆ÷½øÐйÜÀíºÍά»¤¡£Ê¹ÓÃʱָ¶¨µÇ¼Óû§Ãû£¬Ä¿±êÖ÷»ú×÷Ϊ²ÎÊý¡£

µ±Óû§µÚÒ»´ÎµÇ¼SSH·þÎñÆ÷ʱ£¬±ØÐë½ÓÊÜ·þÎñÆ÷·¢À´µÄRSAÃØÔ¿(¸ù¾ÝÊäÈëyes)ºó²ÅÄܼÌÐø¡£½ÓÊܵÄÃØÔ¿ÐÅÏ¢½«±£´æµ½¡°~/.ssh/known_hosts¡±ÎļþÖС£Èç¹ûĬÈ϶˿ڱ»¸ü¸Ä£¬¿ÉÒÔʹÓÃ-pÃüÁîÖÆ¶¨¶Ë¿Ú¡£
ͨ¹ýscpÃüÁî¿ÉÒÔÀûÓÃSSH°²È«Á¬½ÓÓëÔ¶³ÌÖ÷»ú»¥Ïà¸´ÖÆÎļþ¡£Ê¹ÓÃscpÃüÁîʱ£¬³ýÁ˱ØÐëÖÆ¶¨¸´ÖÆÔ´£¬Ä¿±êÒÔÍ⣬»¹Ó¦Öƶ¨Ä¿±êÖ÷»úµØÖ·£¬µÇ¼Óû§£¬Ö´ÐкóÌáʾÑéÖ¤¿ÚÁîµÈ¡£

ͨ¹ýsftpÃüÁî¿ÉÒÔÀûÓÃSSH°²È«Á¬½ÓÓëÔ¶³ÌÖ÷»úÉÏ´«£¬ÏÂÔØÎļþ£¬²ÉÓÃÁËÓëFTPÀàËÆµÄµÇ¼¹ý³ÌºÍ½»»¥Ê½»·¾³£¬±ãÓÚĿ¼×ÊÔ´¹ÜÀí¡£

Èç¹û¿Í»§¶ËÊÇwindowsϵͳ£¬ÄÇôÎÒÃÇ¿ÉÒÔʹÓÃһЩͼÐλ¯µÄ¹¤¾ßÀ´·ÃÎÊLinux·þÎñÆ÷¡£³£¼ûµÄһЩͼÐλ¯¹¤¾ßÓÐPuTTY£¬WinSCPµÈ¹¤¾ß£¬¾ßÌåÈçºÎʹÓÃÇë¸÷λ×ÔÐÐÑо¿¡£

ÎÒÃÇ·ÖËIJ½À´¹¹½¨ÃØÔ¿¶ÔÑéÖ¤µÄSSH¡£
1¡¢ÔÚSSH¿Í»§»ú´´½¨Óû§ÃØÔ¿¶Ô¡£
ÈçÏ£ºÎªtestÓû§´´½¨ÃØÔ¿¶Ô¡£

-tÓÃÓÚÖ¸¶¨Ëã·¨ÀàÐÍ£¬rsa±íʾʹÓÃrsaËã·¨¡£
ÃØÔ¿¶ÌÓïÓÃÀ´¶Ô˽ԿÎĽøÐб£»¤£¬µ±Ê¹ÓÃ˽ԿÑéÖ¤µÇ½ʱ±ØÐëÌṩ´Ë´¦ËùÉèÖõĶÌÓï¡£
ÃØÔ¿¶ÔĬÈϱ£´æÔÚÓû§ËÞÖ÷Ŀ¼ÏµÄ.ssh/Ŀ¼Ï¡£
2¡¢½«¹«Ô¿ÉÏ´«ÖÁSSH·þÎñÆ÷
½«¹«Ô¿ÉÏ´«ÖÁSSH·þÎñÆ÷µÄ·½Ê½Óкܶ࣬¿ÉÒÔʹÓÃUÅÌ¿½±´£¬Ò²¿ÉÒÔʹÓÃftp¡¢¹²ÏíµÈ·½Ê½ÉÏ´«¡£ÔÚ´ËÎÒÃÇʹÓøս²¹ýµÄscpÃüÁîÉÏ´«¹«Ô¿Îļþ¡£

3¡¢ÔÚSSH·þÎñÆ÷Öе¼È빫ԿÎı¾
ÔÚ·þÎñÆ÷ÖУ¬Ä¿±êÓû§(ÓÃÀ´Ô¶³ÌµÇ¼µÄÓû§)µÄ¹«Ô¿Êý¾Ý¿âλÓÚ~/.ssh/Ŀ¼Ï£¬Ä¬ÈÏÎļþÃûÊÇauthorized_keys¡£ÈçÏ£º½«testµÄ¹«Ô¿Îļþµ¼Èëµ½userÓû§µÄ¹«Ô¿Êý¾Ý¿âÖС£

4¡¢´ËʱÔÚ¿Í»§¶Ë¾Í¿ÉÒÔʹÓÃÃØÔ¿¶ÔÑéÖ¤ÁË¡£

´ËʱÐèÒªÓû§ÊäÈë´´½¨ÃØÔ¿¶ÔʱÊäÈëµÄÃØÔ¿¶ÌÓ¶ø²»ÐèÒªÖªµÀÓû§µÄÃÜÂë¼´¿ÉµÇ¼SSH·þÎñÆ÷¡£

×÷Õߣºcshbk
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ